Privacy Policy
Last updated: June 25, 2026
Overview
This Privacy Policy explains how Safety Check-In: Hayo ("Hayo," "the app," "we," "us") collects, uses, and protects your information. We collect only the data needed to provide check-in functionality and do not sell your data or use it for advertising.
Data We Collect
- Contact info — your name and email address, used to identify your account and link you with your check-in contacts.
- Identifiers — a user ID and device identifiers (such as a push notification device token), used to operate your account and deliver notifications.
- User content — check-in status, messages, and related content you create or send within the app.
- Purchases — subscription purchase history, renewal dates, transaction IDs from Apple, and device information, used to manage your subscription.
We do not collect usage analytics, diagnostics, crash data, location data, health data, or financial information such as credit card numbers.
Legal Basis for Processing
| Data | Purpose | Legal Basis |
|---|---|---|
| Name, email | Account creation and sign-in | Contract performance |
| User ID, device token | App functionality, notifications | Contract performance |
| User content | Check-in functionality | Contract performance |
| Purchase history, transaction IDs | Subscription management | Contract performance |
| Security and access logs | Fraud prevention, system security | Legitimate interest |
How We Use Data
We use the data above to:
- Create and maintain your account
- Let you and your contacts send and receive check-ins
- Deliver push notifications related to check-ins
- Manage your subscription
- Provide customer support
Sharing
We do not sell your personal data. We share data only with the service providers listed below, solely to operate the app, and with other users you choose to connect with for check-ins (e.g., your name and check-in status are visible to contacts you add).
Third-Party Services
- Supabase (Supabase Inc.) — backend, authentication, and database. Region: EU West (Ireland). Shares your name, email address, check-in status, and timestamps. Data is linked to your identity but not used for tracking. Supabase Privacy Policy
- Apple Push Notification service (APNs) (Apple Inc.) — delivers push notifications. Shares your device's push token only. Not linked to your identity and not used for tracking. Apple Privacy Policy
- Apple In-App Purchase (Apple Inc.) — subscription payments. Apple handles all billing; we receive only purchase history, renewal dates, and transaction IDs. We never see your credit card or payment details. Apple Privacy Policy
Data Retention
| Data | Retained for | Reason |
|---|---|---|
| Account data | Until you delete it | Provide the service |
| Check-in content | Until you delete it | Provide the service |
| Subscription records | 10 years after subscription ends | Swiss accounting law (OR Art. 958) |
| Security logs | 30 days | Fraud prevention |
| Backups | 30 days | Disaster recovery |
When you delete your account, your account and check-in data are removed within 30 days. Subscription records are retained for 10 years as required by law but cannot be used to contact you.
Security
We protect your data with:
- HTTPS encryption in transit
- Encryption at rest
- Row-Level Security (RLS) to restrict database access to your own data
If there is a breach: we will notify affected users and the relevant supervisory authority (FDPIC and/or ICO) within 72 hours if your rights are at risk.
Your Choices & Rights
You have the following rights over your data:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data by editing your profile in the app or emailing us.
- Deletion — delete your account at any time from within the app while signed in. We will remove your data within 30 days.
- Portability — request your data in a structured, machine-readable format.
- Restriction — ask us to pause processing your data while a dispute is resolved.
- Objection — object to processing based on legitimate interest.
To exercise any right, contact [email protected]. We respond within 30 days.
Children's Privacy
Hayo is not directed to children under 13. We do not knowingly collect personal data from children under 13. If we discover that a child under 13 has created an account, we will delete it immediately. If you believe a child has provided us with personal data, contact us at [email protected].
International Transfers
Your data is stored with Supabase Cloud in the EU West (Ireland) region. Subscription data processed by Apple may be transferred to the United States, subject to Apple's standard contractual safeguards. By using the app, you consent to your data being processed in these regions.
App Tracking Transparency
Hayo does not track you across other companies' apps or websites, as defined by Apple's App Tracking Transparency framework.
Push Notifications
Hayo uses Apple Push Notification service (APNs) to deliver check-in alerts. You can disable push notifications at any time in your device Settings.
Account & Sign-In
You can sign in with Apple Sign-In or via a one-time email code (no password is ever stored). Authentication is handled by Supabase Auth, which stores your name and email address.
Subscriptions
Hayo offers optional paid subscriptions, processed entirely through Apple's In-App Purchase system. Apple handles all payments — we never see your credit card or payment details. To manage your subscription, we receive:
- Purchase history and renewal dates
- Transaction IDs from Apple
- Device information
Subscription records are retained for 10 years after your subscription ends as required by Swiss accounting law.
What We Don't Do
- Sell your data
- Use your data for advertising
- Track you across other apps or websites
- Share your check-in content with third parties beyond the contacts you choose
- Store credit card or payment details
Supervisory Authorities
If you believe we have violated your privacy rights, you can lodge a complaint with:
Switzerland — FDPIC (Federal Data Protection and Information Commissioner)
edoeb.admin.ch
United Kingdom — Information Commissioner's Office (ICO)
ico.org.uk
European Union — Irish Data Protection Commission (DPC) as lead supervisory authority, given our EU data is hosted in Ireland.
dataprotection.ie
We respond to all privacy requests within 30 days (Switzerland/GDPR) or 45 days (US state laws where applicable).
Disclaimer
Hayo is provided for entertainment and convenience purposes only and is not a professional safety, emergency, or monitoring service. We make no guarantee regarding the reliability of check-ins, notifications, or the app's availability, and we assume no liability for technical failures, missed notifications, delayed alerts, or any harm arising from reliance on the app in an emergency. Hayo is not a substitute for professional emergency services — always contact your local emergency number (e.g. 112, 117, 118) in an emergency.
Contact Us
Address
Fabio De Paoli
Postfach
8625 Gossau, Zürich
Switzerland
Email
[email protected]
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes (new data types, new third parties, reduced security, or new countries) will be communicated via in-app notification at least 30 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision. Continuing to use Hayo after changes take effect means you accept the updated policy.