UntilSafe Privacy Policy
Privacy for a scheduled check-in aid.
Effective and last updated August 27, 2026
This Privacy Policy explains how UntilSafe, a BrightByte Apps product, collects, uses, discloses, retains, and deletes information. It covers the UntilSafe mobile app, scheduled check-in service, trusted-contact flow, public website, and support. UntilSafe is intended only for adults age 18 or older in the United States.
Information UntilSafe collects
- Account and eligibility: display name, verified mobile number, authentication identifier, 18+ confirmation, consent versions and timestamps, settings, and notification preferences.
- Check-in plan: scheduled and expected-end times, time zone, a manually entered meeting-place description, a first name or alias for the person being met, plan state, keypad result, and related timestamps.
- Trusted contact: name or label, verified mobile number, invitation and consent status, revocation status, and communication-delivery history.
- Device, security, and diagnostics: push token, platform, app version, hashed installation or attestation information, IP-derived rate-limit signals, security events, diagnostic information, and bounded error details.
- Communications: telephone numbers, Twilio call or message identifiers, timestamps, duration, delivery status, and whether a keypad response was accepted. UntilSafe does not store private PINs in plain text.
- Purchases: RevenueCat app-user identifier, product, store, entitlement status, and purchase, expiration, refund, or revocation events. Apple or Google processes payment-card information.
- Support: the content of messages a person chooses to send to the support email address.
- Optional website waitlist: email address, app interest, separate 18-or-older confirmation, permission to send the requested store link and essential waitlist messages, the submitter’s separate optional choice about broader development and product emails, consent versions and timestamps, and ordinary form-delivery metadata. Broader marketing consent is not required to join the waitlist, buy, or use UntilSafe.
Information UntilSafe does not access
- No GPS or background-location access. A meeting place is collected only when the user types it and may be precise if the user chooses to enter a precise place.
- No microphone permission, speech recognition, call recording, transcript, voiceprint, or spoken-code-word analysis. Automated calls use fixed prompts and telephone-keypad entries.
- No camera, photo library, device address book, call log, SMS inbox, advertising identifier, or cross-app tracking.
- No photograph of the person being met and no payment-card number.
How information is used
UntilSafe uses information to authenticate accounts, verify consent, schedule the check-in requested by the user, deliver operational communications, notify an accepted trusted contact when the fixed plan calls for it, verify paid access, enforce the 10-check-in limit, prevent abuse, troubleshoot delivery, answer support requests, send requested waitlist or product emails, and comply with law.
UntilSafe does not sell personal information, use plan or outcome information for targeted advertising, or use it to train a general-purpose artificial-intelligence model. A waitlist email address is not connected to a check-in plan merely because an adult joins the list.
Service providers and other recipients
- Supabase provides phone authentication, database storage, server functions, scheduling records, and security controls.
- Twilio delivers verification texts and operational text and voice calls. Twilio necessarily processes telephone numbers, fixed message or prompt content, keypad input, and delivery metadata. UntilSafe does not ask Twilio to record calls.
- Expo, Apple Push Notification service, and Google Firebase Cloud Messaging deliver generic device notifications and process push tokens and delivery metadata.
- RevenueCat verifies subscription entitlements and processes an app-user identifier and purchase status. Apple and Google provide app distribution and process store purchases.
- Netlify hosts the public website and related request infrastructure. Google processes email sent to the published support address.
- An accepted trusted contact may receive the user’s display name, scheduled time, manually entered meeting-place description, and a neutral request to contact the user. UntilSafe does not accuse the person being met or claim an emergency occurred.
Information may also be disclosed when legally required or reasonably necessary to protect the service, its users, or another person.
Retention
- After a plan closes or is canceled, the meeting alias, meeting-place text, and trusted-contact link are scheduled for redaction after 24 hours. The remaining closed plan and operational job records are scheduled for deletion after 30 days.
- A pending trusted-contact invitation link expires after 48 hours. Expired pending invitations are scheduled for deletion.
- An inactive push token is scheduled for deletion after 90 days. Expired rate-limit records are deleted after their security window ends.
- Security audit events and provider-webhook receipts may be retained for up to one year. A minimal one-way hashed deletion receipt may be retained to document a completed request.
- Account, current trusted-contact, consent, and entitlement records remain while the account or relationship is active. Minimal consent or opt-out evidence may be kept as needed to honor and document communication preferences.
Apple, Google, Twilio, RevenueCat, Supabase, Expo, Netlify, mobile carriers, and email providers may retain records under their own policies and legal duties. Backup copies expire on the applicable provider’s normal rolling schedule.
Security
UntilSafe uses safeguards designed for the information it handles, including encrypted network connections, authentication, access controls, row-level database rules, one-way PIN hashing, rate limits, webhook verification, app-attestation controls, data minimization, and audit records. No system is perfectly secure, and communications can still be delayed, blocked, or fail.
Choices and deletion
A user can cancel an unstarted plan, manage notification permission, restore or cancel a store subscription, replace a trusted contact, and permanently delete the UntilSafe account in Settings. To prevent a deletion from interrupting a check-in or trusted-contact notification, every open plan must first be canceled or finished and every pending delivery must finish. Account deletion then removes the active account, plans, contact connection, push tokens, PIN credentials, quota, and entitlement record from the application database.
Deleting an UntilSafe account or the app does not cancel Apple or Google billing. Cancel the subscription separately in the store. A person who cannot access the app may start a verified deletion or privacy request at Delete UntilSafe data or by email.
A trusted contact can revoke consent through the invitation flow, through the UntilSafe user, or by replying STOP to a supported text. Any open plan that depends on that contact is canceled and UntilSafe attempts to notify the account owner by push and text.
An adult on the optional website waitlist can withdraw either email permission using the unsubscribe option in an email or ask support to delete the waitlist record. Without the optional broader marketing choice, UntilSafe may send only the requested store link and essential messages needed to administer that waitlist request. Withdrawing consent does not affect app access or a store purchase.
Children
UntilSafe is not directed to anyone under 18 and does not knowingly permit minors to create accounts. Contact support if you believe information from a minor was submitted.
Changes
UntilSafe may update this policy when practices, providers, or legal requirements change. The updated date will change, and additional notice or consent will be provided when required.
Contact
Email lillilkidssongs@gmail.com with privacy questions or requests. Do not include a PIN, one-time verification code, full meeting plan, or another person’s private information in email.