// LEGAL · PRIVACYPrivacy Policy
01Who we are
SafeRoute is a crime-aware walking navigation app for the United Kingdom, 26 US cities, two Canadian cities (Toronto and Vancouver), and Mexico City. The data controller is Minhaj Khan (an individual based in the State of New York, United States), referred to throughout this policy as "we," "us," or "SafeRoute."
Contact: minhaj@safe-route.app
This policy explains what personal information SafeRoute collects, why we collect it, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
02Scope
This policy applies to the SafeRoute iOS app, the optional SafeRoute Apple Watch companion, and the SafeRoute backend service that supports them. It does not cover third-party services that the app links out to (for example, the OpenStreetMap or Open Government Licence pages), which have their own privacy policies.
03Information we collect
SafeRoute is designed to collect as little personal information as possible. We do not require accounts, sign-in, or registration. We do not collect names, addresses, phone numbers, or payment information.
We process the following limited categories of data while you use the app:
Location data (GPS coordinates)
When you actively use SafeRoute to plan or follow a route, the app reads your device's GPS location. Coordinates are sent to our backend solely to compute walking routes and to retrieve crime context for your area. Coordinates are not stored against any persistent identifier on our servers.
Search queries
Text you type into the place-search box (for example, a destination name) is sent to our backend, which forwards it to Mapbox's geocoding service to turn it into a map location. We do not store your searches or link them to you.
Motion sensor data
If you use the SafeRoute Apple Watch companion, the watch reads device motion data on-device only, to detect off-route deviations. Motion data is not transmitted to our servers.
Technical request data
Our backend logs basic request metadata for security and abuse-prevention (request timestamps, IP addresses, response codes). Logs are retained for no more than 30 days and are not used to build a user profile.
Anonymous usage analytics
To understand which features are used and to catch performance problems, SafeRoute records a small number of anonymous, aggregate usage signals through TelemetryDeck, a privacy-focused, GDPR-compliant analytics provider. These signals carry an event name (for example, that a screen was opened or a route was found) and a small set of coarse, bucketed values describing what happened — how many routes were returned and whether the safest was low, moderate or high for reported incidents; a load-time band; a failure reason; how long a screen was open, to the nearest band; and a coarse region label (for example US, UK, Canada, or Mexico). They never include your search text, coordinates, addresses, routes, or contacts.
They are not, however, wholly identifier-free, and we would rather say so than imply otherwise. TelemetryDeck assigns each installation a pseudonymous client identifier, derived from the vendor identifier iOS gives us and hashed before it is stored. It is stable across sessions on the same device, which is what lets us tell one returning user from ten new ones. It is not your name, it is not shared with anyone, it cannot be reversed into your identity, it is reset if you delete and reinstall the app, and it is never combined with data from other companies. TelemetryDeck does not use advertising identifiers and does not track you across other apps or websites. You can turn this off at any time in the app under About → Anonymous analytics.
Beyond the anonymous analytics described above, SafeRoute uses no advertising identifiers and no cross-app trackers, and is configured with NSPrivacyTracking = false in its Privacy Manifest.
Where an install came from
We advertise SafeRoute on the App Store, and we need to know whether those ads work. On its first launch the app asks iOS for an attribution token using Apple's own AdServices framework and sends it to api-adservices.apple.com, which answers whether this install followed one of our Apple Search Ads. We keep two things from that answer: a single label — appleSearchAds or organic — and, where Apple supplies one, the numeric campaign identifier. Everything else Apple returns is discarded on the device.
This is Apple's own measurement API, not a third-party one. It does not use the advertising identifier (IDFA), it requires no App Tracking Transparency prompt, and it describes the advert rather than the person — so it is not tracking as Apple defines it. The resulting label is recorded as one analytics event, which means it carries the same pseudonymous client identifier described above, and it is silenced entirely if you have turned analytics off.
What is in your ears
To decide whether open-ear audio hardware is worth supporting, the app checks which kind of output your audio is currently routed to and records it as one of five broad categories: built-in speaker, wired, other Bluetooth, open-ear glasses, or other. The device's own name for that output — which is free text you may have personalised — is matched on the phone and discarded immediately. It is never stored, never logged and never transmitted; only the category leaves the device. SafeRoute requests no microphone access and records no audio.
04What we do not collect
To remove ambiguity, SafeRoute does not collect:
- Your name, email address, phone number, or postal address
- Your contacts, photos, calendar, or other on-device content
- Your device's advertising identifier (IDFA)
- Browsing history outside of SafeRoute
- Health data, biometrics, or financial information
- Any identifier that ties your activity to you — the analytics client identifier described in section 03 is per-installation and pseudonymous, and is never linked to a name, an account, or data from other companies
- Any identifier that follows you into other apps or websites
05Why we use this information
Under Article 13 UK GDPR, we are required to tell you why we process your data and the lawful basis we rely on. Our processing is grounded in the following bases under Article 6(1) UK GDPR:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Computing walking routes between origin and destination | GPS coordinates | Performance of a contract Art. 6(1)(b) — you cannot use a navigation app without sending coordinates to a routing service. |
| Showing crime context along candidate routes | Approximate area coordinates | Legitimate interests Art. 6(1)(f) — providing the crime-context feature you opened the app for. |
| Geocoding place searches | Search query text | Performance of a contract Art. 6(1)(b) |
| Off-route detection on the watch | Motion sensor (on-device only) | Performance of a contract Art. 6(1)(b) |
| Backend security, abuse prevention, rate limiting | Request metadata, IP address | Legitimate interests Art. 6(1)(f) — protecting the service from abuse. |
| Understanding which features are used, and catching failures | Bucketed event signals; a pseudonymous per-installation identifier | Legitimate interests Art. 6(1)(f) — improving a free safety app we cannot otherwise observe in use. You can withdraw at any time via About → Anonymous analytics, which stops the processing entirely. |
| Measuring whether our App Store adverts produced an install | An Apple attribution token; the resulting label and campaign id | Legitimate interests Art. 6(1)(f) — knowing whether money spent on advertising works. Apple's own API, no advertising identifier, no cross-app tracking; covered by the same analytics opt-out. |
We have considered the balancing test for each "legitimate interests" use and concluded that the limited processing involved is proportionate to a clear user-facing benefit. You can object to legitimate-interests processing at any time (see Section 9).
06Who we share your information with
To deliver the app, your data is processed by a small number of named third parties. We do not sell, rent, or monetise your data, and we share only what is necessary for each subprocessor's specific function.
| Subprocessor | What they receive | Purpose | Where |
|---|---|---|---|
| Mapbox, Inc. | Origin and destination coordinates, search queries | Walking-route directions; map tiles; geocoding | United States |
| OpenStreetMap Foundation (Overpass) | Approximate area coordinates only | Nearby safe-place lookups (Find Help) and street-lighting coverage along candidate routes | Germany (Europe) |
| data.police.uk (UK Home Office) | Bounding-box coordinates only | Public crime statistics retrieval (United Kingdom) | United Kingdom |
| NYC Open Data (City of New York / NYPD) | Bounding-box coordinates only | Public crime statistics retrieval (New York) | United States |
| US city open-data portals — each covered city's official municipal open-data portal (Chicago, San Francisco, Boston, Seattle, Philadelphia, Washington D.C., Denver, Los Angeles, San Diego, Long Beach, Dallas, Detroit, Baltimore, Memphis, Charlotte, Nashville, Minneapolis, Cleveland, Tucson, Fort Worth, Hartford, Kansas City, Houston, New Orleans, and Las Vegas; the respective city police departments) | Bounding-box coordinates only | Public crime statistics retrieval (covered US cities), including the live 911-dispatch datasets a city offers (New Orleans, San Francisco, Cleveland, Minneapolis, Detroit, Seattle, Las Vegas) | United States |
| Canadian police open data — Toronto Police Service (Public Safety Data Portal) and the Vancouver Police Department | Bounding-box coordinates only | Public crime statistics retrieval (Toronto, Vancouver) | Canada |
| Transport for London (TfL) — JamCam street-camera imagery for the London live-camera layer ("Powered by TfL Open Data") | Camera identifiers only — image and clip requests are made by our server, never by your device | Street-camera stills and short clips (London) | United Kingdom |
| City of Toronto — RESCU traffic-camera imagery via the city's open-data portal (Open Government Licence – Toronto) | Camera identifiers only — image requests are made by our server, never by your device | Street-camera stills (Toronto) | Canada |
| City of Vancouver — traffic-camera imagery via the city's open-data portal (Open Government Licence – Vancouver) | Camera identifiers only — image requests are made by our server, never by your device | Street-camera stills (Vancouver) | Canada |
| 511NY / New York State Department of Transportation — street- and highway-camera imagery for the New York live-camera layer | Camera identifiers only — image requests are made by our server, never by your device | Street-camera stills (New York) | United States |
| Nevada Department of Transportation (NVRoads 511) — street-camera imagery for the Las Vegas live-camera layer | Camera identifiers only — image requests are made by our server, never by your device | Street-camera stills (Las Vegas) | United States |
| Live camera video — streamed from the transport authority that operates the camera (Nevada DOT for Las Vegas; 511NY / NYSDOT for New York) | Your device's IP address, because live video is played directly by your device rather than relayed by our server. No account, identifier, or location is sent — only the address of the single camera you opened. We never see which camera you chose. A live stream cannot be cached, so relaying it through our server would add cost and delay without hiding anything more than the address itself; if you would rather not connect, do not open a camera — stills stay on the relayed path above. | Live street-camera video (Las Vegas, New York) | United States |
| Hoyo de Crimen (api.hoyodecrimen.com) — an independent open API that republishes the Mexico City public prosecutor's (Fiscalía General de Justicia, FGJ) open crime data | Point and radius coordinates only | Public crime statistics retrieval (Mexico City) | Internet (independently operated) |
| TelemetryDeck | Anonymous event & performance signals (no personal data; a pseudonymous per-installation client identifier — see section 03) | Anonymous usage analytics (opt-out in app) | Germany (EU) |
| Render Services, Inc. | All backend traffic (transit only) | Hosting our backend | Germany (Frankfurt) |
| Apple Inc. | App distribution; crash reports if you opted in; a first-launch Apple Search Ads attribution token (AdServices) | iOS / watchOS platform services | Various |
Each subprocessor handles your data under their own privacy policy. Mapbox and Render are subject to their own contractual data-protection terms with us. Apple's privacy practices are governed by their public privacy policy.
07International transfers
Because the data controller (Minhaj Khan) is based in the United States, your personal data is processed in the U.S. by us and by Mapbox. Our backend infrastructure runs in Germany.
The European Commission's adequacy decision recognises the UK as providing adequate data protection. There is no current adequacy decision for the United States, so transfers from the UK to U.S. subprocessors rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as applicable. We have conducted a Transfer Risk Assessment for transfers to U.S. subprocessors.
You can request a copy of the safeguards in place by emailing minhaj@safe-route.app.
08How long we keep your information
We keep your information only as long as necessary to provide the service:
- Live route requests: Coordinates are processed in memory only and are not persisted to disk on our servers.
- Backend cache: Public crime data and place-of-interest data fetched from upstream sources is cached on our servers for up to 24 hours to reduce upstream load. Cached data is keyed by area, not by user.
- Request logs: Retained for up to 30 days for security and rate-limiting purposes, then automatically deleted.
- On-device data: Your iPhone and Apple Watch retain locally cached map tiles and route history under your device's normal control. You can clear this at any time by deleting the app.
We do not retain any personally-identifying information about you on our servers, because we do not collect any.
09Your rights under UK GDPR
You have the following rights regarding your personal data. Because we hold no persistent identifiers tying you to specific records, some rights may be inapplicable in practice — but you can always invoke them and we will respond.
- Right of access (Art. 15): you can request a copy of any personal data we hold about you.
- Right to rectification (Art. 16): you can request correction of inaccurate data.
- Right to erasure (Art. 17): you can request deletion. (In practice, simply uninstalling the app removes any locally cached data.)
- Right to restrict processing (Art. 18).
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
- Right to object (Art. 21): you can object to processing based on legitimate interests at any time.
- Rights relating to automated decision-making and profiling (Art. 22A, as introduced by the Data (Use and Access) Act 2025): SafeRoute uses an algorithmic crime-exposure score to rank candidate walking routes. This is route ranking based on public data, not a decision made about you, and does not produce legal or similarly significant effects on you. Article 22A safeguards therefore do not apply, but you can disable the safety overlay in-app at any time.
To exercise any of these rights, email minhaj@safe-route.app with the words "Privacy request" in the subject line. We will respond within one calendar month.
10Children
SafeRoute is a general-audience navigation app. It is not directed at children under 13 and we do not knowingly collect any personal information from children under 13. SafeRoute may be downloaded and used by older minors (13–17) on their own devices; in that case, the same minimal data practices described in this policy apply.
In line with the "children's higher protection matters" duty added to the UK GDPR by the Data (Use and Access) Act 2025, we have considered the needs of minors who may use the app. SafeRoute does not contain advertising, in-app purchases, social features, profiling, or content unsuitable for minors. We do not target children with marketing.
11Security
We protect your data using:
- Transport security: All traffic between the app and our backend uses TLS 1.2 or higher. App Transport Security (ATS) is enforced.
- Authentication on backend endpoints: Our backend rejects unauthenticated requests; the auth key is shipped with the app, not entered by users.
- Rate limiting: All endpoints rate-limited per IP to prevent abuse.
- Minimal data collection: The strongest protection is data we never collect.
- No password storage: SafeRoute has no accounts, so we never store passwords.
- Server hardening: Our backend runs on Render's managed platform with automatic OS patching.
No system is 100% secure. If we ever became aware of a personal data breach affecting users, we would notify the ICO within 72 hours under Article 33 UK GDPR, and notify affected users without undue delay if the breach posed a high risk to their rights.
12Right to complain
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk/concerns
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would prefer the chance to address your concern first — please email minhaj@safe-route.app.
13Changes to this policy
We may update this policy from time to time, for example to reflect changes to our app, our subprocessors, or applicable law. Material changes will be reflected by an updated "Effective date" at the top of this document. Significant changes that introduce new processing purposes will be communicated through an in-app notice before the new processing begins.
The current version of this policy is always available at this URL.
14Contact
For privacy questions, data subject rights requests, or anything else covered by this policy:
Minhaj Khan
Email: minhaj@safe-route.app