Privacy Policy
Policy version: ALPHA_2_8_5_DRAFT_2026_09_15
SafeReport is designed so private reports and public safety information are different records. This page explains the privacy rules used during Alpha development and legal-review deployment.
What SafeReport collects
SafeReport may collect report details, contact information you choose to provide, information about the Person Being Reported, evidence, case activity, staff review records, security events, and technical records needed to operate and protect the service. Technical records can include network and device information supplied automatically during a connection, even when a reporter chooses not to provide a name or contact information.
Reporting without contact information
A reporter may choose not to provide contact information. SafeReport should not describe that choice as a guarantee of complete technical anonymity because hosting, security, authentication, or network systems may process limited technical records needed to operate and protect the service.
Why the information is used
Information is used to receive and review reports, resolve identity, identify repeated factual patterns, manage evidence, contact a reporter when permitted, protect the service, keep audit history, handle corrections, and prepare sanitized public information when publication rules are met.
Private and public information are separate
Original reports, reporter identity, private narratives, private evidence, access codes, internal identifiers, and staff notes are not public search fields. Public search reads from separate sanitized display records after required review and publication controls are satisfied.
Photos, evidence, and metadata
Evidence and Person Being Reported photos are stored as private case material. Files can contain technical metadata. SafeReport limits routine access to authorized staff with appropriate case access and audits evidence viewing. Person photos do not automatically confirm identity and are not public through the evidence system.
Security and service providers
SafeReport uses third-party service providers for functions such as authentication, hosting, storage, and infrastructure. Access to private data is limited by role and workflow controls. No system can promise absolute security, but SafeReport uses access controls, private storage, audit logging, rate limiting, and security monitoring to reduce risk.
Retention, legal holds, and corrections
SafeReport keeps case and audit information according to its approved retention rules and legal obligations. Records that would otherwise be eligible for deletion may need to be preserved when a valid legal hold applies. A correction request does not automatically delete private case records or audit history. Public information may be suppressed while a material challenge is re-checked.
Legal requests and emergency disclosures
SafeReport may preserve or disclose information when required by valid legal process or when otherwise permitted by applicable law. Legal requests and emergency disclosures are subject to documented review, minimization, and audit procedures rather than the public correction process.
Do not share reporter information
Reporter identity and private case information are not provided to the Person Being Reported through the public correction process. SafeReport may disclose information when legally required or when otherwise permitted by law and the final attorney-reviewed policy.