We don't collect your data.
SafeShare and the other DeepHumane Labs apps run on your device. There is no account and no cloud storage of your content. The apps do make a small number of network connections — we list every one of them below, because a privacy policy that says "none" when the answer is "three, and here they are" isn't worth reading.
The short version. No accounts. No analytics, no advertising, no tracking. Your documents and records stay in an encrypted vault on your phone — we hold no copy, so there is nothing on our side to collect, leak, or hand over. The network surfaces that do exist carry either nothing of yours, or content we cannot read.
Who we are. DeepHumane Technologies Private Limited, Bengaluru, Karnataka, India, is the data controller (Data Fiduciary) for these apps. Grievance Officer (India, DPDP): Manu Jose — manu@deephumane.tech. We acknowledge every grievance and respond within 90 days.
What the apps do with data — on your device
SafeShare stores the documents you capture or import in an encrypted vault on your device (AES-256; keys held in your device's secure hardware). On-device machine learning classifies documents, warns you about personal information before you share, and powers search. All of this happens on your device; the models ship inside the app.
What leaves your device
Your documents, the records your assistant keeps, what the on-device AI worked out about them, and your activity log are never sent to us. We run no analytics, no advertising and no tracking.
When you share a document, the watermarked copy is handed to the app you choose through the operating system's standard share mechanism — from that point the receiving app's privacy practices apply. We never see it, and we cannot recall it.
There are exactly three network surfaces in these apps. Here they are:
- The DeepHumane share relay — used only if you send an enforced share to another DeepHumane user. In the app as shipped this is present but dormant: it carries traffic only where a relay address is configured, which our development and test builds do and yours does not; with none configured the same share is routed entirely inside your phone. When it is active it carries a sealed, encrypted envelope addressed to a mailbox identifier derived from a one-way hash of the recipient's phone number. The relay cannot decrypt it — sealing and opening happen on the two devices. It can see that an envelope of a certain size arrived for a certain hashed mailbox at a certain time, and it holds it for at most 14 days.
- The recipient check — whether a phone number belongs to a DeepHumane user. Also dormant in this release (a fixed on-device list stands in for it). When it is active it sends a one-way hash of the number, never the number itself. No recipient profile and no contact list is stored, by the app or by us.
- Google's on-device text recognition (Android only). Reading text out of your documents runs locally on your phone using Google's bundled ML Kit. That component ships with a Google Play library that reports Google's own SDK diagnostics, and it is the reason the Android app has internet permission at all. We do not call it and we pass it none of your content.
What we collect: nothing
- We hold no accounts, identifiers, usage analytics or telemetry.
- We cannot access, restore or recover your vault. If you lose your device or delete the app, we cannot recover your documents — keep your own backups of anything irreplaceable.
- Data-access or deletion requests: there is nothing on our side to provide or erase; your data is under your direct control on the device (view, export, or delete it in-app or by deleting the app).
Diagnostics. The apps can capture your phone's own diagnostic reports (crashes, performance) to help us fix faults. This ships off — it is a choice you make, not a default we set. Switch it on and the reports are written to the app's private storage on your device, excluded from backups, listed in the app's Privacy screen and capped in number: there is no code path that uploads them. Switch it off and capture stops.
Permissions
- Camera (SafeShare, iOS): to scan documents you choose to capture. Never used without your action. On Android, SafeShare asks for no camera permission at all — it hands you to your phone's own camera app.
- Notifications (both apps, Android): to remind you locally before a document expires, and to tell you that something needs you. These notices carry a category and a count, never content.
- Microphone and speech recognition (Control): only while you hold the mic to ask a question. Recognition runs on your phone.
- Contacts and Face ID (Control, optional): for a local "My Agent" shortcut and for unlocking. Nothing is dialled and no number is stored.
- On Android, the installed app also carries internet, network-state, wake-lock and boot-completed permissions. We do not declare these: they arrive inside the Google and AndroidX components the app is built on (see the third surface above). We list them because your phone will show them to you and you deserve to know why they are there.
Children
The apps are general-audience tools and collect no data from anyone, including children.
Security
Vault contents are encrypted at rest with keys in device secure hardware. Our engineering pipeline enforces a "no-egress" gate over our own code: a build fails if networking code is introduced outside the surfaces listed above. That gate checks the code we write, not the third-party components we build on — which is why those are listed by name rather than hidden behind the gate. To report a vulnerability, write to contact@deephumane.tech or see security.txt.
Changes
Future versions may add optional connected features (for example, cross-device sync with an account). Any such feature will be opt-in and disclosed here before it applies to you.
Contact
Privacy questions and data requests: contact@deephumane.tech. Security reports: contact@deephumane.tech.
Your rights
You have rights over your personal data under India's DPDP Act and, where they apply, the GDPR and the CCPA. We honour them the only way that is honest for an app of this shape:
- Access and portability: everything we could give you is already on your device, and both apps export it. We hold no copy to add to it.
- Correction, erasure, restriction, objection: exercised directly in the app — edit, delete one item, or erase everything. There is no server-side record for us to change.
- Withdrawing consent takes effect immediately, because the processing is on your device.
- Nominee (DPDP §14): you may nominate someone to exercise your rights on your behalf — write to the Grievance Officer.
- Complaints: write to the Grievance Officer first. If you are not satisfied you may complain to the Data Protection Board of India; EU/UK users may complain to their supervisory authority.
No automated decision-making produces legal or similarly significant effects about you.
This policy is issued by DeepHumane Technologies Private Limited under its designated legal owner and Grievance Officer, effective as dated above. If any position here changes, this page and its effective date will be updated before the change applies to you. DeepHumane Labs is an initiative of DeepHumane Technologies Private Limited · Bangalore, India.