Safpic

Privacy Policy

Draft — 31 July 2026
DRAFT — for review, not yet published
Before launch — to be confirmed: the legal identity of the operator (a registered company, or a named individual, with a postal address), the governing country/jurisdiction, and — for India — a named Grievance Officer with contact details. This draft uses "Safpic" as a placeholder for that operator.

This policy explains what information Safpic ("Safpic", "we", "us") collects, why, and the choices you have. We've tried to write it plainly. If anything is unclear, email support@safpic.com.

The short version

Information we collect

Account information. To create an account you provide a phone number or an email address (including via Google sign-in), and you choose a username. You may optionally add a profile photo and a short bio.

Your content. Messages and protected photos you send are end-to-end encrypted — they are stored only in encrypted form that we cannot open. We hold this encrypted content, and basic delivery information (such as which conversation a message belongs to and when it was sent), so the service can work across your devices.

Device & usage data. To keep the app working and secure, we process technical data such as app version, a device notification token (to deliver notifications), and diagnostic/crash reports.

Approximate location. For your security, the "active sessions" screen shows the approximate city a sign-in came from. This is estimated from the network (IP) address — we do not collect precise GPS location.

Finding contacts (optional). If you choose to find friends from your contacts, matching is done using encrypted one-way hashes — your actual phone numbers are not uploaded or stored.

What we cannot see

By design, we cannot read your end-to-end encrypted chats or your protected photos. If you turn on Backup & Recovery, your backup is protected by a passphrase that only you know — if you forget it, not even we can restore that content. This is a deliberate trade-off in favour of your privacy.

How we use information

Who we share it with

We use Google Firebase (Google Cloud) as our infrastructure provider to run authentication, storage, databases, notifications and crash reporting on our behalf. They process data under their own security and privacy commitments. We do not sell your personal data, and we do not share your private content with advertisers.

Before launch — to be confirmed: the full list of third-party processors and the data-storage region, and any legally required data-transfer disclosures.

Reports and safety

If someone reports a message or photo, we retain the report and any evidence they choose to attach for a limited period (currently up to 90 days) so we can review it, after which it is automatically deleted.

Retention and deletion

You can delete your account at any time from Settings. Deleting your account removes your profile, messages, stored media and related data from our systems. Some limited records may be retained where required for legal or security reasons.

Your choices

Before launch — to be confirmed: a full statement of your legal rights (for example under India's DPDP Act or GDPR, as applicable) and how to exercise them, including the Grievance Officer contact.

Children

Safpic is intended for adults and is not directed to anyone under 18. We do not knowingly collect information from children.

Security

We use end-to-end encryption for chats and protected photos, encryption of data at rest on your device, and access controls on our servers. No system is perfectly secure, but protecting your content is the core of how Safpic is built.

Changes to this policy

We may update this policy as the app evolves. We'll revise the date at the top and, where changes are significant, let you know in the app.

Contact

Questions about privacy? Email support@safpic.com.

Reminder: this is an accurate first draft based on how the app works, but it has not been reviewed by a lawyer. It should be professionally reviewed — and the placeholders above filled in — before Safpic is offered to the public.