Data Safety

Last updated: 21 July 2026

Data Safety

Last updated: 21 July 2026

SafeCase is built for people in sensitive situations. Protecting your data is central to everything we do. This page explains how your information is kept safe.

🚨

If you are in immediate danger

SafeCase is an organisational tool. It is not designed for emergencies. If you are in immediate danger, please do not rely on this app.

Call 000 — Police, Ambulance or Fire

You can also contact relevant authorities, a crisis service, or a trusted person for support.

At a Glance

Account Authentication

SafeCase uses Firebase Authentication to verify user identities and help prevent unauthorised access to accounts.

Encrypted in Transit & at Rest

All data sent between SafeCase and Firebase is encrypted using TLS. Data stored on Firebase servers is encrypted at rest.

Strict Owner-Only Access

Firebase Security Rules ensure that only your authenticated account can read or write your data through the app. No other SafeCase user can access your files, cases, or audit logs.

Never Sold

Your personal information and case data are never sold, rented, or traded to third parties.

You Control Your Data

You can request deletion of your account and associated data through the Settings screen.

Audit Logging

Key actions within your account are automatically logged and stored privately in your account.

All File Types Accepted

SafeCase accepts file types such as photos, videos, audio, PDFs, documents, spreadsheets, and more.

1. How We Protect Your Data

SafeCase uses Google Firebase for authentication, data storage, and processing. Firebase provides:

  • Firebase Authentication to verify account ownership and secure user access.
  • TLS (Transport Layer Security) encryption for all data in transit between your device and Firebase servers.
  • Encryption at rest for data stored on Firebase infrastructure.
  • Firebase Firestore Security Rules and Firebase Storage Security Rules to restrict access by authenticated user ID.
  • Google's physical and network security for data centre infrastructure.
  • Backup and redundancy systems designed to reduce the risk of data loss.

Users should still maintain their own independent backups of important files, evidence, and case information.

2. Access Controls — What the Rules Actually Enforce

SafeCase uses Firebase Authentication and Firebase Security Rules to strictly control who can access what. Here is what those rules are designed to enforce:

Firestore (database):

  • Cases — only the user whose ID matches the case's ownerId field can read, create, or update their cases.
  • Case ownership — users cannot transfer or overwrite case ownership through the app.
  • Evidence and incidents — only the owner of the parent case can read or write evidence and incident records within it.
  • Journal entries — only the owner of the parent case can read or write journal entries.
  • Audit logs — only the authenticated account holder can read or write their own audit log entries through the app.
  • User profile — only you can read your own user document. You may only update safe profile fields such as display name, first name, last name, and email — not subscription status.
  • Subscription status — the subscriptionActive field can only be set by trusted server-side processes after payment is verified. You cannot modify it yourself through the app.
  • Feedback (bug reports, suggestions) — signed-in users can submit feedback, but users cannot read feedback submitted by others through the app.

Firebase Storage (files):

  • Evidence files — stored at a path that includes your user ID. Only your authenticated account can read or write your evidence files through the app.
  • Bug report screenshots — only the user who uploaded a screenshot can read or write that screenshot through the app.
  • User files — files stored under your user ID can only be read or written by your authenticated account through the app.
  • Everything else — denied by default.

SafeCase administrators do not routinely access or review user case data. Backend access is restricted and used only where reasonably necessary for security, maintenance, legal obligations, or technical support.

3. What Data Is Stored

The following data may be stored within SafeCase:

  • Account details — name and email address.
  • Authentication data — email address and authentication identifiers required to verify account ownership.
  • Plan access data — information used to determine whether your account is on the Free Plan or Premium.
  • Subscription status — whether you have an active Premium subscription, set by our payment system or trusted server-side processes only.
  • Case files — documents, photos, audio recordings, videos, and any other evidence you upload.
  • Case notes, incidents, journal entries, and records you create within the app.
  • Audit logs — a record of key actions taken within your account.
  • App preferences — Incognito Mode and Quick Exit settings, stored locally on your device only.

We do not collect financial card details, precise location data, or device contacts.

4. Where Your Data Is Stored

SafeCase is an Australian application, however Firebase (Google) infrastructure may store your data on servers located outside Australia, including in the United States. Google maintains data processing agreements and complies with applicable privacy obligations.

By using SafeCase, you consent to this cross-border transfer for the purpose of delivering the service to you.

5. Audit Logging

SafeCase logs the following actions within your account:

  • Login and logout events.
  • Account creation and deactivation.
  • Profile updates (name).
  • Evidence created, updated, or deleted.
  • Evidence linked to or unlinked from incidents.
  • Privacy setting changes (Incognito Mode, Quick Exit).
  • Case exports generated.
  • Feedback or bug reports submitted.

These logs are stored in your account data and are accessible only to your authenticated account through the app. They are not sold, rented, traded, or used for advertising.

6. Local Device Storage

Your privacy preferences — Incognito Mode and Quick Exit — are stored locally on your device using shared preferences. This data is not uploaded to Firebase and exists only on your device. Uninstalling the app will remove this local data.

7. A Note on Recordings & Evidence

SafeCase can store recordings and other evidence you create. Please be aware that storing something here does not guarantee it will be accepted by a court or relied upon in any legal matter.

Recording laws and evidence admissibility

Recording laws vary across Australian states and territories, and not all stored material will be admissible in legal proceedings. SafeCase does not guarantee any legal outcome. For full details, please read our Privacy Policy and Terms of Service. If you have questions about your specific situation, we encourage you to consult a qualified legal practitioner.

8. Keeping Your Account Safe

You play an important role in keeping your account secure:

  • Use a strong, unique password that you do not use elsewhere.
  • Enable Quick Exit and Incognito Mode if you are in a sensitive or high-risk situation.

While Quick Exit and Incognito Mode are designed to improve privacy and discretion, they cannot guarantee personal safety or prevent monitoring by third parties.

  • Set a PIN lock for an additional layer of security.
  • Log out of the app when using a shared or public device.
  • Keep independent backups of important evidence and case material.
  • Contact us immediately at [email protected] if you suspect your account has been compromised.

9. Security Incidents

In the unlikely event of a data breach that affects your personal information, SafeCase will notify affected users as required under the Australian Notifiable Data Breaches (NDB) scheme, administered by the Office of the Australian Information Commissioner (OAIC).

10. Data Retention & Deletion

Your data is retained for as long as your account is active. If you deactivate or delete your account through Settings, your account and associated data will be scheduled for deletion. Some data may be retained for a limited period after account deletion where reasonably necessary to meet legal obligations, resolve disputes, maintain security, or enforce our Terms of Service, after which it is permanently deleted.

11. Age and Young Users

SafeCase is intended for users aged 16 years and older. It is not directed to children under the age of 16. Users under 18 should review the Terms of Service and Privacy Policy with a parent, guardian, or other responsible adult where appropriate.

12. Contact Us

For data safety questions or to report a suspected security issue:

[email protected]

For data breach complaints: Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

SafeCase is an organisational tool only and does not provide legal advice. Firebase/Google may process and store data internationally. SafeCase complies with the Australian Privacy Act 1988 and the Notifiable Data Breaches scheme.