Travel Safety
How the App collects and uses your information
Application: Travel Safety
Provider / Data Controller: Forfutdinov Volodymyr Viktorovych, an individual entrepreneur registered in Kharkiv, Ukraine ("we", "us", "Provider")
Contact: support@travelsafety.app
Registered address: Serpova str, 4a, apt.84, Kharkiv, Ukraine
This Privacy Policy explains how we collect, use, and share information when you use the Travel Safety mobile application (the "App").
Travel Safety is an informational reference tool and is not an emergency service. This Policy describes data handling only; it does not change the disclaimers in our Terms of Use. The App does not transmit your location to emergency services and cannot summon help.
If you grant location permission, the App uses your device location to detect your current country (and, where relevant, region) so it can show locally relevant emergency numbers and embassy or consulate contacts. Location is accessed only while the App is in use (foreground), never in the background.
Your coordinates are processed on your device: the country is determined using your operating system's geocoding service or, offline, a data set bundled with the App. Your precise coordinates are not sent to our servers and are not used to summon help.
During onboarding the App shows a screen explaining why location is used before requesting the system permission, and you can skip it — the App is fully usable by selecting a country manually. If you skipped that step, the App may ask once via the standard system permission dialog when country detection first runs. You can change or revoke location permission at any time in your device settings.
If you create an account or contact us, we process information such as your email address, your password (stored only in hashed form by our authentication provider), and basic profile details — for example your home country / country of citizenship, saved destinations, and the content of feedback or support messages you send. We use this to provide account features and respond to your requests.
We use Sentry for crash and error reporting and basic performance diagnostics. Reports may include device and app information such as device model, operating system version, app version, language, time zone, crash logs, and error diagnostics. Crash reports are not linked to your account identity by us. Session replay is not used. In addition, our infrastructure providers (such as our backend host) process IP addresses transiently in server logs for security and delivery purposes.
We do not intentionally collect special categories of personal data (such as health data); please do not send such data to us. The App does not record your phone calls. The automated systems we use to compile public reference content (including AI/LLM-based extraction) operate on public source websites only and are not given your personal data.
Our public website uses Google Analytics 4 to measure how the pages are used (for example which sections visitors read and which download links they select). Analytics cookies are set only after you accept them in the cookie banner; until then, and if you decline, no analytics cookies are stored and measurement is limited to aggregated, cookieless signals. You can change or withdraw your choice at any time through the "Cookies" control in the website footer, which also removes the analytics cookies already set. The App itself does not use advertising or cross-site tracking cookies.
We use information to: detect your country and display relevant emergency and embassy/consulate information; provide core features such as manual country selection, saved destinations, and offline pre-loading of reference data; operate, secure, and improve the App and fix errors; respond to support requests; and comply with legal obligations and enforce our Terms.
Where the EU or UK GDPR applies, we rely on: consent — for location access (granted through the system permission, withdrawable at any time in device settings); contract — to provide the App and account features you request; consent — for website analytics cookies (given and withdrawable through the cookie banner and footer control); legitimate interests — for crash reporting, error diagnostics, security, and abuse prevention, balanced against your rights; and legal obligation — where processing is required by law.
We do not sell your personal data. We share information only with service providers that process it on our behalf as processors, under data-processing agreements and only on our instructions, and with authorities where required by law. Our processors currently include:
Separately, our server-side content pipeline uses AI/LLM providers (a locally hosted model and, as fallbacks, providers such as Anthropic, OpenRouter, or OpenAI) solely to extract publicly available embassy and emergency information from public source websites. These providers process public source content only and never receive your personal data.
Your information may be processed in countries other than where you live, including outside the EEA and the UK — in particular by our processors listed above and by the Provider in Ukraine. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses (and the UK equivalents), together with the safeguards implemented by our processors.
We keep personal data only as long as necessary for the purposes described here and to comply with legal obligations. Account data is retained until your account is deleted (see Section 7); accounts inactive for 24 months may be deleted or anonymized earlier. Diagnostics and crash data is kept for up to 12 months, then deleted or retained only in aggregated form. Data stored only on your device (such as cached reference data) remains until you delete it or uninstall the App.
You can request deletion of your account at any time:
Deletion works as follows: your account is immediately deactivated and scheduled for deletion, followed by a 30-day grace period during which you can cancel the deletion by signing back in (via email recovery). If you do not sign back in, your account and associated personal data are permanently deleted at the end of the grace period, and we confirm by email. Residual copies may persist in encrypted backups for a limited additional period before being overwritten in the normal backup cycle. We may retain limited information where required for legal, security, or fraud-prevention purposes.
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to restrict or object to processing, and to withdraw consent at any time. EEA/UK users may lodge a complaint with their local supervisory authority. To exercise your rights, contact support@travelsafety.app. You can also control location permission in your device settings.
If you are in California, the CCPA gives you similar rights to know, delete, and correct your personal information. We do not sell personal information and do not share it for cross-context behavioral advertising. Exercising your rights will not result in different treatment.
The App is intended for adults and is not directed to anyone under 18 (see our Terms of Use). It is not listed in Google Play's Designed for Families program or Apple's Kids Category. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
We use reasonable technical and organizational measures to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We may update this Privacy Policy from time to time; the "Last updated" date reflects the latest version, which is available in the App. Material changes will be highlighted in the App.
For any privacy questions or requests: support@travelsafety.app. Provider: Forfutdinov Volodymyr Viktorovych, individual entrepreneur, Serpova str, 4a, apt.84, Kharkiv, Ukraine.