Privacy Policy
Last updated: 2 October 2026 · Effective: 2 October 2026
SafeKeep is provided by Usman Mahmood, an individual developer in Lahore, Pakistan, who publishes it as BinaryCraftsmen ("SafeKeep", "we", "us"). Questions about privacy: binarycraftsmen@gmail.com.
1. The short version
- Your documents stay on your phone, encrypted. We can't read them.
- Nothing about a document leaves your phone unless you turn on a feature that needs it (cloud AI auto-fill), and we tell you what is sent before it is, or you export or share it yourself.
- We don't sell your data, and we don't use your documents to train AI.
- The Free plan can show ads from Google AdMob. They're non-personalised, and the ad SDK never receives your documents, their text or your name; like any ad request, it receives information about your device (section 11).
- SafeKeep includes no analytics or crash-reporting SDK. If you agree (it asks once), it sends a few usage counts: numbers only, like how many searches found something.
2. What stays on your phone
What is stored:
- Your documents: page images, labels, notes, categories and tags.
- The text read from each page, with the position of every word, so search can highlight what it found. The text is read on your phone by your platform's own engine (Google ML Kit on Android, Apple Vision on iOS).
- Dates, amounts, phone numbers, email addresses, links and bank account numbers found in that text, by SafeKeep's own rules, also on your phone.
- Your reminders and the search index.
How it is protected:
- Everything is kept in SafeKeep's private storage on your phone. The database is encrypted with AES-256 (SQLCipher); every page image is a separate file encrypted with AES-256-GCM.
- The keys are held by your phone's secure hardware (Android Keystore, iOS Keychain / Secure Enclave). They never leave the phone.
- Photos you take with the scanner, and images you import or share to SafeKeep from another app, are deleted from temporary storage as soon as their encrypted copy is saved (or when you discard them). SafeKeep finds the page's edges and crops it on your phone.
- Reminders are delivered by your phone's own alarm system. On Android their text is stored encrypted, and the lock screen shows only "SafeKeep reminder".
- App lock (optional): SafeKeep asks for your phone's own fingerprint, face or screen lock. Your phone checks it; SafeKeep never sees or stores it. You can also hide SafeKeep in recent apps, which blocks screenshots of it.
- Deleting a document moves it to Recently deleted on your phone, where you can restore it for 30 days. After that it's erased, with its pages and files. You can erase it sooner there.
- SafeKeep excludes its data from Android Auto Backup and device-to-device transfer, because a copy restored without the keys couldn't be opened.
- Export and Share (only when you tap them): SafeKeep makes a PDF or images of that document on your phone, with its label, notes and details if you keep them in, and saves it where you choose or hands it to the app you pick. That copy isn't encrypted, and what happens to it then depends on where you put it or whom you send it to. SafeKeep doesn't write it to its own storage: a shared file is held in memory for the app you picked and forgotten within 30 minutes.
If you lose your phone: SafeKeep has no backup yet, so your documents exist only on that phone. See the Terms of Service, section 6.
3. Your account
You need an account to use SafeKeep. You can sign in with an email address and password, or with Google.
What we keep:
- Your email address, and the name and profile photo address your sign-in provider shares (Google, for example).
- A SafeKeep user id, the sign-in method, and when the account was created and last updated.
- Your plan (Free or Plus) and your role.
- Your app settings: theme, reminder timing, whether cloud AI auto-fill is on, and which actions SafeKeep may take without asking.
Where: Google Firebase (Authentication and Cloud Firestore), stored in the United States. SafeKeep is run from Pakistan, so we may access these records from there to operate the service.
We use this to sign you in, to apply your plan, and to keep your settings when you reinstall the app. It never includes your documents.
4. Cloud AI auto-fill (optional)
Reading the text, suggesting a label and category, and finding dates happens on your phone for everyone. Cloud AI auto-fill is an optional extra that you turn on yourself.
When it's on:
- When you add a document (by scanning, importing or sharing it to SafeKeep) and your plan has premium documents left, SafeKeep sends it to Google's Gemini API through SafeKeep's server to suggest a better label, category, dates and amounts, which you see on the review screen.
- Today what is sent is a reduced image of the first page. In a later version only the text read on your phone will be sent (with your label and notes), and the image only when too little text was found. We will update this section before that changes.
- A document can contain sensitive details (health, identity or financial information), so SafeKeep asks for your explicit agreement before it turns cloud AI auto-fill on. You can turn it off at any time in Settings.
What we keep:
- We don't store what is sent or what comes back.
- Our server records only that an analysis happened, for your plan's monthly allowance: a count, the size of the request, how long it took, and which model was used.
What Google does with it:
- We use Google's paid Gemini API service. Google does not use this content to train its models.
- Google does keep it for a limited period to detect abuse, under its own terms (Gemini API additional terms).
5. Backup and sync
SafeKeep doesn't back up or sync your documents yet: they exist only on your phone. Before backup is offered, we'll update this section and tell you in the app.
6. Plan and usage numbers
When SafeKeep checks your plan (when you open the app or return to it, at most every few minutes), it sends numbers only, never content.
Always: how many documents you have, your platform (Android or iOS) and your app version. We use them to apply your plan's limits, to show you relevant messages (for example, when you're close to the Free limit), and to detect modified versions of the app.
Usage counts (only if you agree: SafeKeep asks you once, and Settings → Share usage counts changes your answer at any time): since the last check, how many
- searches you made, and in how many you opened a result;
- documents and pages you saved, and scans you discarded on the review screen;
- documents you deleted and restored;
- reminders you set.
They never include a word, a name, a date, an image, or which document. We add them up per account and per day to see whether SafeKeep works for people (for example, whether search finds what they look for), and look at them only in totals. Settings → What's sent shows the exact numbers waiting to be sent. Turning usage counts off deletes the ones not yet sent.
We also record the day you first open SafeKeep, save your first document and reach five documents, to measure whether new users get started.
7. App integrity
To protect SafeKeep's services from modified apps, requests to our server carry an integrity check from your phone's platform (Google Play Integrity on Android, Apple App Attest on iOS), delivered through Firebase App Check. It tells us whether the app and the device are genuine; it tells us nothing about your documents.
8. Problem reports and messages to support
Problem reports. If a document can't be read, the review screen offers a Report button. Only when you tap it, SafeKeep sends:
- the error message and technical details (the error and where in the code it happened);
- the document's internal id, where its capture was stored on your phone, and how it was captured;
- your device model and manufacturer, the operating system version, and the app version.
A report never includes page images. The error text is technical, but it can occasionally quote a short piece of what was read, so only tap Report when you are comfortable with that.
Messages to support. Contact support and Report a problem (in Settings and on the sign-in screen) open your own email app with your message filled in; you read it and send it yourself. We then receive your email address, your message, and, if you leave Include app and device details on, the lines it shows: app version, operating system version, phone model, and your SafeKeep account email and plan. We use them only to answer you. Support email is handled in Gmail (Google). Please never send documents or photos of them.
9. Permissions
- Camera: to scan documents. Photos are processed on your phone. SafeKeep explains this before your phone asks.
- Biometrics (only if you turn on App lock): to ask for your phone's fingerprint, face or screen lock.
- Notifications, and "Alarms & reminders" on Android: to deliver reminders you set, at the time you chose.
- Internet: to sign in, check your plan, show ads on the Free plan and, if you turn them on, cloud AI auto-fill and usage counts.
- Advertising ID (Android): the ad SDK on the Free plan reads your phone's advertising ID (section 11). You can reset or delete it in your phone's settings, usually under Privacy → Ads.
- No access to your photo library or files: imports use your platform's photo picker, so SafeKeep sees only the images you pick.
10. Purchases
Nothing can be bought in SafeKeep yet. When the Plus subscription goes on sale, purchases will be handled by Google Play or the App Store, and we'll update this section first.
11. Ads (Free plan)
- Where: the Free plan shows ads from Google AdMob: one at the end of Home and of your document list, and sometimes a full-screen ad when you finish saving documents (never after your first). Ads never appear over your documents or their text, and never while you scan, sign in or unlock SafeKeep. We can turn ads off for everyone at any time; while they're off, SafeKeep requests no ads and doesn't ask for ad consent.
- Non-personalised: the ads aren't chosen from a profile of you or of what you do in other apps. SafeKeep never gives AdMob your documents, their text, your name or your email address.
- What AdMob receives, as with any ad request: your IP address (from which it estimates your approximate location), information about your device and the app, your phone's advertising ID and other device identifiers, and how you interact with the ads (for example views and taps). Google uses it to show and measure ads, to limit how often you see them and to prevent fraud, under its own policy: How Google uses information from sites or apps that use its services.
- Your choice: where the law requires it (for example in the EEA, the UK and Switzerland), SafeKeep asks with Google's consent form before it shows ads, and Settings → Ad privacy choices changes your answer at any time. You can also reset or delete your phone's advertising ID.
12. Who processes data for us
- Google Firebase (Authentication, Cloud Firestore, Cloud Functions, App Check, Installations): your account, plan, settings, server functions and problem reports. Its components use identifiers for each installation of the app to provide these services.
- Google ML Kit, on your phone: reads the text of your pages there. It sends Google diagnostics (device model, operating system version, app version, performance figures, error codes and an identifier for the installation), never your images or their text.
- Google (Gmail): messages you send to support.
- Google Firebase Hosting: SafeKeep's website (safekeep.binarycraftsmen.org, also served at safekeep-web.web.app), including the links that open the app and this policy and the terms when you open them in the app. Like any web server it logs requests (IP address, browser) for security. The site sets no cookies and has no analytics.
- Google Gemini API: cloud AI auto-fill, only when you turn it on.
- Google Play and Apple: app integrity checks (section 7). If you install SafeKeep from a link on our website, Google Play tells the app, on your phone, which SafeKeep screen that link was for (its install referrer), so it opens there the first time. SafeKeep reads it once and sends it nowhere.
- Google AdMob: ads on the Free plan (section 11). Google decides how it uses ad data, under its own policy.
These providers may process data in the United States and other countries. Google stores SafeKeep's account data in the United States; for data from the EEA, the UK and Switzerland it relies on the EU–US Data Privacy Framework and the European Commission's standard contractual clauses. SafeKeep itself is run from Pakistan, which has no EU adequacy decision; we access the data from there only to run the service, and protect it as this policy describes.
13. Legal bases (EEA and UK)
- Contract: your account, your plan, reminders and the app's core features.
- Consent: cloud AI auto-fill (explicit consent, since documents can contain sensitive data), usage counts, problem reports and ads (through Google's consent form). You can withdraw consent at any time in Settings; that doesn't affect what was done before.
- Legitimate interests: app integrity checks, plan usage numbers and the milestones above, to keep the service secure and fair and to understand whether people get started; the website's server logs, for security. You can object to these by writing to us.
Your email address is needed to create an account; everything else is optional. We don't make decisions about you based only on automated processing that have legal or similarly significant effects.
14. How long we keep data
- Your account and settings: until you delete your account.
- Plan usage numbers and milestones: while your account exists.
- Daily usage records (usage counts, library size, platform, app version): 13 months, and deleted with your account.
- Recently deleted (on your phone): 30 days, then erased.
- Ad data: kept by Google under its own policy (section 11); SafeKeep doesn't receive it.
- Problem reports: 90 days.
- Messages to support: until your question is answered, and then up to 12 months, unless you ask us to delete them sooner.
- Server logs (no document content): 30 days.
- Your documents on your phone: until you delete them, delete your account, or uninstall the app.
15. Your choices and rights
- Turn cloud AI auto-fill and usage counts off at any time in Settings. Where the law gives you a choice about ads, change it in Settings → Ad privacy choices.
- Delete your account in the app (Settings → Delete account) or at safekeep.binarycraftsmen.org/delete-account. This deletes your data on our servers and everything SafeKeep stored on your phone.
- Depending on where you live, you can ask us for a copy of your data, to correct it, to delete it, or to stop using it: write to binarycraftsmen@gmail.com. We'll reply within 30 days.
- In the EEA and the UK, you have the right to access your data, to correct it, to have it deleted, to restrict or object to its use, to receive it in a portable format, and to withdraw consent at any time.
- You can also complain to the data protection authority where you live or work.
- We don't sell or share personal information for cross-context behavioural advertising, as those terms are defined by California law.
16. Security
We protect data with encryption on your phone, TLS in transit, access controls on our servers, and by keeping document content off our servers. No system is perfectly secure; if a breach affects your data, we'll tell you and the authorities as the law requires.
17. Children
SafeKeep isn't meant for children under 13 (under 16 in the EEA), and we don't knowingly collect their personal information. If you believe such a child has given us personal information, write to binarycraftsmen@gmail.com and we'll delete it.
18. Changes to this policy
We'll tell you in the app before a change to this policy affects you. The date at the top shows the latest version.
19. Contact
Usman Mahmood (BinaryCraftsmen), Lahore, Pakistan · binarycraftsmen@gmail.com · Help: safekeep.binarycraftsmen.org/support