SafeMyPhone privacy policy
Last updated: July 21, 2026
SafeMyPhone is an owner-controlled Android anti-theft and recovery application. Install and configure it only on a phone you own or are explicitly authorized to manage.
Data SafeMyPhone may handle
Depending on the features and permissions you enable, SafeMyPhone may process:
- Account data such as email address, password hash, authentication tokens, private recovery key, and app-PIN hash.
- Recovery evidence such as front- or back-camera photos captured after an enabled security event.
- Location coordinates, accuracy, event time, map links, and last-known or newly requested location when Android permits.
- Device and event information including manufacturer, model, Android version, battery state, network state, installation identifier, and trigger type.
- SIM/subscription information available through Android, such as carrier, slot, country, and change status.
- Protection settings, account backup data, alert history, remote-lock commands, and Google Play subscription entitlement status.
The microphone is used locally only when the owner starts Find Phone clap listening. Clap audio is not saved or uploaded by the current app version.
Why the data is used
Data is used to detect enabled security events, prepare recovery evidence, notify the owner, synchronize pending alerts, restore account settings, verify private recovery access, perform owner-requested commands, provide purchased features, prevent abuse, and maintain service security. SafeMyPhone does not sell personal data or use recovery evidence for advertising.
Permissions and background operation
Camera, location, notification, phone-state, microphone, foreground-service, boot, and device-administrator capabilities are requested only for the features described in the app. Some enabled protection actions may run while the app is not visible. Android displays required system permission screens and foreground-service notifications. Permissions can be revoked in Android Settings, and protection features can be disabled in SafeMyPhone.
Storage and transfer
Evidence may first be stored locally on the protected phone. When internet access is available, enabled alerts may be transmitted over HTTPS to SafeMyPhone servers and associated with the verified account, installation, or hashed recovery key. Sensitive credentials are stored as hashes where verification permits. Google Play processes subscription payments; SafeMyPhone receives purchase tokens and entitlement status, not full payment-card details.
Sharing
Data is shared only with service providers needed to operate hosting, email delivery, Google Play Billing, and owner-requested map or sharing actions; when required by law; or when the owner deliberately shares evidence through Android. Recovery results require owner credentials. Service providers may process data only for their contracted purpose.
Retention
Account data, backups, alert records, and uploaded evidence are retained while the account is active or as needed to provide recovery services. Local history is limited by the app. Operational logs may be retained for a limited period for security and troubleshooting. Data may be retained longer only where legally required, necessary to prevent fraud or abuse, or needed to resolve a transaction.
Deletion and user controls
Signed-in users can open Help → Account → Privacy and your data → Permanently delete my account. This deletes the account and associated server-side backups, alerts, evidence files, devices, commands, tokens, and entitlement records. Local recovery data is also cleared. Google Play subscriptions must be cancelled separately in Google Play.
You can also request deletion without the app through the SafeMyPhone account deletion page.
Optional website analytics
Website analytics remains off until you choose “Allow analytics.” When allowed, SafeMyPhone records aggregate counts for page visits and interactions such as CTA clicks, guide use, recovery-tool starts and completions, downloads, scroll milestones, and internal links. Reports use only the page path without its query string, a constrained event name, content category, coarse device and traffic-source classes, and a new-or-returning class stored locally after consent.
For consented sessions, SafeMyPhone records the page title and path, referral category, IP address, approximate country, region and city, device class, new-or-returning status, session times, clicks, form-action counts and event counts. The IP address is also sent over HTTPS to the IPWho geolocation service for approximate location resolution. Session records and IP addresses are retained for up to 30 days; longer-term reports contain aggregated counts. IP-derived locations are approximate and are not GPS locations. Analytics does not collect recovery answers, recovery keys, passwords, GPS coordinates, IMEI or serial numbers, email addresses, phone numbers, or form contents. Declining does not prevent use of the website or recovery tools. You can reopen the analytics choice by clearing this site's local storage and reloading the page.
Security and children
SafeMyPhone uses HTTPS, access tokens, hashed verification values, private recovery credentials, and restricted evidence lookup. No system is perfectly secure, so owners should keep their PIN and private key secret. SafeMyPhone is not directed to children and must not be used to monitor another person without authorization.
Contact
For privacy questions or data requests, email support@safemyphone.com or visit Support.
Scan to install
SafeMyPhone on Google Play