PRIVACY POLICY

CarrySafe Privacy Policy

Last updated August 26, 2026 · Hoydia LLC, New Jersey

CarrySafe is a legal-reference app made by Hoydia LLC. It helps adults understand mapped firearm-carry restrictions and find cited source material. This policy explains the information CarrySafe handles, why it handles it, who processes it, how long it is kept, and the choices available to you.

The short version

CarrySafe uses precise location only after you grant permission for requested nearby, boundary, routing, and optional Carry Mode features. CarrySafe does not add those coordinates to an account location history. Permit records and private files are account-scoped. There is no microphone or audio collection in this release. The app does not request microphone access, record a voice turn, or transmit audio. We do not sell personal information, use permit or location data for advertising, or track you across other companies' apps or websites. The App Store review build contains no active advertising. You can delete CarrySafe data from inside the app.

Information you provide

Account and contact information. We handle your email address, Supabase account identifier, optional display name, authentication provider, and security metadata needed to create and protect the account. Authentication may use email, Google, or Sign in with Apple. Passwords are handled in hashed form by the authentication service and are not visible to Hoydia.

Legal profile and permit details. You may provide a home state, local preview jurisdiction, issuing state, resident or nonresident status, permit type, issuing authority, relevant dates, holder name, permit number, date of birth, address, notes, and physical descriptors. CarrySafe uses these details for product scope, permit-aware references, recognition material, and renewal reminders. They do not become a government credential or a public permit registry.

Private permit files. Permit images or documents attached in supported versions are stored in a private, account-scoped area. They are not available through public endpoints or to other customers.

User content and communications. Community activity can include memberships, follows, blocks, posts, replies, reports, event responses, and messages to verified businesses. Content you deliberately publish is visible to the audience shown in the app. Reports are shared with authorized CarrySafe reviewers. Messages to a business are shared with that business. Support messages can include your email address, subject, message, topic, app version, and a coarse browser-family label. Support abuse protection processes a one-way hash of the request IP address; the support record never stores the raw IP address or raw browser identifier. Do not send a password, verification code, private permit image, or other unnecessary sensitive material in a support message.

Bookings. When booking features are available, CarrySafe may handle your name, phone number or other contact information, notes, requested time, service, merchant, and booking status. The selected merchant receives the information needed to respond to and fulfill the request.

Location, maps, and routes

CarrySafe uses location only after you grant iOS permission. An exact coordinate can be sent to CarrySafe's server for a nearby-rule lookup, state-boundary check, or restricted-place request. A coarse state or the area visible on the map may be used to personalize the result. Coordinates used for these requests are not added to a CarrySafe account travel history. State-crossing de-duplication is kept in session memory rather than stored as a route trail.

Carry Mode is an explicit, account-scoped setting stored on the iPhone and shared with CarrySafe's Siri and Shortcuts actions. Foreground nearby and state-boundary monitoring runs while CarrySafe is open. In a supported iOS build, you may separately enable Background nearby warnings. That feature asks for Always Location, Precise Location, notifications, and Background App Refresh, then gives iOS a small rotating set of eligible mapped regions. Those regions can include strict reviewed warnings and separately labeled mapped-place advisories whose legal status has not been reviewed. The feature does not continuously sample or upload GPS, perform background network lookups, or build a route or location history. iOS can delay or suppress delivery, and no operational warning radius is a legal property boundary.

CarrySafePro route planning remains available in this release. When you deliberately request a route, the places you enter pass through CarrySafe's server to Mapbox Geocoding and Mapbox Directions. If you explicitly choose your current location as the origin, that fresh coordinate is included. Route calculations and address suggestions are transient, and CarrySafe does not save the request, result, or route endpoints to your account. Providers may create short-lived security and reliability logs under their own service practices.

Purchases, subscriptions, Duo, and existing access

Apple processes App Store purchases. CarrySafe never receives your payment-card number or full billing details. To grant, restore, acknowledge, and protect access, CarrySafe handles the StoreKit product identifier, transaction and original-transaction identifiers, account binding, storefront environment, subscription status, renewal and expiration state, grace or billing-retry state, and refund or revocation state. Store lifecycle notifications can update access after renewal, cancellation, refund, or revocation.

Duo access uses household, invitation, membership, and access-period records. A previously granted fixed-term entitlement can retain its status, end date, and refund or revocation state so CarrySafe can show passive existing access accurately. Current iOS surfaces do not offer a separate purchase, transfer, activation, or management path for that access. A purchase changes product access only. It never changes a legal review result or creates permission to carry.

Microphone and audio in this release

There is no microphone or audio collection in this release. The app does not request microphone access, record a voice turn, transmit audio for transcription, create a transcript, or request synthesized audio. Dormant compatibility fields and retained StoreKit product records do not create a customer data flow because no microphone or spoken feature runtime is reachable. We will update this policy, the app's native permissions, and the applicable store privacy disclosures before enabling a future microphone or spoken feature.

Product interaction and diagnostics

First-run and sign-in analytics. CarrySafe records allowlisted event codes for onboarding steps viewed, skipped, or completed and sign-in attempts, outcomes, route, and coarse failure category. It also records platform and app version. It never puts answers, coordinates, permit details, home state, free-form text, raw errors, or a device advertising identifier in this channel. Events created before sign-in remain in a bounded on-device queue and are sent only after the person creates or signs into an account. Someone who never signs in is never recorded on the server. Staff sees aggregate counts.

Crash and operational diagnostics. CarrySafe can record an allowlisted render-failure or operational-failure code, affected app surface, platform, app and build version, time, and random support reference. It never sends a raw exception, stack trace, coordinate, permit, route, event, or device identifier through this channel. The account link exists only for abuse control and deletion. Staff sees aggregate operational summaries.

How we use information

We use the information described above to authenticate accounts; provide maps, permit-aware references, alerts, subscriptions, Duo, passive existing entitlements, community, booking, support, and route planning; personalize the app to the chosen area and permit profile; restore purchases; prevent fraud and abuse; secure and troubleshoot the service; understand aggregate first-run and sign-in reliability; comply with legal obligations; and enforce these Terms. We do not use permit details, private files, precise location, routes, or support messages for advertising.

Processors and other recipients

Apple processes App Store billing and provides StoreKit, Sign in with Apple, notifications, Siri, and system location services. Supabase provides authentication, database, server functions, and private file storage. Mapbox provides map tiles requested by the device and processes geocoding and directions sent through CarrySafe's server; those requests can include an IP address and device or network metadata and, depending on the request, an entered place, current coordinate, or route geometry. Google processes Google sign-in when selected and delivers fonts on the hyda.studio website. Twilio SendGrid processes authentication, account, purchase, and support email delivery.

A merchant, event organizer, or verified business receives information only when you direct an interaction, message, response, or booking to that recipient. Authorized Hoydia personnel and CarrySafe reviewers can access information only as needed for support, security, moderation, legal review, and service operations. We may disclose information when required by law, to protect rights or safety, or as part of a business transaction subject to appropriate safeguards.

No sale, advertising, or cross-app tracking

We do not sell or rent personal information. The App Store review build has no active advertising and no third-party advertising or cross-app tracking SDK. Mapbox telemetry is disabled in the iOS review build. We do not build or share a public registry of permit holders. Before any sponsored placement is activated in a later build, we will update this policy and the App Store privacy disclosures.

Retention

Account, permit, preference, membership, report, booking, and entitlement-link data is kept while the CarrySafe account is active and as reasonably needed to provide the service, resolve disputes, prevent abuse, meet security or accounting obligations, and enforce agreements. Private permit files are removed before account deletion can finish. Public business or legal content may remain with personal attribution removed. Limited unlinked App Store transaction and server-notification records may remain for refund, fraud, accounting, and audit purposes.

Allowlisted client diagnostics are retained for 30 days. First-run and sign-in funnel events are retained for 90 days. Closed support-message email, subject, body, and staff-note content is redacted after 180 days; the reference, topic, and timestamps can remain as a compliance record. Support abuse hashes are cleared after 30 days, spam records are deleted after 30 days, and short-lived rate-limit counters are pruned after 48 hours. Operational provider logs can follow the provider's contract and security-retention schedule.

Deletion and your choices

You can delete your CarrySafe account in the app from Profile, Account, Delete account. Deletion removes the CarrySafe profile, permit records, private files, preferences, memberships, reports, bookings, analytics events, diagnostics, and account-linked entitlement records. Public business or legal content may remain without your identity. Authentication is shared across Hoydia products, so the global sign-in identity remains when another Hoydia product still has data tied to it; the CarrySafe data and CarrySafe session are still removed.

Deleting CarrySafe does not cancel an Apple subscription. Cancel separately in Apple's subscription settings if you do not want billing to renew. If CarrySafe does not hold an Apple token that can be revoked automatically, the app gives you Apple's steps to stop using Sign in with Apple after deletion. You can also turn off location, notifications, Background App Refresh, or Background nearby warnings in the app or iOS Settings. To request access to or correction of information, contact us at info@hyda.studio.

Security

Traffic is encrypted in transit. Account access uses database row-level security and narrow server functions; the customer app contains no service-role database key. Private permit files are account-scoped. Purchase transactions are verified against Apple's signed data. Privileged legal publication actions require staff authorization and are designed to be audited. No service can be guaranteed perfectly secure, so contact us promptly if you believe an account has been compromised.

Age

CarrySafe is intended for adults who may lawfully use firearm-carry reference material. It is not directed to children under 18, and we do not knowingly create CarrySafe accounts for children.

Changes and contact

We may update this policy when the product or its data practices change. The current effective date appears at the top of this page. Privacy questions and requests can be sent to info@hyda.studio or mailed to Hoydia LLC, 180 Gress Ct, Paterson, NJ 07501, United States.

← Back to CarrySafe