SAFEROUTE // CRIME-AWARE WALKING NAVIGATOR · UK·US·CA·MX

// LEGAL · PRIVACYPrivacy Policy

Effective
6 June 2026
Updated
4 September 2026
Controller
Minhaj Khan
Contact
minhaj@safe-route.app

01Who we are

SafeRoute is a crime-aware walking navigation app for the United Kingdom, 26 US cities, two Canadian cities (Toronto and Vancouver), and Mexico City. The data controller is Minhaj Khan (an individual based in the State of New York, United States), referred to throughout this policy as "we," "us," or "SafeRoute."

Contact: minhaj@safe-route.app

This policy explains what personal information SafeRoute collects, why we collect it, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.

02Scope

This policy applies to the SafeRoute iOS app, the optional SafeRoute Apple Watch companion, and the SafeRoute backend service that supports them. It does not cover third-party services that the app links out to (for example, the OpenStreetMap or Open Government Licence pages), which have their own privacy policies.

03Information we collect

SafeRoute is designed to collect as little personal information as possible. We do not require accounts, sign-in, or registration. We do not collect names, addresses, phone numbers, or payment information.

We process the following limited categories of data while you use the app:

Location data (GPS coordinates)

When you actively use SafeRoute to plan or follow a route, the app reads your device's GPS location. Coordinates are sent to our backend solely to compute walking routes and to retrieve crime context for your area. Coordinates are not stored against any persistent identifier on our servers.

Search queries

Text you type into the place-search box (for example, a destination name) is sent to our backend, which forwards it to Mapbox's geocoding service to turn it into a map location. We do not store your searches or link them to you.

Motion sensor data

If you use the SafeRoute Apple Watch companion, the watch reads device motion data on-device only, to detect off-route deviations. Motion data is not transmitted to our servers.

Technical request data

Our backend logs basic request metadata for security and abuse-prevention (request timestamps, IP addresses, response codes). Logs are retained for no more than 30 days and are not used to build a user profile.

Anonymous usage analytics

To understand which features are used and to catch performance problems, SafeRoute records a small number of anonymous, aggregate usage signals through TelemetryDeck, a privacy-focused, GDPR-compliant analytics provider. These signals carry an event name (for example, that a screen was opened or a route was found) and a small set of coarse, bucketed values describing what happened — how many routes were returned and whether the safest was low, moderate or high for reported incidents; a load-time band; a failure reason; how long a screen was open, to the nearest band; and a coarse region label (for example US, UK, Canada, or Mexico). They never include your search text, coordinates, addresses, routes, or contacts.

They are not, however, wholly identifier-free, and we would rather say so than imply otherwise. TelemetryDeck assigns each installation a pseudonymous client identifier, derived from the vendor identifier iOS gives us and hashed before it is stored. It is stable across sessions on the same device, which is what lets us tell one returning user from ten new ones. It is not your name, it is not shared with anyone, it cannot be reversed into your identity, it is reset if you delete and reinstall the app, and it is never combined with data from other companies. TelemetryDeck does not use advertising identifiers and does not track you across other apps or websites. You can turn this off at any time in the app under About → Anonymous analytics.

Beyond the anonymous analytics described above, SafeRoute uses no advertising identifiers and no cross-app trackers, and is configured with NSPrivacyTracking = false in its Privacy Manifest.

Where an install came from

We advertise SafeRoute on the App Store, and we need to know whether those ads work. On its first launch the app asks iOS for an attribution token using Apple's own AdServices framework and sends it to api-adservices.apple.com, which answers whether this install followed one of our Apple Search Ads. We keep two things from that answer: a single label — appleSearchAds or organic — and, where Apple supplies one, the numeric campaign identifier. Everything else Apple returns is discarded on the device.

This is Apple's own measurement API, not a third-party one. It does not use the advertising identifier (IDFA), it requires no App Tracking Transparency prompt, and it describes the advert rather than the person — so it is not tracking as Apple defines it. The resulting label is recorded as one analytics event, which means it carries the same pseudonymous client identifier described above, and it is silenced entirely if you have turned analytics off.

What is in your ears

To decide whether open-ear audio hardware is worth supporting, the app checks which kind of output your audio is currently routed to and records it as one of five broad categories: built-in speaker, wired, other Bluetooth, open-ear glasses, or other. The device's own name for that output — which is free text you may have personalised — is matched on the phone and discarded immediately. It is never stored, never logged and never transmitted; only the category leaves the device. SafeRoute requests no microphone access and records no audio.

04What we do not collect

To remove ambiguity, SafeRoute does not collect:

05Why we use this information

Under Article 13 UK GDPR, we are required to tell you why we process your data and the lawful basis we rely on. Our processing is grounded in the following bases under Article 6(1) UK GDPR:

Purpose Data used Lawful basis
Computing walking routes between origin and destination GPS coordinates Performance of a contract Art. 6(1)(b) — you cannot use a navigation app without sending coordinates to a routing service.
Showing crime context along candidate routes Approximate area coordinates Legitimate interests Art. 6(1)(f) — providing the crime-context feature you opened the app for.
Geocoding place searches Search query text Performance of a contract Art. 6(1)(b)
Off-route detection on the watch Motion sensor (on-device only) Performance of a contract Art. 6(1)(b)
Backend security, abuse prevention, rate limiting Request metadata, IP address Legitimate interests Art. 6(1)(f) — protecting the service from abuse.
Understanding which features are used, and catching failures Bucketed event signals; a pseudonymous per-installation identifier Legitimate interests Art. 6(1)(f) — improving a free safety app we cannot otherwise observe in use. You can withdraw at any time via About → Anonymous analytics, which stops the processing entirely.
Measuring whether our App Store adverts produced an install An Apple attribution token; the resulting label and campaign id Legitimate interests Art. 6(1)(f) — knowing whether money spent on advertising works. Apple's own API, no advertising identifier, no cross-app tracking; covered by the same analytics opt-out.

We have considered the balancing test for each "legitimate interests" use and concluded that the limited processing involved is proportionate to a clear user-facing benefit. You can object to legitimate-interests processing at any time (see Section 9).

06Who we share your information with

To deliver the app, your data is processed by a small number of named third parties. We do not sell, rent, or monetise your data, and we share only what is necessary for each subprocessor's specific function.

Subprocessor What they receive Purpose Where
Mapbox, Inc. Origin and destination coordinates, search queries Walking-route directions; map tiles; geocoding United States
OpenStreetMap Foundation (Overpass) Approximate area coordinates only Nearby safe-place lookups (Find Help) and street-lighting coverage along candidate routes Germany (Europe)
data.police.uk (UK Home Office) Bounding-box coordinates only Public crime statistics retrieval (United Kingdom) United Kingdom
NYC Open Data (City of New York / NYPD) Bounding-box coordinates only Public crime statistics retrieval (New York) United States
US city open-data portals — each covered city's official municipal open-data portal (Chicago, San Francisco, Boston, Seattle, Philadelphia, Washington D.C., Denver, Los Angeles, San Diego, Long Beach, Dallas, Detroit, Baltimore, Memphis, Charlotte, Nashville, Minneapolis, Cleveland, Tucson, Fort Worth, Hartford, Kansas City, Houston, New Orleans, and Las Vegas; the respective city police departments) Bounding-box coordinates only Public crime statistics retrieval (covered US cities), including the live 911-dispatch datasets a city offers (New Orleans, San Francisco, Cleveland, Minneapolis, Detroit, Seattle, Las Vegas) United States
Canadian police open data — Toronto Police Service (Public Safety Data Portal) and the Vancouver Police Department Bounding-box coordinates only Public crime statistics retrieval (Toronto, Vancouver) Canada
Transport for London (TfL) — JamCam street-camera imagery for the London live-camera layer ("Powered by TfL Open Data") Camera identifiers only — image and clip requests are made by our server, never by your device Street-camera stills and short clips (London) United Kingdom
City of Toronto — RESCU traffic-camera imagery via the city's open-data portal (Open Government Licence – Toronto) Camera identifiers only — image requests are made by our server, never by your device Street-camera stills (Toronto) Canada
City of Vancouver — traffic-camera imagery via the city's open-data portal (Open Government Licence – Vancouver) Camera identifiers only — image requests are made by our server, never by your device Street-camera stills (Vancouver) Canada
511NY / New York State Department of Transportation — street- and highway-camera imagery for the New York live-camera layer Camera identifiers only — image requests are made by our server, never by your device Street-camera stills (New York) United States
Nevada Department of Transportation (NVRoads 511) — street-camera imagery for the Las Vegas live-camera layer Camera identifiers only — image requests are made by our server, never by your device Street-camera stills (Las Vegas) United States
Live camera video — streamed from the transport authority that operates the camera (Nevada DOT for Las Vegas; 511NY / NYSDOT for New York) Your device's IP address, because live video is played directly by your device rather than relayed by our server. No account, identifier, or location is sent — only the address of the single camera you opened. We never see which camera you chose. A live stream cannot be cached, so relaying it through our server would add cost and delay without hiding anything more than the address itself; if you would rather not connect, do not open a camera — stills stay on the relayed path above. Live street-camera video (Las Vegas, New York) United States
Hoyo de Crimen (api.hoyodecrimen.com) — an independent open API that republishes the Mexico City public prosecutor's (Fiscalía General de Justicia, FGJ) open crime data Point and radius coordinates only Public crime statistics retrieval (Mexico City) Internet (independently operated)
TelemetryDeck Anonymous event & performance signals (no personal data; a pseudonymous per-installation client identifier — see section 03) Anonymous usage analytics (opt-out in app) Germany (EU)
Render Services, Inc. All backend traffic (transit only) Hosting our backend Germany (Frankfurt)
Apple Inc. App distribution; crash reports if you opted in; a first-launch Apple Search Ads attribution token (AdServices) iOS / watchOS platform services Various

Each subprocessor handles your data under their own privacy policy. Mapbox and Render are subject to their own contractual data-protection terms with us. Apple's privacy practices are governed by their public privacy policy.

07International transfers

Because the data controller (Minhaj Khan) is based in the United States, your personal data is processed in the U.S. by us and by Mapbox. Our backend infrastructure runs in Germany.

The European Commission's adequacy decision recognises the UK as providing adequate data protection. There is no current adequacy decision for the United States, so transfers from the UK to U.S. subprocessors rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as applicable. We have conducted a Transfer Risk Assessment for transfers to U.S. subprocessors.

You can request a copy of the safeguards in place by emailing minhaj@safe-route.app.

08How long we keep your information

We keep your information only as long as necessary to provide the service:

We do not retain any personally-identifying information about you on our servers, because we do not collect any.

09Your rights under UK GDPR

You have the following rights regarding your personal data. Because we hold no persistent identifiers tying you to specific records, some rights may be inapplicable in practice — but you can always invoke them and we will respond.

To exercise any of these rights, email minhaj@safe-route.app with the words "Privacy request" in the subject line. We will respond within one calendar month.

10Children

SafeRoute is a general-audience navigation app. It is not directed at children under 13 and we do not knowingly collect any personal information from children under 13. SafeRoute may be downloaded and used by older minors (13–17) on their own devices; in that case, the same minimal data practices described in this policy apply.

In line with the "children's higher protection matters" duty added to the UK GDPR by the Data (Use and Access) Act 2025, we have considered the needs of minors who may use the app. SafeRoute does not contain advertising, in-app purchases, social features, profiling, or content unsuitable for minors. We do not target children with marketing.

11Security

We protect your data using:

No system is 100% secure. If we ever became aware of a personal data breach affecting users, we would notify the ICO within 72 hours under Article 33 UK GDPR, and notify affected users without undue delay if the breach posed a high risk to their rights.

12Right to complain

If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

We would prefer the chance to address your concern first — please email minhaj@safe-route.app.

13Changes to this policy

We may update this policy from time to time, for example to reflect changes to our app, our subprocessors, or applicable law. Material changes will be reflected by an updated "Effective date" at the top of this document. Significant changes that introduce new processing purposes will be communicated through an in-app notice before the new processing begins.

The current version of this policy is always available at this URL.

14Contact

For privacy questions, data subject rights requests, or anything else covered by this policy:

Minhaj Khan
Email: minhaj@safe-route.app