Privacy Policy for ZelSafe Last Updated: July 2, 2026 At ZelSafe, we believe something simple and non-negotiable: your data belongs to you, and to no one else. So we built ZelSafe to prove it. ZelSafe operates on a foundational Zero Data Collection architecture. We do not collect your data. We do not store your data. We do not track you. We do not profile you. We do not transmit anything to our servers, because there is nothing sent to our servers at all. Every single thing ZelSafe does happens entirely on your own device, and nowhere else. This is not a promise to handle your data responsibly. It is a promise that there is no data for us to handle in the first place. Read that again, because it is the entire point of this app. 1. The Core Principle: Nothing Leaves Your Phone ZelSafe is an offline-first, on-device application. When you open ZelSafe to learn about phishing, scams, deepfakes, password hygiene, or any other cybersecurity topic, everything you do stays sealed inside your device. There is no account to create. There is no login. There is no cloud sync. There is no telemetry beacon quietly reporting back. There is no analytics SDK counting your taps. ZelSafe has no server-side component that receives, processes, or stores anything about you, ever. If you turned on airplane mode and never connected to the internet again, ZelSafe would continue to work exactly the same way. That is by design. 2. Information We Do Not Collect Unlike traditional security and education applications, ZelSafe collects nothing. To be completely explicit about what that means: No server-side personal information. We do not collect, transmit, or store your name, email address, phone number, date of birth, or account credentials on any remote server. Your name and email retrieved locally via "Sign in with Apple" for RCCS certificate verification are stored exclusively on your device. No identifiers. We do not collect your device ID, advertising identifier, IP address, IMEI, serial number, or any other persistent identifier that could be used to recognize or follow you. No location data. We never access, request, collect, or infer your location, whether precise or approximate. No usage tracking or analytics. We do not use Google Analytics, Firebase Analytics, Facebook SDK, Mixpanel, or any third-party analytics or attribution service. We do not track how you use the app, which cards you read, how long you stay, or what you tap, for any purpose that leaves your device. No browsing or cross-app data. We do not monitor your browsing history, your other apps, your contacts, your calendar, your messages, or anything happening outside of ZelSafe. No cookies or trackers. As an on-device app, ZelSafe uses no web cookies, tracking pixels, or fingerprinting of any kind. No third-party sharing, selling, or renting. Because we harvest no data at all, we have absolutely nothing to sell, rent, share, disclose, or hand over to advertisers, data brokers, analytics firms, or any third party. This is not a policy choice we could quietly reverse. It is an architectural fact of how the app is built. 3. On-Device Learning Progress (Stored Only on Your Phone) To function as a cybersecurity education and awareness platform, ZelSafe keeps track of your own learning progress so you can pick up where you left off, see which modules you have completed, and know how you performed on quizzes. This is the kind of information any learning app needs to be useful. Here is the critical difference: all of it lives exclusively on your device. The app locally records events such as which threat cards and awareness modules you have viewed, the time you spend reading, your quiz results, your completion status, and your progress through the ZelSafe curriculum. This information is written only to your device's own protected local storage (for example, iOS UserDefaults or SwiftData), which is sandboxed and encrypted by Apple's operating system. It is never uploaded, never backed up to a ZelSafe server, and never seen by us or by anyone else. You can erase all of it at any time by deleting the app from your device. 4. Compliance Certificates and RCCS Identity Verification ZelSafe lets you generate an official Compliance Certificate or Training Report documenting the cybersecurity awareness modules you have completed, which is useful for workplace, academic, or personal record-keeping. To ensure the security, integrity, and authenticity of your RCCS Certification, ZelSafe requires you to authenticate using "Sign in with Apple" when unlocking or issuing your certificate. This allows the app to retrieve the full name and email address associated with your Apple ID for identity verification. The name and email retrieved from Apple are stored exclusively in your device's protected local storage (iOS sandboxed environment). This keeps your certificate personalized and maintains your verified training records locally on your device without requiring repeated sign-ins. This information is never transmitted to, processed by, or stored on ZelSafe or Rocheston servers, nor is it sent to any third party. The finished certificate and audit JSON are compiled entirely on your device. If you decide to share them-for example, by uploading to your employer's private ZelSafe Private Dashboard (ZPD) instance or sharing via Apple's native Share Sheet-that action is initiated entirely by you. ZelSafe's systems never view, intercept, route, or receive these certificates or training files. 4.1 Sign in with Apple (On-Device Storage Only) ZelSafe utilizes Apple's native "Sign in with Apple" framework solely as an on-device identity verification mechanism to award your RCCS certification. - Local Retention Only: The name and email retrieved from Apple remain sealed in local storage on your device to personalize your certificate and populate your local audit export. - No Remote Account: Signing in with Apple does not create an account on any remote server, nor does it register a user profile with Rocheston. - Direct Export Only: This identity data only leaves your device when you explicitly choose to upload your signed audit JSON to your employer's private ZPD or share your certificate document directly. 5. App Permissions: We Ask for Almost Nothing ZelSafe follows Apple's native iOS security and privacy protocols and deliberately avoids requesting invasive permissions. ZelSafe does not require access to your Contacts, Photo Library, Camera, Microphone, Location Services, Health data, or any other sensitive system resource in order to teach you cybersecurity. If a future optional feature ever needed a permission, iOS would ask you first, and you could always decline and keep using the app. 6. No Network Transmission of Personal Data Because ZelSafe has no user accounts and no backend service that collects personal information, no personal data is ever transmitted off your device. There is no server that ZelSafe uses to store or process information about you. This eliminates entire categories of risk that affect conventional apps, including server breaches, cloud data leaks, credential theft, and unauthorized internal access, because the data those attacks target simply does not exist in our hands. 7. Compliance and Data Protection by Design Most privacy policies spend pages explaining how a company complies with data protection regulations. ZelSafe takes a different path: we designed the app so that the obligations these regulations exist to enforce simply do not arise. You cannot mishandle data you never collect. You cannot breach data you never store. You cannot be compelled to hand over data you never had. To be clear and honest with our enterprise, academic, and healthcare customers: ZelSafe is not claiming to hold any formal certification such as SOC 2, ISO 27001, or similar. Those certifications audit how an organization protects the personal data it processes on its servers and systems. ZelSafe processes no personal data on any server, so there is nothing of that kind to audit. Instead, ZelSafe is built to align with the underlying principles that these frameworks and laws are designed to protect: Data minimization (GDPR Article 5, CCPA/CPRA). The strongest form of data minimization is collecting nothing at all. ZelSafe processes zero personal data, which is the fullest possible expression of this principle rather than a partial compliance measure. Purpose limitation and storage limitation. Because your learning progress lives only on your own device and is never transmitted to us, there is no central store of personal data to be retained, repurposed, or exposed. No cross-border data transfer concerns. Since no personal data ever leaves your device or crosses a network to us, the complex questions of international data transfer, data residency, and jurisdiction do not apply to ZelSafe. COPPA and children's privacy. ZelSafe collects no personal information from any user, including children, which means the data-collection obligations COPPA is built to regulate do not arise. FERPA and student records. When a student uses ZelSafe, no education record or personal data is created on our side, transmitted to us, or held by us. Any certificate a student generates is produced on-device and shared only by the student's own choice. HIPAA-adjacent environments. For healthcare organizations using ZelSafe for staff awareness training, ZelSafe introduces no new data-handling surface, because it neither collects nor transmits any information about the user. For an enterprise buyer, the practical takeaway is straightforward. There is no ZelSafe server holding your employees' data to be breached. There is no ZelSafe database to be subpoenaed. There is no vendor data-processing agreement required for personal data, because ZelSafe processes none on your behalf. The most secure data is the data that was never collected, and that is the foundation ZelSafe is built on. 8. Children's and Students' Privacy ZelSafe is designed to be safe for learners of every age, including children and students, precisely because it collects no personal information from anyone. We do not knowingly or unknowingly collect data from children under 13, or from any user of any age, because the app is architecturally incapable of collecting it. Parents, teachers, and schools can let students use ZelSafe with confidence that no personal data about the child is being gathered, stored, or shared. 9. Your Control You are always in complete control. You never provide us data, so there is nothing for you to request, correct, or ask us to delete on our end. To remove all locally stored progress and any generated information from your device, simply delete the app. Everything goes with it, instantly and permanently. 10. Changes to This Policy We may update this Privacy Policy from time to time to reflect new offline features or clarifications. However, our foundational commitment to Zero Data Collection will never change. If we ever update this policy, we will revise the date at the top of this page. We encourage you to review it periodically. 11. Contact Us If you have any questions about ZelSafe's local-only, zero-data privacy architecture, we are happy to help. Email: info@rocheston.com Website: https://rocheston.com/zelsafe Built with love by Haja Mo