CarrySafe
Get early accessPortal access

Privacy

The short version: CarrySafe holds what it needs to answer the question you asked, does not build a picture of where you go, does not sell anything about you, and hands you a delete button that actually deletes.

What the CarrySafe app deliberately does not do

  • No tracking across other companies' apps or websites. No advertising identifier, no data broker. This is a statement about the app. This website measures ad campaigns, with your consent and never before it — see “This website, advertising, and cookies” below.
  • No location history. Coordinates leave your phone only to answer an explicit lookup such as nearby records, boundary checks, restricted-place queries or route planning, and are not kept as a trail on your account.
  • No continuous background GPS. The optional background warning service hands iOS a small set of circular regions and lets the system do the watching; it does not sample or upload GPS and does not make background network calls.
  • No microphone or audio collection in this release. The app does not request microphone access, record a voice turn or transmit audio.
  • No data sales.
  • No map telemetry. It is switched off in the app.
  • No advertising in this release. Sponsored placements are disabled in both the app and the database. If that ever changes, the privacy manifest, the App Store answers and the published policy have to change first.

This website, advertising, and cookies

We run ads for CarrySafe, and we measure whether they work. If you accept, this website loads measurement tags from Google (Google Ads and Google Analytics), which set cookies and tell those companies that a browser arriving from one of our ads reached this site.

  • You are asked first, and denied is the default. Google Consent Mode is set to denied for advertising and analytics storage before anything loads, and the Meta pixel is not requested from Meta at all until you accept.
  • Declining costs you nothing. Every page, every word and every link behaves identically. There is no feature behind the banner.
  • There is no legal data to leak. This website is a set of static files. It holds no map, no records, no statuses and no account — so there is nothing here about what you looked up for these tags to receive, because the lookups do not happen here.
  • Your answer is stored on your device, in this browser's local storage, so you are not asked on every page. Clearing site data asks you again.
  • We do not sell or share this for money. What we receive back is aggregate campaign reporting.

To change your mind, clear this site's data in your browser and answer the banner again. Browser-level tracking-protection settings and the platforms' own controls — Google Ads settings and Meta ad preferences — work independently of anything we do here.

What it holds, and why

Third-party services receive data only for a feature you choose to use: Apple handles Sign in with Apple and App Store purchases, and Mapbox answers requested search and routing. The rows below state what is sent and why; the full policy of record covers retention and each provider in detail.

DataWhy
Email address, and a display name if you set oneSigning in, and nothing else.
Home state, and the free preview's bound municipalityDeciding which map area your account opens. Asked, never guessed.
Permit details you type inThe wallet card, renewal reminders, and permit-aware recognition. Includes fields such as permit number, dates, issuing authority and physical descriptors — because that is what a permit contains.
Private permit files added by earlier beta versionsKept private to your account, and removed with it.
Precise coordinates, at the moment of a lookupNearby-rule, boundary-crossing and restricted-place queries. The coordinate is used for the requested answer and is not retained as a location history.
Route places you enter, or your current location when you explicitly choose it as the originSent through our server to Mapbox Geocoding and Mapbox Directions, and not saved to your CarrySafe account. Operational request logs are kept for the shortest practical period and are never repurposed for analytics or advertising.
Purchase state from AppleThe StoreKit product, the transaction-to-account binding, environment, status, entitlement and expiry. Never your payment card — Apple collects that and we never receive it.
User content, community reports and blocksRunning the community surfaces and moderating them.
Carry ModeA device-local choice, shared with Siri and Shortcuts on that iPhone. It does not cross accounts.
Limited diagnosticsAn allowlisted failure code, app version and time, plus a random support reference. No raw exceptions, no stack traces, no location, no permit, no route, no device identifier. Kept 30 days and shown to staff as counts.

Partner applications

  • The customer app does not accept partner, publisher or FFL applications. Those applications use the separate authenticated website portal and its disclosed intake; contextual FFL markers in the app are not a customer directory.

Deletion

  • Profile → Account → Delete account removes your CarrySafe data: permit details, alerts, memberships, reports, follows, blocks and subscription links. Private permit files are removed from storage before the database record goes, and the deletion refuses to complete while any private file remains.
  • Public business or legal content you contributed may remain, with your attribution removed.
  • Sign-in is shared with other products from the same publisher. The global sign-in identity is removed only when no other product still holds data for it; otherwise only your CarrySafe account, data and session go.
  • Deleting the account does not cancel Apple billing. Cancel the subscription with Apple separately.

The background-warning opt-in, stated exactly

It is off unless you turn it on. Turning it on requires Always Location, Precise Location, notifications and Background App Refresh. iOS then monitors a small, rotating set of regions built from a cache on your phone, refreshed while the app is open.

Contact us with privacy questions or data requests

Email support@hyda.studio. For the full text — retention periods, legal bases, and the complete list of declared data types — read the policy of record.