← GeoSafe
Privacy policy

Your zones are security context, not identity.

Last updated September 2026 · Issued under the ADGM Data Protection Regulations 2021

This policy explains what personal data GeoSafe Holdings Ltd ("GeoSafe", "we") collects when you use the GeoSafe app and website, why, and the rights you have. We have written it to be read, not skimmed. The short version: we collect as little as a security product can, we never ask who you are, and we never track where you are.

1. Who is responsible

The controller of your personal data is GeoSafe Holdings Ltd, a company registered in Abu Dhabi Global Market (ADGM), Abu Dhabi, United Arab Emirates. Contact: [email protected].

2. What we collect, and why

  • Email address — if you join early access or write to us. Used to send the App Store link, respond to you, and tell you about material changes to the service. Basis: consent (early access) and our legitimate interest in answering you. You can withdraw at any time by replying "stop".
  • Device and push token — an anonymous identifier for your phone and a notification token, so we can deliver withdrawal requests to the phone you registered. Basis: performance of our contract with you.
  • Public wallet address and Vault contract address — needed to connect your wallet and show your Vault. These are public on the blockchain by their nature. Basis: performance of our contract.
  • Location, at the moment you act — when you approve a withdrawal or set a Safe zone, your phone checks its position. The check runs on your device. GeoSafe receives the result of the check (inside or outside a zone), not a stream of your movements. Your zones are held on your phone and never stored by GeoSafe in readable form; the app shows them as "Safe zone 01, Safe zone 02", never as an address. Basis: performance of our contract, and the location permission you grant iOS, which you can revoke in Settings at any time.
  • App diagnostics — crash reports and basic usage events (screens opened, errors), so we can fix bugs. These do not include location, amounts or addresses. Basis: legitimate interest in keeping the app working. You can disable diagnostics in the app.

3. What we do not collect

  • No name, government ID, date of birth, phone number or photograph. GeoSafe has no KYC and no identity check.
  • No background location. Location is read only at the moment you tap, never while the app is closed.
  • No zone names, addresses or map history. Lock-screen alerts show no amount, address or location.
  • No private keys, seed phrases or PINs. Your phone's key never leaves its secure hardware.
  • No advertising identifiers, no advertising trackers, no sale of data — ever.

4. Data on the blockchain

Your Vault is a smart contract on a public blockchain. Transactions to and from it, and the contract's own settings, are public and permanent by design, and are not controlled by GeoSafe. Nothing recorded on-chain by GeoSafe reveals your zones in readable form. Please treat your wallet and Vault addresses as public information.

5. Who we share data with

We use a small number of processors under contract: Apple (push notifications and App Store distribution), our hosting and infrastructure provider, and our email provider for early-access and support mail. Wallet connections are made through WalletConnect, and your chosen wallet's own privacy policy applies to it. We do not share personal data with anyone else unless the law requires it, and we will tell you if it does unless we are prohibited from doing so.

6. International transfers

Our processors may store data outside ADGM, including in the European Union, the United Kingdom and the United States. Where data leaves ADGM we rely on the safeguards permitted by the Data Protection Regulations 2021, including contractual clauses that give your data equivalent protection.

7. How long we keep it

We keep personal data for as long as we need it for the business purposes described above, and delete it when we no longer do. Data recorded on the blockchain is permanent and outside our control.

8. Security

Your phone's key lives in the device's secure hardware and is protected by Face ID or your PIN. Communication with our servers is encrypted in transit. Access to our systems is limited to named staff under confidentiality obligations. No system is perfect; if a breach affects you, we will tell you without undue delay and notify the ADGM Commissioner of Data Protection within 72 hours as the Regulations require.

9. Your rights

Under the ADGM Data Protection Regulations 2021 you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to our processing, to receive it in a portable form, and not to be subject to a decision based solely on automated processing that significantly affects you. GeoSafe makes no such automated decisions: every withdrawal is decided by you. To exercise a right, email [email protected]; we will respond within one month. You may also complain to the ADGM Office of Data Protection (Commissioner of Data Protection) at adgm.com.

10. Changes

If we change this policy in a way that matters, we will tell you in the app and by email before it takes effect. Earlier versions are available on request.