Privacy policy

This policy covers the SafeSpotter iPhone app and this website. It is written to be read, not to be survived.

Last updated 5 August 2026 · App version 1.1

The short version

SafeSpotter has no account and no developer server. What you write stays on your iPhone, and — only if you switch sync on — in your own private iCloud database. There are no analytics, no crash-reporting SDKs, no advertising and no trackers. The developer cannot see your items.

1. What is collected

Nothing. SafeSpotter does not ask you to create an account, does not ask for your email address, and contains no analytics, attribution, advertising or crash-reporting SDKs. No usage data, device identifier or diagnostic report is sent to the developer.

Apple may share aggregate App Store statistics and, separately, anonymised crash or usage data with the developer if you opted into sharing analytics with app developers in iOS Settings. That flow belongs to Apple, is anonymised by Apple, and never contains the contents of your items.

2. Where your data lives

Everything you type — item names, categories, places, rooms, containers, exact spots, private notes, reminder settings and any photos you attach — is written to the app's own storage on your device, and is available offline.

If you turn on Sync with iCloud in Settings, the same records are also stored in your private iCloud database through Apple's CloudKit, so they appear on your other devices signed in to the same Apple Account. Item details are stored in encrypted CloudKit fields, and photos as encrypted CloudKit assets. That database belongs to your Apple Account. The developer has no access to it and no server of their own that receives your content.

3. Turning iCloud sync on and off

Sync is optional and reversible. Turning it off copies your items into a local-only store on that iPhone and stops further synchronising. Turning it back on merges local additions, edits and deletions with what is already in iCloud, keeping the most recent change for each item.

Copies that were already synchronised are intentionally retained in your iCloud account when you switch sync off, so that re-enabling it does not lose anything. To remove them, delete the items in the app while sync is on, or remove SafeSpotter's iCloud data from your Apple Account settings.

4. Face ID and passcode

The optional app lock uses Apple's LocalAuthentication framework. Matching happens inside the Secure Enclave on your device; the app receives only a success or failure result and never has access to your face or fingerprint data. Authentication is requested when you tap Unlock — never silently in the background.

5. Photos

Attaching a photo uses the system PhotosUI picker, so the app sees only the image you pick — not your library. Photos are resized and stripped of metadata before being saved. They stay on the device when sync is off, and travel as encrypted CloudKit assets when sync is on.

6. Notifications

Check-in reminders are local notifications scheduled on your device. Their text never contains the item's name or location. When iCloud sync is enabled, CloudKit uses silent push messages to tell the app that something changed; these carry no content of yours and are never used for marketing.

7. This website

This site sets no cookies, runs no analytics and loads no third-party resources — fonts, images and scripts are all served from this domain. It is hosted on GitHub Pages, whose servers keep standard web logs (including IP addresses) as part of delivering the page; that processing is GitHub's, described in the GitHub Privacy Statement.

Your theme choice (dark or light) is remembered in your browser's local storage. It never leaves your browser.

8. Deleting your data

Deleting an item in the app removes it, and its photo, from the device — and from your iCloud database when sync is on. Deleting the app removes its local store from that iPhone. If you had sync enabled, remove SafeSpotter's iCloud data from your Apple Account settings to clear the cloud copy as well.

There is nothing for the developer to delete on request, because the developer holds nothing.

9. Children

SafeSpotter is rated 4+ and is not directed at children specifically. It collects no personal data from anyone, of any age.

10. Changes

If this policy changes, the updated version is published on this page with a new date, and material changes are noted in the App Store release notes. There is no mailing list to notify, because there are no email addresses.

11. Contact

Questions about this policy are welcome at mattioli.simone.10@gmail.com, or through the support page.