Privacy Policy
Last updated September 24, 2026. SafetyKit is built for parents. This policy explains what we collect, why, and the controls you have.
Who we are
SafetyKit is operated by People In Tech LLC (“we”). We provide an app and website that help parents and guardians understand and reduce online risks to their children. We are the data controller for the information described here. Email hello@safetykit.app for privacy requests, or see the Contact page.
Children
SafetyKit is for adults. We do not knowingly allow anyone under 18 to create an account, and the app is not directed at children. The information you enter about your child (a nickname, an age band, and any usernames, emails or phone numbers you choose to add) is provided by you as their parent or legal guardian. We never ask for a child's legal name, date of birth, photo, school or location. If you believe a child has created an account, contact us and we will delete it.
What we collect
- Account. Your email and, if you share it, your name, from Sign in with Apple or email sign-in. You can use Apple's Hide My Email.
- Household. Child nicknames and age bands, the devices and apps you say are in your home, the identifiers you add for checks, and the co-parents or viewers you invite.
- Conversations and checks. What you ask SafetyKit, the results of checks, and screenshots or photos you upload for analysis. These stay in your account so you can revisit them.
- Usage and diagnostics. Which features you use, crash reports and performance data, collected through Sentry and PostHog with identifiers limited to your account id and plan.
- Purchases. Your subscription and credit-pack status from Apple or Google via RevenueCat. We never see your card details.
- Voice. If you use Live voice mode, your microphone audio is streamed to our speech provider (Google) for the length of the conversation so it can listen and reply. We do not record or store the audio. The on-screen transcript is kept for that session only, and anything the assistant looks up is saved like any other check.
- Notifications. A device push token if you turn alerts on.
How checks work
When you run a check, the specific identifier you entered (for example a username, link, email or phone number) is sent to the relevant public service and to one of our AI model providers (Anthropic or Google) to write the plain-English explanation. Services we use include Have I Been Pwned (email leaks), Google Web Risk (link safety), Shodan (what is visible about your home connection), a licensed registry data provider where configured (registered offenders), the Apple App Store (app ratings), public DNS and domain registries (RDAP), OpenStreetMap (place names), and the public profile pages of the sites we check usernames against. We do not send your name or your child's name with a check. Photos you upload are analysed for visible location clues and stored privately in your account until you delete them.
People who are not SafetyKit users
This is the part of the policy most privacy notices skip, and it matters most here. When you run a check you often hand us information about someone else: the person messaging your child, the profile you pasted, the number that keeps calling. Those people never agreed to anything with us, so we limit what happens to their information.
- What we do. We take the single identifier you typed, send it to the relevant public source, and return what is already publicly visible. We do not build a profile of that person, we do not enrich it with other sources, and we do not keep a searchable index of people across accounts.
- Why we are allowed to. Our legal basis is legitimate interests: protecting a child from harm is a recognised interest, the data is already public, and we use the least information needed to answer one question. We have weighed this against the other person's rights, which is why the Acceptable Use policy forbids using SafetyKit on adults who are not a safety concern, and why the assistant declines those requests.
- How long we keep it. A check result lives in your conversation history so you can revisit it, and in an audit row so misuse can be traced. Delete the conversation and the result goes; delete your account and it all goes within 30 days.
- If you are that person. Anyone has the right to ask what we hold about them, to object to it, and to have it deleted. Contact us and we will search our records and respond within 30 days. Because we index by the account that ran a check and not by the person checked, we may need enough detail to find it. We may decline where responding would expose a child or a parent to risk, which is a recognised exemption, and we will say so if we do.
- Where the notice is. Data protection law expects people to be told when their information is processed. Telling the person you are checking would often defeat the child-safety purpose and could put a child at risk, so we rely on the exemption for that and publish this section instead.
Registry results deserve a specific note: sex offender registry information is published by government agencies for public safety. We pass it through, we do not add to it, and using it to harass or discriminate against anyone is both a breach of our Acceptable Use policy and a crime in most states.
Why we process it (legal bases)
- To provide the service you asked for (performance of a contract).
- To keep the service secure, rate-limited and free of abuse (legitimate interests).
- To send optional alerts and the monthly briefing (consent, which you can withdraw in Account).
- To comply with law and respond to lawful requests (legal obligation).
- To answer a check about someone who is not a user, where protecting a child is the purpose and the data is already public (legitimate interests, described above).
What we don't do
- We don't sell or share personal information for advertising, and we show no ads.
- We don't monitor your child's messages, track their location, or access their accounts. SafetyKit only uses information that is already public plus what you tell it.
- We don't train AI models on your conversations, and our model providers are used on paid business terms that prohibit training on your data.
Who we share with (subprocessors)
Supabase (database, authentication and file storage), Vercel (hosting and AI gateway), Anthropic and Google (the AI models that write answers; which one handles a message depends on the question), Google (also the speech model behind Live voice mode, and Web Risk for link checks), RevenueCat (subscriptions and credit packs), Apple and Google Play (sign-in, payments, push), Expo (app updates and crash-free launch statistics), Sentry (crash reporting), PostHog (product analytics), Upstash (rate limiting), and the public check services listed above. Each receives only what it needs for its function. Our AI and speech providers are used on paid business terms that prohibit training on your data.
Retention
Your data is kept while your account is active. Deleting a conversation, child profile or photo removes it immediately. Deleting your account removes all data within 30 days, except billing records we must keep for tax and fraud purposes and anonymised aggregate statistics.
Your rights
Wherever you live, you can access, correct, export and delete your data from within the app. If you are in the EU, UK, California or another region with privacy law, you also have the right to object to or restrict processing, to data portability, and to complain to your supervisory authority. We do not discriminate for exercising these rights. Contact us to exercise any right we have not automated.
Security
Data is encrypted in transit and at rest. Sessions are stored in the device keychain. Access to production data is limited to staff who need it, and every check is logged to the account that ran it.
International transfers
Our providers process data in the United States and the EU under standard contractual clauses or equivalent safeguards.
Changes
We will tell you in the app before any change that reduces your rights takes effect.
Contact
Privacy questions and requests: see the Contact page. We answer within 30 days.