GenesisCipher Labs

HomeSafe Privacy Policy

Last updated: July 24, 2026

GenesisCipher Labs (“we”, “us”) builds HomeSafe, a route-choice and location-sharing aid for five Indian metros (Delhi NCR, Mumbai, Bengaluru, Pune, Hyderabad). HomeSafe is currently distributed on the Indian App Store only. Privacy is the architecture, not a footnote: HomeSafe runs on your device and we do not operate a server that receives your location, routes, contacts, or trips. This policy explains exactly what is processed, where it goes, and the rights you have under India’s Digital Personal Data Protection Act, 2023 (DPDP Act).

HomeSafe is decision support, not a guarantee of safety, and it never contacts emergency services for you. See our Terms & Emergency Services Disclaimer.

The short version

Who is the data controller

GenesisCipher Labs is the controller for the limited processing described here. Because almost all processing happens on your device, your device — and the platform providers below acting as processors — do most of the work. Contact for privacy questions, data-rights requests, and grievances (including the grievance contact required under the DPDP Act): genesiscipherlabs@gmail.com.

Data Where it is processed Why Lawful basis (DPDP Act)
Precise location (GPS) On your device Plan and score routes, determine day/night, show the map, reverse-geocode the area name, detect off-route drift and arrival during a trip Your consent via the iOS location permission, for the specified purpose for which you voluntarily provided the data
Trusted contacts (name, phone) On your device Only to open your system Messages composer when you choose to share your location Your consent / the specified purpose you voluntarily provided the data for
Trip journal, recent places, saved Home/Work On your device Convenience and your private history (never uploaded) The specified purpose you voluntarily provided the data for
Community safety reports (category, coordinate, time, plus the opaque creator identifier Apple stamps on every public record) Apple public CloudKit Warn other users about on-ground conditions (poor lighting, waterlogging, no transport, etc.); the creator identifier lets the app count distinct authors on device, so repeat submissions from one person cannot manufacture agreement Your consent each time you submit
The optional note you may add to a report On your device Your own reminder of what you saw. It is not published — see below The specified purpose you voluntarily provided the data for
Guardian Live-Link (live coordinate, ETA, distance, score, transport, destination label) Apple public CloudKit, keyed by a per-trip unguessable token; viewed by your recipient in any browser at genesiscipher-labs.github.io/track/ Let a person you trust watch you reach your destination, without needing the app, only while a trip is active Your specific consent each trip — minted only when you tap Share live and send the iMessage; location data deleted on arrival (a brief, non-locating “arrived” marker remains), the whole record on stop/end; sharing stops after 6 hours
Optional motion data On your device Detect pace mismatch / wandering for the optional Drink-Safety mode Your consent via the iOS motion permission
Speech, when you tap the mic button in the AI Bestie chat On your device Transcribe what you say into a typed question for the Bestie Your consent via the iOS microphone and speech-recognition permissions

The mic is used only while you hold the mic button in the Bestie chat. Speech is transcribed on your device using Apple’s on-device speech recognition; the audio is never recorded, never stored, and never uploaded, and the transcription stays on your device like the rest of your Bestie conversation. If on-device speech recognition is not available, the mic button is not shown.

We do not process special-category data, we do not profile you for advertising, and we do not make solely-automated decisions producing legal effects. Safety scores are heuristics shown to you for your own decision; they are not a judgment about you.

Who else receives data (processors and third parties)

Those three — Apple, the Overpass host, and Open-Meteo — are our only third-party recipients. There are no advertising SDKs, no analytics SDKs, and no data brokers.

The Guardian Live-Link is opt-in, per trip, and built around three guarantees:

The recipient can only watch — there is no reverse channel from the link back to you.

Community reports, moderation, and defamation

Community reports are public by design — a poorly-lit corner one person flags should warn the next person. To keep them safe and lawful:

Where requests are processed

Apple’s MapKit, reverse-geocoding, and CloudKit services run on Apple infrastructure that may be located outside India; the public Overpass endpoint is similarly run by a third party that may be located outside India. Those transfers are made directly between your device and the respective provider under their own terms — we do not receive, store, or re-transfer your data on our own servers, and we do not initiate any additional cross-border transfer.

Retention

Your rights

Under the DPDP Act, you can access, correct, update, erase, and grieve the processing of your personal data, and withdraw consent at any time. We will respond without undue delay and in any case within the timelines required by the Act once it is notified.

How to exercise them — most data never leaves your device, so you are in direct control:

Children

HomeSafe is not directed to children. We do not knowingly process the personal data of a child without verifiable parental consent as required by the DPDP Act. If you believe a child has used the app, contact us and we will help you delete the data (which, being on-device, you can also clear directly).

Security

Data on your device is protected by iOS app sandboxing and device encryption. Community reports in CloudKit are secured by Apple. Because we hold no central database of your personal data, there is no company server for an attacker to breach. If a security issue affecting users’ data ever arises, we will notify affected users and the Data Protection Board of India without undue delay, consistent with the DPDP Act.

Changes

We will update this page when our practices change and revise the “Last updated” date. Material changes that affect on-device data handling are also reflected in the in-app terms you accept.

Contact

GenesisCipher Labs — genesiscipherlabs@gmail.com

This policy describes HomeSafe’s actual on-device behaviour. It is provided in good faith and should be reviewed by qualified counsel before publication in your specific jurisdiction.