Privacy Policy
Effective date: 4 August 2026
OSSafe Assistant ("the App", "we", "us") provides overseas safety check-in, safety maps and AI safety consultation for international students and their parents. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights. By using the App you agree to the practices described below.
1. Data We Collect
- Account information. When you register we collect your email address, password (stored only as a salted hash), your role (student or parent), display name, and timezone. Student accounts may additionally store university, home address text and home coordinates. Email is encrypted at rest.
- Safety check-in records. When you check in we store the timestamp and method (manual, widget or geo-fence). Check-in records do not include GPS coordinates.
- Trip Guardian (location sharing). When you actively start a Trip Guardian, with your explicit consent, we record the destination, the consent event (user id, consent time, IP address) and receive approximate GPS positions roughly once per hour while the trip is active. Trip data is automatically deleted after 30 days.
- AI consultation content. When you ask a safety question, the text is sent to our AI provider (DeepSeek) to generate an answer. We do not store conversation history.
- User-generated markers. When you submit a community marker on the map, we store the marker category, description and location.
- Device information. To send push notifications we store your device push token and platform.
- Purchase information. Subscription status and expiry are stored to manage your membership. Payment itself is processed by Apple through the App Store.
- Referral information. If you use or provide a referral code, we store the referral relationship and accumulated bonus days.
2. How We Use Your Data
- To provide check-in status and daily/weekly safety reports to the parent you have bound.
- To show your safety score card, campus safety map and crime data around your university.
- To answer your AI safety questions and generate reports.
- To send push notifications you have opted into (check-in reminders, check-in notifications, reports).
- To manage subscriptions and the referral reward program.
- To detect and prevent abuse (e.g. duplicate-account reward abuse).
3. Legal Bases (GDPR / UK GDPR)
Where the GDPR applies, we process personal data on the following bases:
- Contract performance — providing the services you requested (account, check-in, reports, binding).
- Consent — Trip Guardian location sharing, push notifications, and community markers. You may withdraw consent at any time in the App or device settings.
- Legitimate interests — fraud and abuse prevention, and security of the service.
- Legal obligations — where we are required by law.
4. Sharing and Third Parties
We do not sell your personal data. We share data only as needed to operate the service:
- Apple — App Store distribution, in-app purchases and push notification delivery (APNs).
- DeepSeek — AI answer generation. Your question text is transmitted to their API and processed by the third-party AI provider in accordance with its own privacy policy.
- OpenStreetMap / Nominatim — geocoding addresses into coordinates.
- Amazon Web Services (Lightsail) — hosting of our servers and database.
- Public safety data providers — we display public crime/news data from data.police.uk, NYPD, LAPD, TfL, and news RSS feeds. These are public data sources, not your personal data.
5. Data Retention
- Trip Guardian location data: 30 days, then automatically deleted.
- Account data: retained while your account is active, or until you request deletion.
- Community markers: removed automatically after their display period (6 hours for unrest-type, 3 days for infrastructure-type), or earlier upon reports of inaccuracy.
6. Your Rights
Depending on your jurisdiction (e.g. GDPR, CCPA/CPRA, PIPEDA, or China's PIPL), you may have the right to:
- Access and obtain a copy of your personal data.
- Correct inaccurate data.
- Delete your account and all associated data — you can initiate account deletion in the App; we complete deletion of all personal data within 48 hours.
- Restrict or object to processing, and withdraw consent at any time.
- Data portability, where applicable.
To exercise these rights, contact us using the details in Section 8. We respond within applicable legal timeframes.
7. Security
We protect data with industry-standard measures including encryption in transit (TLS), encryption at rest for personal data (email addresses), hashed passwords, restricted server access and a single-VPS deployment in the United States. No method of transmission or storage is 100% secure, but we work to maintain appropriate safeguards.
8. Contact
For any privacy questions, requests or complaints, contact us at:
Email: pength@yeah.net
9. Changes to This Policy
We may update this Policy from time to time. The "Effective date" at the top reflects the latest revision. Material changes will be notified through the App.