Privacy Policy
Last Updated: July 2026 • Version 1.0 (Zero-Knowledge Standard)
Safa Summary: TL;DR (Plain English)
Zero-Knowledge Storage
We cannot read your child's medical info, phone number, or address. All decryption keys are generated and stored exclusively on your device.
No Location Tracking
Safa does not track your location in the background or use GPS. It only logs presence data when you actively scan a kiosk QR code.
COPPA & Parental Control
Children under 16 cannot publish data globally without active parental consent. Parents retain full veto control and audit logs.
Instant Global Erasure
Pressing "Delete Identity Wallet" immediately shreds all credentials and deletes memberships from all organization rosters.
1. Non-Custodial Architecture & Client-Side Encryption
Safa operates under a strict **Zero-Knowledge Architecture**. When you create a profile or register a Safa Tag, your device automatically generates a unique pair of cryptographic keys (RSA-OAEP 2048 and ECDSA P-256) inside your web browser.
Sensitive profile metadata (such as home address, emergency contacts, medical records, or allergen information) is encrypted *directly on your device* before being sent to Safa servers. Because your master symmetric encryption key is derived using your private PIN and secret word—neither of which is ever transmitted to Safa—**Safa staff, databases, and third-party host systems cannot read, access, or decrypt your personal records.**
2. Data We Collect & Siloed Data Sharing
Safa limits data storage strictly to what is necessary to operate our secure presence-verification system:
- Global Directory Package: We store your encrypted metadata package, your email address (optional for minors), and a unique hashed user identifier.
- Organization Silos: When you scan to join an organization (e.g. gym, martial arts dojo, school club), your device decrypts your profile details and re-encrypts them specifically using the organization's public key. This data is stored in a isolated tenant silo. Organizations can only see what you explicitly choose to share.
- Attendance Logs: We log check-in timestamps, status (Present, Late, Absent, or Excused), and the associated class roster ID.
3. COPPA Direct Disclosures & Minor Data Controls
Safa is strictly compliant with the **Children's Online Privacy Protection Act (COPPA)**. We recognize the importance of protecting the privacy of minors:
- Shadow Roster Isolation: When a school or youth program places a child under 16 on a local roster, the child’s profile exists as a "Shadow Profile" linked purely to that organization. The minor does not have a global public account.
- Verifiable Parental Consent (VPC): A child cannot link their tag to a global wallet or share their data across multiple organizations without a parent inputting their email. We send an instant, direct authorization link to the parent.
- Parental Dashboard Veto: Parents receive a dedicated control URL (`/consent/control/[token]`) enabling them to audit staff decryption history, review attendance scorecards, submit retroactive excuse reasons, and revoke optional profile fields or disconnect the child from organizations at any time.
4. Presence Verification vs. Geolocation Tracking
Safa does **not** track your location. Unlike applications that run GPS tracking in the background to log your movement, Safa is a passive check-in utility. A presence log entry is only created when you physically scan a QR code on a check-in kiosk or present your Safa tag to a scanner terminal. We do not integrate passive background location APIs, and your day-to-day movements remain entirely private.
5. Essential Cookie & Local Storage Disclosures
Safa does not use marketing pixels, social media tracker codes, or third-party behavioral cookies. We use cookies and local storage exclusively for essential operational utilities:
- Authentication Cookies: NextAuth session tokens to keep you logged in to your dashboard portal.
- Local Storage Vaults: Secure local storage is used inside your browser tab to hold temporary cryptographic keys while you are active in the consent manager.
6. Global Deletion & Erasure Mandates
Under California AB 656 and global portability laws, you maintain absolute ownership of your digital identity. Tapping the **"Delete Global ID"** button in your settings triggers a complete, cascading purge:
All cryptographic metadata packages are permanently deleted from Safa's servers, active credentials are marked as permanently revoked, and your name is scrubbed from all associated organization rosters. Deleted data is cleared from backup cycles within 14 calendar days.