Privacy Policy
Review how RestfulSync collects, uses, shares, retains, and protects personal information across the unified RestfulSync and LawYeti platform.
Document type
Privacy Policy
Brand note
Formerly known as SafeZone
Format
Public-facing legal document
Overview
RestfulSync, Inc. · A LawYeti Company · Incorporated in Delaware, USA
privacy@restfulsync.com · support@restfulsync.com
Preamble — About This Privacy Policy
This Privacy Policy explains how RestfulSync, Inc. ("RestfulSync," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you use the RestfulSync mobile application (formerly SafeZone), the unified LawYeti platform, the Evidence Vault, and all related services, features, and content (collectively, the "Services").
This Policy applies to all participants on the platform, including users (clients), Emergency Contacts designated by users, parents or guardians of minor users, promoters, and RestfulSync administrators. It does not apply to independent attorneys who access the platform through the separate LawYeti Attorney portal, who are governed by the LawYeti Attorney Privacy Policy.
Strictest-Jurisdiction Commitment
RestfulSync strives to comply with all applicable U.S. state privacy laws and incorporates the most stringent protections where they apply. California's CCPA/CPRA, Virginia's VCDPA, Colorado's CPA, Texas's TDPSA, and other state consumer privacy laws grant residents specific data rights — we have integrated these requirements into our platform. In the event that privacy laws differ by jurisdiction, we adhere to the strictest applicable standard to protect your privacy.
Section 1 — Scope, Key Definitions, and Privilege Warning
1.1 Definitions.
For purposes of this Privacy Policy, the following terms have the meanings set forth below:
"User" or "Client": An individual who uses the RestfulSync Safety Stack features and/or the LawYeti legal information and attorney connection features.
"Attorney": An independent licensed attorney who participates in the LawYeti platform to receive routed inquiries and provide legal consultations.
"Emergency Contact": An individual designated by a User to receive plain-text SMS alerts upon the User's SOS activation.
"Promoter": An individual or entity participating in RestfulSync's marketing, referral, or incentive programs.
"Personal Information": Information that identifies, relates to, describes, or could reasonably be linked with an individual or household, as defined under applicable privacy laws.
"Sensitive Information": Categories of personal data treated with heightened protections, including: precise geolocation data; audio and video recordings; biometric data; government-issued identification documents; health or medical information; financial account details; and personal information concerning minors.
"Evidence Vault": The unified encrypted storage infrastructure shared between RestfulSync and LawYeti where user media, documents, and evidence are stored, including long-term retention-protected long-term storage.
"AI Triage": RestfulSync/LawYeti's automated intake and issue-spotting functionality; does not provide legal advice.
"Compliance Decision Engine" or "CDE": The server-driven, on-device-enforced policy system that determines applicable recording compliance profiles based on detected geographic jurisdiction.
"Restricted-Access Long-Term Storage": restricted-access evidence preservation immutable storage infrastructure that prevents alteration or deletion of stored evidence.
1.2 Privilege and Confidentiality Warning.
Attorney-Client Privilege Disclaimer
RestfulSync, Inc. is not a law firm. Information submitted to RestfulSync before a user directly engages an independent attorney through the LawYeti module is generally NOT protected by attorney-client privilege. You should avoid including unnecessary highly sensitive personal, financial, or legal details in free-text fields on the platform until you have established a direct engagement with an independent attorney. Interactions with the AI Triage system are NOT protected by attorney-client privilege and do not constitute legal advice.
1.3 Scope of This Policy.
Section 2 — Information We Collect
2.1 Information You Provide Directly.
Evidence Wizard Data — Scene Photos and Video: Video and photo media captured during a SafeWalk, SafeTrip, or SOS session is uploaded to the Evidence Vault in compliance with the applicable H.265/HEVC encoding standard. Each upload is accompanied by GPS coordinates (if location services are active), device identifier, and timestamp metadata. Media stored in long-term retention-protected storage for Premium and Family tier users cannot be deleted, altered, or modified by any party during the 7-year retention period.
Evidence Wizard Data — Voice Memos: Audio recordings captured through the Voice Memo feature are encrypted locally on your device before upload. Voice memos are stored in the Evidence Vault and are accessible only to you and authorized RestfulSync personnel under role-based access controls.
Evidence Wizard Data — Document Scans and OCR: When you scan a document using the Evidence Wizard, the scan is processed locally on your device using on-device OCR (optical character recognition). The OCR processing does not send raw document images to a remote server for text recognition — recognition is performed entirely on your device. The resulting scanned image and OCR text output are then encrypted and uploaded to the Evidence Vault. This design minimizes the transmission of potentially sensitive document content to remote servers.
Evidence Wizard Data — Witness Information: Witness names, contact information, and scanned identification documents entered into the Evidence Wizard constitute Sensitive Information belonging to third parties. Please see Section 2.4 for the special handling rules applicable to third-party Sensitive Information. Please do not include Social Security numbers, full financial account numbers, or other highly sensitive identifiers in witness or scene description free-text fields. Our forms are designed to capture only what is necessary, and we may automatically mask or redact certain sensitive number patterns in free-text fields.
2.2 Information Collected Automatically.
2.3 Opt-In Only — Enhanced Sensitivity Information.
The following categories of Sensitive Information are collected only upon your explicit affirmative consent and are never collected without it:
2.4 Special Handling of Third-Party Sensitive Information in the Evidence Wizard.
Witness contact information, scanned identification documents (driver's licenses, passports, government IDs), and other personal information belonging to individuals who are not RestfulSync users constitute Sensitive Information that you collect from and about third parties. RestfulSync applies the following protections to third-party Sensitive Information submitted through the Evidence Wizard:
Third-party Sensitive Information is encrypted end-to-end using AES-256 encryption before it leaves your device.
It is stored exclusively within the Evidence Vault and is not transmitted to any third-party service provider for processing, analysis, or storage other than the restricted-access long-term storage infrastructure (DigitalOcean) and the RestfulSync backend infrastructure.
Access is restricted to the submitting user and authorized RestfulSync personnel under strict role-based access controls (RBAC). No other user, attorney, or external party has access to third-party Sensitive Information you submit.
It is not used for any purpose other than storage in the Evidence Vault and user-directed retrieval.
It is retained for the applicable vault retention period and then securely deleted.
As noted in the Terms of Use, you are solely responsible for ensuring that you are authorized to collect and submit third-party personal information, and that you comply with all applicable privacy laws in doing so.
Section 3 — How We Use Your Information
We use your personal information only for legitimate, specified purposes associated with operating the platform, providing the Services, and meeting our legal obligations. We do not use your personal information for purposes incompatible with those disclosed in this Policy without your consent. Specifically:
We do not sell your personal information to any third party for their own marketing or commercial use. We do not share your personal information for cross-context behavioral advertising purposes.
Section 4 — AI Triage and Automated Processing
4.1 Privilege Warning and Scope of AI Processing.
The AI Triage feature is an automated intake and issue-spotting tool designed to collect general information about your legal matter and route it to appropriate attorneys. Before you begin an AI Triage session, the platform displays a clear notice that conversations with the AI are not protected by attorney-client privilege and are not a substitute for actual legal advice. The AI Triage system collects: your free-text description of your legal issue; the legal category you select; your jurisdiction; any follow-up responses you provide during the session; and session metadata.
4.2 AI Processing and Data Handling.
AI Triage session data is processed by RestfulSync's automated systems to generate informational issue-spotting responses and to route your inquiry to available attorneys in the appropriate practice area. A limited number of authorized RestfulSync staff may review selected AI Triage transcripts for quality assurance, safety monitoring, or in response to reported issues.
4.3 Third-Party AI Providers.
To the extent RestfulSync utilizes third-party AI services to power the AI Triage chatbot or other AI features, we transmit only the minimum information necessary for the AI functionality to operate. Our agreements with such providers expressly prohibit them from using RestfulSync user data to train, fine-tune, or improve their general AI models, or from retaining or selling your data.
4.4 AI Output Limitations.
AI Triage outputs are for general informational purposes only. They may not be accurate, current, or applicable to your specific jurisdiction or circumstances. The AI may not be aware of recent legal developments. You should not rely on AI Triage outputs as legal advice and should consult a licensed attorney for advice specific to your situation.
Section 5 — Evidence Vault: Data Handling, Encryption, and Integrity
5.1 Encryption Architecture.
All media and data stored in the Evidence Vault is protected by the following encryption layers:
5.2 Per-Chunk Integrity Checksum Records.
Each 5–10 second media segment is individually hashed using integrity checksum. The following metadata is stored alongside each hash: the integrity checksum value; recording timestamp; GPS coordinates at time of recording (if location services active); device identifier; and server-side upload receipt timestamp. This approach provides a per-chunk integrity record without employing hash chaining, Merkle trees, blockchain, or distributed ledger technology.
5.3 long-term evidence preservation Immutability and Long-Term Retention.
Evidence stored in the 7-Year Legal Vault for Premium and Family tier subscribers is written to long-term evidence preservation (restricted-access evidence preservation) immutable storage hosted on DigitalOcean infrastructure. Once evidence is committed to restricted-access long-term storage, it cannot be altered, deleted, overwritten, or modified by RestfulSync, Inc., LawYeti, Inc., any employee, or any user through any platform interface for the duration of the 7-year retention period. This immutability is a core design feature intended to preserve evidentiary integrity.
5.4 The 60-Second Exception Window.
SOS media is committed to long-term restricted-access long-term storage only if the SOS alarm is not cancelled within 60 seconds of activation. If cancelled within this window, the media session will not be automatically committed to long-term storage. If you cancel an SOS alarm that was a genuine emergency event, you should manually commit the evidence through the Post-Incident Evidence Wizard before it is purged from temporary storage.
5.5 Role-Based Access to Evidence Vault.
Access to Evidence Vault contents is governed by strict role-based access controls (RBAC). Your stored evidence is accessible to: you (the account holder and submitter); authorized RestfulSync engineering and security personnel on a need-to-know basis for system maintenance, security investigations, or legal compliance; and, in the case of minor users, the parent or guardian who holds the verified parental consent on the account. No other party — including participating attorneys, other users, RestfulSync sales or marketing personnel, or any external party — has access to your Evidence Vault contents, except as required by law or compelled by valid legal process.
5.6 Evidence Vault and Legal Process.
RestfulSync may be required to disclose Evidence Vault contents in response to valid legal process, including court orders, subpoenas, search warrants, or governmental requests. RestfulSync will, to the extent legally permissible, provide you with prior notice of any such disclosure request so that you may seek a protective order or other appropriate relief. RestfulSync will disclose only the minimum evidence necessary to comply with the specific legal process.
Section 7 — Calls, Video Consultations, and Recording Metadata
7.1 Call and Video Session Recording Policy.
Calls and video consultations facilitated through the LawYeti attorney connection module are not recorded by default. If a recording feature is activated (subject to the Compliance Decision Engine's jurisdiction-based restrictions), the system will always require affirmative consent before recording begins. Any recordings made with consent are stored in encrypted form in the Evidence Vault and are treated as confidential.
7.2 Call and Session Metadata.
Regardless of whether a call or session is recorded, RestfulSync collects session metadata for all consultations facilitated through the platform, including: session start and end times; session duration; participant identifiers (account IDs, not raw personal information); practice area category; billing status (New Matter vs. Recurring Matter); and payment events. This metadata is retained for the period applicable to account data (generally 7 years) and is used for billing accuracy, dispute resolution, fraud prevention, and quality assurance.
7.3 Recording Compliance and Overt Notice.
As described in the RestfulSync Terms of Use (Article XI), the CDE automatically applies recording compliance profiles based on detected jurisdiction. In all-party consent jurisdictions (Profile B states), audio recording is only active if effective overt notice can be delivered to all parties. If overt notice cannot be confirmed, audio is automatically disabled. RestfulSync retains records of: the jurisdiction profile applied to each recording session; whether overt notice was successfully delivered; and whether audio was active or automatically disabled during the session. These records are maintained as part of RestfulSync's regulatory compliance documentation.
Section 9 — Data Retention Schedule
We retain personal information for specific, defined periods based on the nature of the data and the legal, business, and operational purposes for which it was collected. The following table sets forth our data retention schedule:
Data Category Retention Period Notes
Account & Profile Data 7 years from last interaction Or from account closure
Evidence Vault — 7-Year long-term evidence preservation (Premium/Family) 7 years from capture date Immutable; cannot be deleted early
Evidence Vault — 1-Year Cloud (Plus) 1 year from capture date May be deleted upon account closure
Device-Local Media (Essential) Not retained by RestfulSync User's sole responsibility
SOS Event Logs (Premium/Family) 7 years Tied to long-term evidence preservation vault retention
SOS Event Logs (Essential/Plus) 90 days Then deleted or de-identified
Precise GPS Session Data (Active Session) Duration of session only Not stored beyond active session
GPS Session Metadata (Paid Tiers) Up to vault retention period Route summary, times, not raw GPS track
Chat / AI Triage Transcripts 7 years Aligned with account retention
Call / Video Consultation Metadata 7 years Start/end time, duration, participants
Fraud Logs (IP / Device Fingerprint) 12 months, then anonymized/hashed Raw identifiers purged after 12 mo.
Referral Program Data Duration of program + 12 months Then deleted or de-identified
Non-Converted Inquiries 90 days Then deleted or de-identified
Payment Records (Stripe) 7 years Required for tax/financial compliance
Parental Consent Records Duration of minor's account + 3 years COPPA compliance
9.1 long-term evidence preservation Retention and Deletion Limitations.
Evidence stored in restricted-access long-term storage (Premium and Family tier users' 7-Year Legal Vault) cannot be deleted, altered, or overwritten during the 7-year retention period, even in response to a data deletion request. If you submit a data deletion request under Section 11 and you have data in restricted-access long-term storage, we will delete all other personal information associated with your account but will be legally and technically unable to delete long-term retention-stored evidence until the 7-year retention period expires. We will inform you of this limitation in our response to any deletion request.
9.2 Legal Hold and Preservation Obligations.
Notwithstanding the above retention schedule, RestfulSync may retain personal information beyond the standard retention period if: (a) it is subject to a legal hold or preservation order in connection with actual or reasonably anticipated litigation or legal proceedings; (b) it is required by applicable law or regulatory obligation; or (c) it is necessary to resolve an active dispute, investigation, or enforcement matter.
9.3 Secure Deletion.
Upon expiration of the applicable retention period (or upon a valid data deletion request for non-long-term evidence preservation data), personal information is securely deleted from active databases and, after an additional period for backup purging, from backup systems as well.
Section 10 — Security
10.1 Security Measures.
RestfulSync implements the following technical and organizational security measures to protect your personal information:
10.2 Security Incident Response.
RestfulSync maintains an internal Incident Response Plan for handling data security incidents efficiently. In the event of a suspected or confirmed security incident, we investigate promptly, contain the incident, assess the scope of any impact, and notify affected users and applicable regulatory authorities as required by law. Our security contact is security@restfulsync.com. We encourage security researchers and users to report any potential vulnerabilities or security concerns through this contact.
10.3 Your Role in Security.
While RestfulSync implements extensive security measures, you also play an important role in protecting your account. You are responsible for: maintaining the confidentiality of your account credentials; using a strong, unique password; enabling device-level security features (e.g., device PIN, biometric lock); and notifying RestfulSync immediately at security@restfulsync.com of any suspected unauthorized access to your account. RestfulSync is not liable for account security compromises caused by your failure to maintain adequate credential security.
Section 11 — Your Privacy Rights
RestfulSync honors privacy rights under all applicable U.S. state privacy laws. We apply the most stringent applicable standard to all users where those standards require broader protections. The following table summarizes applicable privacy rights:
Right Who Has It How to Exercise
Right to Know / Access All users; CCPA/CPRA mandated for CA residents Email privacy@restfulsync.com — "Right to Access"
Right to Delete All users; CCPA/CPRA mandated for CA residents Email privacy@restfulsync.com — "Right to Delete"
Right to Correct All users; CPRA mandated for CA residents Update in-app or email privacy@restfulsync.com
Right to Data Portability All users; required in VA, CO, CT, and others Email privacy@restfulsync.com — "Data Portability"
Right to Opt Out of Sale/Sharing All users (we do not sell data) See Section 11.4 — no action required
Right to Limit Sensitive Data Use CA residents (CPRA) Email privacy@restfulsync.com
Right to Non-Discrimination All users Automatically honored
Right to Appeal a Denial Required in VA, CO, CT, TX, and others Email privacy@restfulsync.com — "Appeal"
Parental Right to Access/Delete (Minors) Parents/guardians of minor users Email privacy@restfulsync.com
11.1 California Residents (CCPA / CPRA).
California residents have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
11.2 Other U.S. State Privacy Laws.
Users in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive consumer privacy laws have similar rights, including rights to access, delete, correct, and obtain a portable copy of their personal data, and to opt out of profiling and certain automated processing decisions. RestfulSync honors valid requests under these state laws in a manner consistent with each state's specific requirements. If we deny a request that you believe is valid, we will provide a written explanation and information about how to appeal the denial within the timeframes required by applicable law.
11.3 How to Exercise Your Rights.
To submit a privacy rights request, contact us by email at privacy@restfulsync.com with the subject line identifying your request (e.g., "Right to Access," "Right to Delete," "Data Portability," or "Appeal"). You may also mail a written request to RestfulSync, Inc., Attn: Privacy Rights, c/o Legal Department.
Section 12 — Children's Privacy and COPPA Compliance
12.1 Age Threshold and Data Collection Restrictions.
RestfulSync does not knowingly collect personal information from children under 13 years of age without verified parental consent (VPC) as required by the Children's Online Privacy Protection Act (COPPA). Our platform's onboarding flow requires all users to confirm their age. Access to all data-collecting features is blocked for users under 13 pending completion of the VPC workflow.
12.2 Teen Users (Ages 13–17).
Users between the ages of 13 and 17 may access a restricted set of features after verified parental or guardian consent is completed. For teen users, we collect only the personal information necessary to operate the permitted features (SOS, location sharing with Emergency Contacts, recording, and Emergency Contact management). The Attorney Connection module and all payment features are disabled for users under 18. Parental consent records for teen users are retained for the duration of the minor's account plus 3 years for COPPA compliance documentation purposes.
12.3 Parental Rights.
12.4 Reporting Underage Accounts Without VPC.
If you believe a child under the applicable age threshold has created a RestfulSync account without verified parental consent, please notify us immediately at privacy@restfulsync.com. We will promptly investigate and, if confirmed, delete the account and associated personal information, and may notify the parent or guardian.
Section 13 — HIPAA-Adjacent Safeguards and Health-Sensitive Data
13.1 RestfulSync Is Generally Not a HIPAA Covered Entity.
RestfulSync, Inc. is generally not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA). However, users may submit information in the context of Evidence Wizard entries, legal inquiries, or AI Triage sessions that touches on health or medical circumstances. RestfulSync applies safeguards to any health-related or especially sensitive personal information consistent with the spirit of HIPAA's minimum necessary and security standards, even where HIPAA does not technically apply.
13.2 Applicable Safeguards for Health-Sensitive Information.
Section 14 — Data Transfers and International Considerations
RestfulSync is operated by RestfulSync, Inc., a Delaware corporation, and the Services are hosted and operated primarily within the United States. If you access the Services from outside the United States, you acknowledge that your personal information will be processed and stored in the United States, which may have different data protection laws than your country of residence. Where required by applicable law, we implement appropriate safeguards for cross-border data transfers (such as Standard Contractual Clauses for transfers from the European Economic Area, where applicable). At this time, RestfulSync's Services are primarily designed for use within the United States.
Section 15 — Security Incidents and Breach Notification
Despite our best efforts to protect your personal information, data security incidents can occur. If RestfulSync experiences a data breach or security incident that compromises the privacy or security of your personal information, we will:
Contain the incident and assess its scope as quickly as possible.
Notify affected users as required by applicable law — all 50 U.S. states and Washington, D.C. have data breach notification laws. We will comply with the most stringent applicable requirements, targeting notification as quickly as feasible consistent with law enforcement needs and the requirements of the investigation.
Notify applicable regulatory authorities as required by law.
Provide you with information about what happened (to the extent known), what information was involved, what we are doing in response, and any steps you can take to protect yourself.
Breach notifications will be provided by email to your registered email address, by in-app notification, and/or by any other method required by applicable law. We will also fulfill any regulator or agency notification obligations, including notifying state Attorneys General or other officials where required.
To report a potential security vulnerability or incident, contact security@restfulsync.com. We appreciate responsible disclosure from security researchers and take all reports seriously.
Section 16 — Third-Party Services and Links
16.1 Third-Party Privacy Practices.
RestfulSync integrates with and relies upon third-party service providers as described in Section 6. These providers — including Stripe, DigitalOcean, SMS delivery carriers, the emergency support service, and the location/telematics SDK provider — operate under their own privacy policies and terms of service. RestfulSync is not responsible for the privacy practices of these third-party providers. We encourage you to review the privacy policies of any third-party service you interact with through the platform.
16.2 No External Links in Safety Features.
RestfulSync's Safety Stack features do not generate external links, third-party map URLs, or tracking links. All location sharing is conducted within the platform's walled-garden architecture. This design prevents inadvertent disclosure of your location to third-party analytics or advertising platforms through link-click tracking.
16.3 No Third-Party Advertising.
RestfulSync products are operated as ad-free environments by RestfulSync, Inc. RestfulSync does not display advertising, does not allow advertisers to pay to have content promoted in the Services, and does not share user data with advertising networks or data brokers.
Section 17 — Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or applicable laws. If we make any material changes to how we collect, use, share, or retain personal information, we will notify you by:
Sending an email notification to your registered email address;
Displaying a prominent in-app notification when you next open the application; and/or
Posting a notice on our website at least fourteen (14) days before the changes take effect.
The "Last Updated" date at the top of this Policy will always indicate when the most recent changes were made. By continuing to use the Services after a revised Privacy Policy takes effect, you are acknowledging and agreeing to the updated terms. If you do not agree with any changes, you should stop using the Services and may contact us to exercise your data rights.
Section 18 — Contact Us
If you have any questions, concerns, requests, or complaints regarding this Privacy Policy or our data practices, please contact us through one of the following channels:
For privacy requests, please include in your email: your full name; the email address associated with your RestfulSync account; the nature of your request (e.g., Right to Access, Right to Delete, Data Portability, Parental Rights Request, Security Report); and any relevant details that will help us process your request promptly.
We take all privacy inquiries seriously and will respond within the timeframes required by applicable law.
RestfulSync is formerly known as SafeZone. RestfulSync and LawYeti are products of LawYeti, Inc. and its affiliates.
