Legal Agreement

Terms of Service

Last Updated: July 2026 • Version 1.0 (Fair Use & Custody Standard)

Safa Summary: TL;DR (Plain English)

You Control Your Keys

You own your on-device encryption key. Because Safa has no backdoors or master passwords, if you lose your PIN and recovery word, we cannot restore access.

Organization Conduct

Admins are legally banned from utilizing presence data for tracking outside check-in, marketing, or collecting biometric markers.

Fair Use & Kiosks

Kiosk terminal software licenses are provided for dojos, schools, and offices. Any structural abuse or hacking will void your usage license.

Liability Allocation

Safa is a cryptographic utility provider. If an organization violates privacy agreements off-platform, the liability falls solely on that organization.

1. Acceptance of Terms & Universal ID Wallet

By creating a Safa account, scanning a physical check-in tag, or launching an organization dashboard, you agree to comply with and be bound by these Terms of Service. Safa provides a decentralized, client-side encrypted Personal Data Store (PDS) and attendance logging infrastructure. If you do not agree to these terms, you must not access or use our services.

2. Cryptographic Self-Custody & Pin Management

Safa utilizes non-custodial cryptography. Your private encryption keys are generated directly on your browser client. Because we do not store your master PIN or secret recovery word on our servers:

  • You are solely responsible for maintaining the confidentiality and safety of your PIN and secret word.
  • Safa Cannot Recover Your Account: If you forget your PIN and lose your secret word, Safa cannot decrypt your wallet, restore your profile credentials, or bypass security rules. All encrypted data will remain permanently locked.

3. Code of Conduct for Organization Admins

Administrators using Safa’s dashboard portal, roster management, and insights tools are bound by strict legal covenants. As an Admin, you represent and warrant that:

  • No Secondary Marketing: You will use member checked-in data (names, emails, attendance metrics) solely for operational attendance, safety rosters, and program statistics. You are strictly prohibited from utilizing Safa data to build marketing email lists, sell advertising, or profile minors.
  • Zero-Biometrics Policy: You will not request, input, or integrate biometric features (such as facial matching feeds or fingerprint scans) into the Safa check-in flow, which avoids BIPA compliance disputes.
  • No Passive Surveillance: Safa must only be used for active kiosk scans or tag taps. You are forbidden from attempting to integrate passive GPS tracking models using Safa credentials.

4. Kiosk Licensing & Fair Use

Safa grants registered organizations a limited, revocable, non-exclusive license to run check-in terminals (`/kiosk`) at their physical premises. You agree not to:

Reverse-engineer the client-side cryptographic handshakes, perform automated scraping on check-in APIs, forge QR attendance tags, or inject fabricated logs. Attempting to exploit these endpoints will result in instant organization bans and account terminations.

5. Subscription Billing & Cancellation Rights

Organizations accessing premium dashboard insights, advanced security settings, and multi-roster metrics are billed on a subscription basis. Subscriptions are handled through secure payment processors (Stripe). You may cancel your subscription at any time via your Billing settings. Upon cancellation, your premium features will remain active until the end of the current billing cycle.

6. Disclaimers & Allocation of Liability

SAFA IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED. BECAUSE SAFA HAS NO CUSTODIAL CONTROL OVER ENCRYPTED DATA PACKAGES OR END-USER KEY VAULTS:

Safa shall not be held liable for any data loss resulting from forgotten client credentials, or for administrative misuse of shared information by organizations. Any dispute regarding off-platform data handling, employment rosters, dojo attendance score sheets, or parent excuse disputes must be resolved directly between the organization and the user/parent.