Privacy Policy
Effective date: 15 September 2026 · Applies to the StudySafeLink iOS app and this website.
StudySafeLink ("留学平安通", "the App", "we", "us") provides safety information and family-reassurance services for international students and their parents: official crime maps, university safety scores, one-tap check-ins, trip guardian, anti-scam guard and an AI safety assistant. This Privacy Policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have.
1. Data we collect
- Account information. Email address, password (stored only as a salted hash), your role (student or parent), display name, language preference and time zone. Email addresses are encrypted at rest (AES); lookups use a SHA-256 hash of the address. If you sign in with Apple or Google instead, we store the provider's account identifier — not your password.
- Student profile. University, optional home-address text and home coordinates (used for geo-fence auto check-in). Parents store no address.
- Email verification & password reset. We send transactional email (verification links, magic-link password resets) via Amazon SES. Verification state is stored per account.
- Safety check-ins. Timestamp and method (manual / widget / geo-fence). Check-in records contain no GPS coordinates.
- Trip Guardian (location sharing). Only when you actively start it. Each start records a consent event (user ID, consent time, IP address). While active, we receive approximate GPS points roughly once per hour plus arrival events from a destination geo-fence; coordinates shown to the bound parent are rounded to ~100 m precision. Trip data is deleted 30 days after a trip ends.
- Anti-scam guard. When you report a suspected scam (e.g. a suspicious "customs parcel" call), we store the case type, your free-text description and reminder/escalation status so we can remind you to verify and notify your bound parent if you ask us to escalate. If you confirm a verification request, we record the approximate location you confirmed from (coordinates rounded to ~100 m) and the reverse-geocoded address.
- AI consultation content. Your question text is sent to our AI providers (Zhipu GLM as primary, DeepSeek as fallback) to generate an answer. Conversation history is not stored on our servers. Prompts may include coarse context such as "1 km around campus" statistics or a truncated district name — never your precise coordinates or full home address.
- User-generated map markers/reports. Category, description and location of markers you submit.
- Device information. Push token and platform for notifications, plus a random device identifier used solely to prevent referral-reward abuse (one bonus per device).
- Purchases. Subscription status/expiry and consumable credit balances, verified through Apple's App Store Server API. Payments are handled entirely by Apple; we never see card details.
- Referral programme. Referral code relationships and accumulated bonus days.
- Notification settings. Quiet-hours configuration and muted notification categories.
- Product usage data. We record feature-usage events (such as app launches, onboarding steps, and pages or buttons you tap) to understand how the App is used and improve it. These events contain no GPS coordinates, address or other personally identifying content; events from signed-in users are linked to their account.
2. How we use your data
- To deliver check-in notifications, the daily reassurance summary to your bound parent, and safety-news briefs around your university.
- To display crime maps, university safety scores and trends computed from official public data.
- To answer AI safety questions and generate daily safety cards and optional deep region reports.
- To operate Trip Guardian and the anti-scam verification reminders/escalation you requested.
- To manage subscriptions, consumable credits and the referral programme, and to detect abuse.
- To understand how the App is used and improve it (usage analytics without location or personal content).
3. Legal bases (GDPR / UK GDPR)
- Contract performance — accounts, check-ins, reports, binding, purchases.
- Consent — Trip Guardian location sharing, push notifications, community markers, marketing-free by design. Withdrawable at any time in App/system settings.
- Legitimate interests — fraud/abuse prevention and service security.
- Legal obligation — where required by law.
4. Sharing & third parties
We do not sell personal data. Data is shared only with the processors needed to run the service:
- Apple — App Store distribution, in-app purchase verification, APNs push delivery, and Apple sign-in (we receive your account identifier).
- Zhipu GLM / DeepSeek — AI answer generation (primary and fallback providers); question text and prompt context are processed under their commercial terms.
- Amazon Web Services (Lightsail, US East) — hosting of servers, database and SES transactional email.
- Google — only if you choose Google sign-in; we receive your account identifier.
- Nominatim (OpenStreetMap) — geocoding of place names in news processing and explicit addresses you enter.
- Public safety data providers — data.police.uk, US/Canadian/Australian city and regional police open data, FBI UCR, Statistics Canada, TfL, and police/news RSS feeds. These are public datasets about recorded events, not your personal data.
5. Retention
- Trip Guardian locations & consent records: 30 days after trip end, then automatic deletion.
- Deep region reports you generate: kept up to 6 months, then deleted.
- Community markers: expire automatically (hours to days depending on category).
- Safety check-ins and product usage events: kept while your account is active and permanently deleted with your account.
- Account data: while your account is active. If you request account deletion there is a 30-day grace period during which you can cancel in the App; after that all associated personal data is permanently deleted by automated cleanup.
6. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, PIPEDA, China PIPL and others) you may have the right to access, correct, export, restrict or object to processing of your personal data, withdraw consent, lodge a complaint with a supervisory authority, and — most importantly — delete your account and all associated data directly in the App (Settings → Account → Delete). You can also exercise any right by emailing us (Section 8). We respond within applicable statutory timeframes.
7. Security
TLS in transit; AES encryption at rest for email addresses; salted password hashes; parameterised database access; restricted server access; single-region VPS deployment in the United States; automated least-30-day cleanup of location history. No system is perfectly secure, but safeguards are maintained and reviewed.
8. Contact
Privacy questions, requests or complaints:
Email: studysafelink@yeah.net
9. Changes
The effective date above reflects the latest revision. Material changes will be announced in the App before taking effect.