BeSafe 1.5 is coming soon

This site previews the next release. The App Store link opens the version currently available.

Legal information

Privacy Policy

This policy explains in practical terms how BeSafe uses information in the iOS app and on be-safe.app.

Last updated: September 11, 2026

Audio stays on your iPhone

Files are transferred only when you choose an export destination.

Sharing starts with you

A time limit, a latest location and a link to send to people you choose.

Your controls stay accessible

Manage your account in BeSafe, permissions in iOS and cookies at the bottom of this page.

1. Introduction

BeSafe is published by Hugo Bertin. This policy describes information used by the iOS app and be-safe.app website. It covers the upcoming version 1.5; available features depend on your version. The sharing and automatic SMS features described here concern version 1.5 and operate after you enable them.

BeSafe is a personal assistance tool and does not replace emergency services.

2. Data and information used by BeSafe

Local tools can be used without an account. A BeSafe account is required for Premium location sharing and automatic SMS. Sign-in uses Supabase Auth with Apple, Google or an emailed code. The service processes the account ID, email provided by the sign-in provider (which Apple may mask) and technical authentication information. App session tokens are stored in the iOS Keychain.

The BeSafe app does not include advertising tools, audience analytics or cross-app tracking. The website uses cookie-free Vercel Web Analytics to produce aggregate statistics and Google Analytics only after the visitor consents. Some information also leaves the device when the user requests an Apple service, displays a map, sends a message, opens an external link or contacts support. Those cases are explained in the following sections.

Processing needed for requested app features is based on providing the service selected by the user. Microphone and location remain subject to the user’s choice and iOS permissions. Handling support requests and protecting the website rely on the legitimate interests of responding, operating the service and preventing abuse, together with applicable legal obligations where relevant.

  • Profile, phrase, preferences, contacts and prepared messages: stored locally for app features.
  • Audio recordings and local histories: stored on the iPhone, without automatic audio uploads.
  • Maps: search text, location and destination used for Apple Maps results and routes.
  • Account, verified Premium status and technical information: processed by server services to authenticate and authorize your requests.
  • Voluntary sharing: latest location, accuracy, timestamp and session duration sent to the server while sharing.
  • Automatic SMS, after you enable it: recipients, message, trigger, deadline and optional location sent to the server for enabled alerts.
  • Support and website: messages you send us and technical information needed to display, secure and measure use of the website.

3. Microphone and audio

The microphone is used when the user enables voice protection, starts a guided test or requests a recording. Voice protection that has already been enabled may continue listening for the safety phrase when the app moves into the background; it stops when the user disables protection or iOS interrupts the audio session.

Since version 1.3, phrase recognition runs on the iPhone using a bundled Whisper model. Version 1.4 uses the selected language, French or English. Older versions may use a different implementation based on iOS audio or recognition components. No BeSafe server is configured to receive the voice stream.

The audio and text fragments needed for detection are handled during the active session and are not retained as a conversation history. Local technical events may nevertheless indicate the state of phrase detection or the audio session.

After detecting the safety phrase, or following a manual action where the feature permits it, BeSafe may start a separate recording. Users can withdraw Microphone permission at any time in iOS Settings; the relevant features will then be unable to work normally.

In version 1.4, the first-launch introduction uses demonstrations only and does not activate the microphone. The real guided test starts separately after your action and microphone permission. Phrase recognition is real, but recording and message steps are simulated: no audio file is saved and no recipient is contacted. Status and results may remain temporarily in memory to show the outcome when you return to the app.

4. Location

Location is optional for voice recognition and the guided test. After your action, a one-time location may be added to a manual SMS. That point is not live tracking.

Place, destination and route searches send search text, origin location or area and destination to Apple Maps. Places include police, hospitals, pharmacies, transport, fire stations, hotels, cafés, shops and gas stations. A result guarantees neither opening hours nor safety.

The map keeps the chosen place, results and route in memory during the app session, including after screen locking or returning Home. Its GPS updates pause when it is not being viewed. An active trip keeps its destination and travel mode locally until closed, without a completed-trip GPS history. Opening directions in Maps sends the destination to Apple.

Premium location sharing is separate and voluntary: you choose 15, 30, 60 or 120 minutes. BeSafe sends your location and accuracy to the server, including in the background while iOS permits it. Only the latest location is retained for the share, encrypted in the database, without a route history.

You send the link using the iOS share menu. Anyone with it can view the latest location until sharing stops or expires, without a BeSafe account. The page uses Apple Maps and does not request the recipient’s location. The last-received time indicates freshness; network access, GPS, battery and closing the app may interrupt updates.

A server-confirmed stop revokes the link and removes the location. Offline, local transmission stops but the last location may remain accessible until the stop is confirmed or sharing expires. Expiry denies access immediately, with coordinate cleanup normally within the next minute. Voluntary link sharing sends no automatic SMS.

In version 1.2, some local diagnostics could include coordinates. Later versions no longer add them to diagnostics; older data may remain until erased.

5. Contacts and messages

Trusted contacts are entered manually in BeSafe. The source code examined does not access the iPhone address book. The contact’s name, phone number, prepared message and selection remain stored locally until they are edited or deleted.

For a manual SMS, BeSafe opens Messages with text and recipients. You confirm sending. Apple, the carrier and recipients then process the message. Other numbers may be visible in a group message.

In version 1.5, your settings and activation of automatic SMS authorize the server to process chosen phone numbers, message content, trigger and deadline for sending through OVHcloud. Numbers and content are encrypted in the database, then sent to OVHcloud for delivery. Depending on your options, the message may include a temporary location link. OVHcloud, carriers and recipients process SMS under their services. Emergency calls are never automatic and SMS delivery cannot be guaranteed.

Users must provide only contact details they are authorised to use and should inform their trusted contacts about the intended use where necessary.

6. Recordings

Audio files are created in the app’s local folder and appear in history with their date and duration. BeSafe does not upload them to a BeSafe server or automatically transmit them to a contact or support.

In version 1.5, manual recording, playback, export and deletion are free. Triggering through voice protection requires Premium. BeSafe deletes the file before removing its history entry. If deletion fails, the entry remains so you can retry; bulk deletion may be partial. In older versions, some access depended on a subscription and an error could leave a file without a history entry.

Export opens the iOS share sheet: you choose “Save to Files”, a location or another available destination. BeSafe does not upload the file to a BeSafe server. A destination such as iCloud Drive or a third-party app may synchronize or process the copy under its own settings. The original stays in BeSafe. Deleting the original or uninstalling BeSafe does not remove exported copies, which are managed at their destination.

A temporary local copy is prepared in the cache for sharing and cleaned up when the operation ends, including cancellation. If the operation is interrupted or cleanup fails, BeSafe retries during a subsequent export.

Depending on iPhone settings, app data may be included in an iCloud backup or device backup managed by Apple. BeSafe does not control those possible copies; users must manage them through Apple backup settings.

7. App Store subscriptions and purchases

BeSafe Premium purchases are processed by Apple using StoreKit. BeSafe asks Apple for the product list, displayed prices and verified entitlement status to activate or restore Premium. The app retains Premium status and its last update time locally.

To authorize Premium server services, BeSafe sends the Apple purchase receipt to its server for verification. The server keeps the verification result, purchase environment, product, expiry and account association to control access and prevent misuse. Test receipts do not enable paid SMS. The receipt is also retained in encrypted form to recheck entitlements.

BeSafe receives no card number, Apple Account password or full payment details. Apple is responsible for handling payment, purchase history and the Apple Account under its own terms.

Manage and cancel through the Apple Account used for purchase. Deleting the app or your BeSafe account does not cancel that subscription.

8. Apple services and other providers

Account and sharing services use the BeSafe API hosted by OVHcloud and Supabase for authentication and the database. Sign-in emails use Resend. Apple or Google are involved if you choose their sign-in. OVHcloud also delivers automatic SMS that you enable. These providers receive information needed for the features described here; BeSafe does not upload audio recordings to them.

BeSafe uses iOS components for the microphone, location, Maps, Messages, phone calls, local notifications, alarms, Live Activities and StoreKit. These services may process the information needed for the requested feature under Apple’s terms.

Google receives a coordinate when a Google Maps link containing that coordinate is opened. The be-safe.app website is hosted by Vercel: to deliver and secure pages, Vercel processes information including IP address, date, requested URL, browser type, location information derived from the IP address and technical logs. BeSafe has enabled no user account, form or advertising on this website.

The website uses Vercel Web Analytics to understand aggregate usage and improve its pages. According to Vercel, this service does not use cookies and retains only aggregate data that does not allow BeSafe to identify a visitor. Data points may include the page viewed, referrer, approximate location, browser, operating system and device type. This processing is based on BeSafe’s legitimate interest in measuring audience without individual tracking.

With the visitor’s consent, the website loads Google Analytics to produce usage statistics and improve its pages. Google may then process information including pages viewed, referrer URL, browser and device information, approximate location and identifiers stored in _ga cookies. No Google Analytics tag is loaded before consent. Consent can be declined or withdrawn at any time through the “Cookie settings” link at the bottom of every page.

Emails sent to support@be-safe.app are processed by BeSafe’s email provider. Depending on their organisation and the selected service, Apple, Google, Vercel or the email provider may process information in countries outside the European Economic Area. The applicable conditions and safeguards depend on the provider and are described in its privacy documents and the rules applicable to it.

From version 1.4, StoreKit may offer a review after a completed guided test when no protection or safety session is active. Apple controls whether the request appears and handles submitted reviews. BeSafe does not know whether you posted a review or what rating you gave. The Settings button opens the App Store review page directly.

The guided test in 1.4 offers a local success notification, disabled by default. After your choice and iOS permission, successful recognition in the background may trigger that notification. Its content does not include your personal phrase, contacts or location. iOS settings may limit its display.

9. Data retention and deletion

Local data and server services have distinct retention periods. Support cannot remotely erase a file that exists only on your iPhone. Use app controls for recordings and iOS settings for backups.

  • Profile, contacts, messages, phrases, settings and scenarios: retained locally while configured; they can be edited and, where the interface provides a control, deleted.
  • Voice detection stream: handled during the active session and then discarded; no conversation transcript is added to history. Local technical events may remain subject to iOS log management.
  • Audio recordings: retained until deleted from History or until app data is erased. In version 1.4, deletion remains available without a subscription.
  • Trip position: retained during the active trip until removed or the trip is explicitly closed; becoming overdue alone does not close the trip. Completed history does not retain coordinates.
  • Timer and trip histories: retained locally until the relevant item or history is deleted.
  • Drafts and sent SMS: retained by Messages, carriers and recipients according to their settings and obligations.
  • Local Premium status: retained until the next update or until app data is erased; Apple retains its own purchase data under its rules.
  • Support emails: retained for as long as needed to handle the request, prevent abuse and meet any evidence or retention obligations. The exact period depends on the nature of the request and applicable obligations; emails are deleted when no longer needed.
  • Website logs: retained by Vercel according to the plan and retention periods applicable to its service.
  • Vercel Web Analytics: the hash used to distinguish a visitor is automatically renewed after twenty-four hours; aggregate statistics remain available according to the reporting window of the applicable Vercel plan.
  • Google Analytics choice: stored locally in the browser for six months, after which the visitor is asked again. Declining prevents the tag from loading; withdrawing consent also removes Google Analytics cookies accessible to the website.
  • Google Analytics: the _ga and _ga_<identifier> cookies may be retained for up to two years according to Google’s documentation, subject to browser settings and any earlier withdrawal. Event-data retention in Google Analytics depends on the settings applied to the property and Google’s rules.
  • Audio exports in 1.4: the temporary copy is cleaned up after sharing, or during a subsequent export if the operation or cleanup was interrupted. Copies saved elsewhere remain under your control at their destination, independently of BeSafe.
  • Review requests in 1.4: first observed use date, last active day, an active-day count capped at three, and the version/date of the last request attempt are kept in local app data until erased. They are used only to space requests and are not sent to a BeSafe server.
  • Map browsing: chosen place, results and route kept in memory during the app session; no GPS history is added.
  • Live sharing: coordinates removed on confirmed stop or cleaned after expiry. Metadata is cleaned after 24 hours from creation; hashed cancellation markers remain for up to eight days to prevent recreation by delayed requests.
  • Account: retained while it exists. Deletion from My account removes associated alerts and shares, server entitlements and the authentication account. Hashed technical deletion and purchase-association markers may remain to prevent misuse. Account deletion does not remove information held by Apple, recipients or export destinations.
  • Automatic SMS: alert data, including encrypted message and recipients, is scheduled for cleanup seven days after the planned dispatch time, after pending operations have been handled. Copies held by OVHcloud, carriers and recipients follow their own retention periods.
  • Provider backups and logs: deletion in the active database does not necessarily erase infrastructure backups immediately; retention follows applicable provider settings and periods. Contact us for requests concerning this data.

10. Security

iOS isolates local app data. The active phrase configuration and authentication tokens are protected by the iOS Keychain; older migrated copies may remain in local storage. API exchanges use HTTPS. Sharing locations and sensitive alert content are encrypted in the database. This is not end-to-end encryption: the server must process data to provide the service.

Security also depends on the iPhone passcode, iCloud settings, access to the Apple Account and people who can access the device. No storage or transmission method can guarantee absolute security.

11. Children

BeSafe does not provide a dedicated child account. The App Store age rating concerns content and does not replace any supervision required when using personal data.

A minor should use BeSafe with a parent or legal guardian’s involvement where required by law or the circumstances, especially before saving contacts, using the microphone, sharing a location or making a purchase.

12. Changes to this policy

This policy may change to reflect a new BeSafe version, a provider change or a legal requirement. The current version is published on this page with its update date. If a material change requires a new choice, BeSafe will provide appropriate notice in the app, on the website or when the relevant feature is used.

13. Contact and rights

Controller: Hugo Bertin, 253 rue du Maquis de l’Oisans, 38750 Huez, France.

For questions about this policy or to exercise, where the conditions apply, your rights of access, rectification, erasure, restriction, objection or portability regarding information held by BeSafe, contact the address below. Describe your request without sending unnecessary recordings, locations, phone numbers or other sensitive information.

For information that exists only on your iPhone, use the app’s edit or deletion controls and iOS Settings. You may also lodge a complaint with the CNIL or the data protection authority responsible for your country.

support@be-safe.app

14. Last updated

September 11, 2026: updated for BeSafe 1.5, covering accounts, server Premium verification, routes, live location sharing, free audio tools and automatic SMS.