RestfulSync logo
RestfulSync
Privacy

Privacy Policy

Review how RestfulSync collects, uses, shares, retains, and protects personal information across the unified RestfulSync and LawYeti platform.

Document type

Privacy Policy

Brand note

Formerly known as SafeZone

Format

Public-facing legal document

Overview

RestfulSync, Inc. · A LawYeti Company · Incorporated in Delaware, USA

privacy@restfulsync.com · support@restfulsync.com

Preamble — About This Privacy Policy

This Privacy Policy explains how RestfulSync, Inc. ("RestfulSync," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you use the RestfulSync mobile application (formerly SafeZone), the unified LawYeti platform, the Evidence Vault, and all related services, features, and content (collectively, the "Services").

This Policy applies to all participants on the platform, including users (clients), Emergency Contacts designated by users, parents or guardians of minor users, promoters, and RestfulSync administrators. It does not apply to independent attorneys who access the platform through the separate LawYeti Attorney portal, who are governed by the LawYeti Attorney Privacy Policy.

Unified Platform Notice: RestfulSync and LawYeti share a single unified backend, user identity, Stripe customer profile, and Evidence Vault. Personal information you provide or generate through RestfulSync is part of the same data environment as your LawYeti account. This Privacy Policy should be read together with the LawYeti Privacy Policy and the RestfulSync Terms of Use. If anything in this Policy conflicts with a jurisdiction-specific notice or addendum that applies to you, RestfulSync will follow the requirements that apply in your jurisdiction.

Strictest-Jurisdiction Commitment

RestfulSync strives to comply with all applicable U.S. state privacy laws and incorporates the most stringent protections where they apply. California's CCPA/CPRA, Virginia's VCDPA, Colorado's CPA, Texas's TDPSA, and other state consumer privacy laws grant residents specific data rights — we have integrated these requirements into our platform. In the event that privacy laws differ by jurisdiction, we adhere to the strictest applicable standard to protect your privacy.

Section 1 — Scope, Key Definitions, and Privilege Warning

1.1 Definitions.

For purposes of this Privacy Policy, the following terms have the meanings set forth below:

"User" or "Client": An individual who uses the RestfulSync Safety Stack features and/or the LawYeti legal information and attorney connection features.

"Attorney": An independent licensed attorney who participates in the LawYeti platform to receive routed inquiries and provide legal consultations.

"Emergency Contact": An individual designated by a User to receive plain-text SMS alerts upon the User's SOS activation.

"Promoter": An individual or entity participating in RestfulSync's marketing, referral, or incentive programs.

"Personal Information": Information that identifies, relates to, describes, or could reasonably be linked with an individual or household, as defined under applicable privacy laws.

"Sensitive Information": Categories of personal data treated with heightened protections, including: precise geolocation data; audio and video recordings; biometric data; government-issued identification documents; health or medical information; financial account details; and personal information concerning minors.

"Evidence Vault": The unified encrypted storage infrastructure shared between RestfulSync and LawYeti where user media, documents, and evidence are stored, including long-term retention-protected long-term storage.

"AI Triage": RestfulSync/LawYeti's automated intake and issue-spotting functionality; does not provide legal advice.

"Compliance Decision Engine" or "CDE": The server-driven, on-device-enforced policy system that determines applicable recording compliance profiles based on detected geographic jurisdiction.

"Restricted-Access Long-Term Storage": restricted-access evidence preservation immutable storage infrastructure that prevents alteration or deletion of stored evidence.

1.2 Privilege and Confidentiality Warning.

Attorney-Client Privilege Disclaimer

RestfulSync, Inc. is not a law firm. Information submitted to RestfulSync before a user directly engages an independent attorney through the LawYeti module is generally NOT protected by attorney-client privilege. You should avoid including unnecessary highly sensitive personal, financial, or legal details in free-text fields on the platform until you have established a direct engagement with an independent attorney. Interactions with the AI Triage system are NOT protected by attorney-client privilege and do not constitute legal advice.

1.3 Scope of This Policy.

This Policy covers personal information collected: (a) directly from you when you create an account, use platform features, submit evidence, designate emergency contacts, or make purchases; (b) automatically through your use of the Services; and (c) from third-party service providers to the extent necessary to operate the platform. This Policy does not cover: personal information collected by independent attorneys from their own clients outside the platform; information collected by third-party websites or services linked to from the platform; or employer-administered deployments governed by a separate enterprise agreement.

Section 2 — Information We Collect

We collect personal information in three primary ways: (a) information you provide to us; (b) information collected automatically when you use the Services; and (c) information from third-party service providers as needed to operate the platform. We collect only the minimum personal information necessary for each stated purpose (data minimization principle).

2.1 Information You Provide Directly.

Account Registration Information: When you create a RestfulSync account, we collect your name, email address, phone number, and account credentials. Passwords are stored in a secure hashed form — RestfulSync never stores your password in plaintext. We also collect account preferences and settings you configure, including your selected subscription tier, notification preferences, and feature settings.
Emergency Contact Information: When you designate Emergency Contacts, we collect the name and phone number of each designated contact. We store this information solely for the purpose of transmitting plain-text SOS alerts on your behalf. Emergency Contact phone numbers are not used for marketing, advertising, or any purpose other than the delivery of safety alerts you have initiated. We rely on you to have the Emergency Contact's knowledge or consent before designating them.

Evidence Wizard Data — Scene Photos and Video: Video and photo media captured during a SafeWalk, SafeTrip, or SOS session is uploaded to the Evidence Vault in compliance with the applicable H.265/HEVC encoding standard. Each upload is accompanied by GPS coordinates (if location services are active), device identifier, and timestamp metadata. Media stored in long-term retention-protected storage for Premium and Family tier users cannot be deleted, altered, or modified by any party during the 7-year retention period.

Evidence Wizard Data — Voice Memos: Audio recordings captured through the Voice Memo feature are encrypted locally on your device before upload. Voice memos are stored in the Evidence Vault and are accessible only to you and authorized RestfulSync personnel under role-based access controls.

Evidence Wizard Data — Document Scans and OCR: When you scan a document using the Evidence Wizard, the scan is processed locally on your device using on-device OCR (optical character recognition). The OCR processing does not send raw document images to a remote server for text recognition — recognition is performed entirely on your device. The resulting scanned image and OCR text output are then encrypted and uploaded to the Evidence Vault. This design minimizes the transmission of potentially sensitive document content to remote servers.

Evidence Wizard Data — Witness Information: Witness names, contact information, and scanned identification documents entered into the Evidence Wizard constitute Sensitive Information belonging to third parties. Please see Section 2.4 for the special handling rules applicable to third-party Sensitive Information. Please do not include Social Security numbers, full financial account numbers, or other highly sensitive identifiers in witness or scene description free-text fields. Our forms are designed to capture only what is necessary, and we may automatically mask or redact certain sensitive number patterns in free-text fields.

Legal Inquiry Information (LawYeti Module): When you submit a legal question, initiate an AI Triage session, or connect with an attorney through the LawYeti module, we collect the information you provide about your legal matter — including the legal category or practice area you select, a description of your issue, and your jurisdiction or state. This information is used to route your inquiry to appropriate attorneys and is shared with participating attorneys as described in Section 6.1.
Communications: If you send messages, chat with attorneys, or correspond with RestfulSync support through the platform, we collect and retain those communications, including chat logs, email or message content, and any attachments you provide. Communications with attorneys through the LawYeti module are retained as described in the LawYeti Privacy Policy.
Payment Information: When you make a purchase — including subscription fees, Booster Pack purchases, or the On-Demand Access Pass — payment is processed by Stripe. RestfulSync stores only your Stripe customer identifier. We do not store full credit card numbers, CVV codes, or bank account details. You should review Stripe's privacy policy for information about how Stripe handles your payment information.
Referral and Promoter Information: If you participate in a referral program, we collect your referral code submissions, the contact information of any individuals you refer (name and email or phone number, as applicable), and tracking data to confirm successful referrals. We rely on you to have the referred individual's permission before providing their contact information. Referral contact information is used only to send an initial invitation and track referral status; it is not used for any other marketing purpose.

2.2 Information Collected Automatically.

Device and Network Data: When you use the Services, we automatically collect: your device type, device model, device operating system version, device identifier, browser type and version, app version, network type (WiFi vs. cellular), and IP address. IP addresses are used for fraud prevention, security, and geo-detection by the Compliance Decision Engine.
Usage Data: We collect data about how you use the platform, including: the features you access; the pages or screens you view; session start and end times; session duration; feature activation events (e.g., SOS activations, session initiations, Evidence Wizard opens); and error and crash logs. Usage data is used to operate the platform, improve features, detect abuse, and enforce billing limits.
Compliance Decision Engine Jurisdiction Data: When you use recording or location-sharing features, the CDE automatically detects your geographic jurisdiction at the state level using your device's GPS data (if available) or IP address as a fallback. This jurisdiction detection is used solely to apply the appropriate recording compliance profile (Profiles A–D as described in the Terms of Use). The CDE's jurisdiction detection is not a continuous location tracking mechanism and does not create a persistent location history.
Fraud Detection Data: For fraud prevention and account integrity purposes, we collect IP address, device fingerprint, session metadata, and usage pattern data. This data is retained for up to 12 months, after which IP address and device fingerprint data in fraud logs is programmatically anonymized or hashed.
SOS Activation Logs: When you activate the SOS or Panic workflow, we log: the activation timestamp; your GPS coordinates at the moment of activation (if location services are active); the SMS delivery status for each Emergency Contact notification; and whether the 60-second exception window was exercised to cancel the alarm.

2.3 Opt-In Only — Enhanced Sensitivity Information.

The following categories of Sensitive Information are collected only upon your explicit affirmative consent and are never collected without it:

Precise Geolocation (Live Map / Real-Time Tracking): We collect real-time GPS coordinates only when you explicitly activate a Live Map or Safe Trip location-sharing session. You may revoke consent at any time by ending the active session. We do not engage in background location tracking outside of an active, user-initiated session. For Essential tier users, precise GPS data is not stored beyond the active session.
Audio Recording: Audio recording is enabled only when you initiate a recording session and only if the Compliance Decision Engine determines that audio recording is permitted in your current jurisdiction. In all-party consent jurisdictions (Profile B), the CDE may automatically disable audio recording if multi-signal overt notice cannot be confirmed. You will always be informed when audio recording is active through the in-app recording indicator and audible notice tone (where required).
Video Recording: Video recording is enabled only when you initiate a recording session. Recording is always overt — the in-app recording indicator is always visible when recording is active.

2.4 Special Handling of Third-Party Sensitive Information in the Evidence Wizard.

Witness contact information, scanned identification documents (driver's licenses, passports, government IDs), and other personal information belonging to individuals who are not RestfulSync users constitute Sensitive Information that you collect from and about third parties. RestfulSync applies the following protections to third-party Sensitive Information submitted through the Evidence Wizard:

Third-party Sensitive Information is encrypted end-to-end using AES-256 encryption before it leaves your device.

It is stored exclusively within the Evidence Vault and is not transmitted to any third-party service provider for processing, analysis, or storage other than the restricted-access long-term storage infrastructure (DigitalOcean) and the RestfulSync backend infrastructure.

Access is restricted to the submitting user and authorized RestfulSync personnel under strict role-based access controls (RBAC). No other user, attorney, or external party has access to third-party Sensitive Information you submit.

It is not used for any purpose other than storage in the Evidence Vault and user-directed retrieval.

It is retained for the applicable vault retention period and then securely deleted.

As noted in the Terms of Use, you are solely responsible for ensuring that you are authorized to collect and submit third-party personal information, and that you comply with all applicable privacy laws in doing so.

Section 3 — How We Use Your Information

We use your personal information only for legitimate, specified purposes associated with operating the platform, providing the Services, and meeting our legal obligations. We do not use your personal information for purposes incompatible with those disclosed in this Policy without your consent. Specifically:

Service Delivery: To operate the Safety Stack features, Evidence Vault, Attorney Connection module, AI Triage, and all other platform features. This includes processing SOS activations, transmitting Emergency Contact alerts, generating per-chunk integrity checksum records for evidence integrity, applying recording compliance profiles, and routing legal inquiries to available attorneys.
Emergency Contact Alert Delivery: To transmit plain-text SMS alert messages to your designated Emergency Contacts upon your SOS activation. SMS alerts contain only the information necessary to notify your contacts of a safety event — no tracking links, URLs, or sensitive personal data are included.
Third-Party Emergency Support Workflow Integration: To transmit relevant SOS event data (activation timestamp, GPS coordinates, and account identifiers) to our third-party emergency support service partner to enable human operator verification and coordination with emergency services upon your SOS activation.
Location Sharing: To transmit your real-time GPS coordinates through the third-party telematics and location SDK to your designated trusted contacts or Emergency Contacts during an active, user-initiated location-sharing session.
Evidence Integrity: To generate and store per-chunk integrity checksum records and associated metadata for captured media, supporting chain-of-custody documentation.
Recording Compliance Enforcement: To detect your geographic jurisdiction and apply the appropriate recording compliance profile (A–D) through the CDE, ensuring automatic compliance with state recording laws.
Account Management and Communications: To verify your account, manage your subscription, process your payments, respond to your support requests, and send necessary service communications (account verification, billing receipts, security alerts).
Attorney Connection Routing: To share relevant intake information with participating attorneys when you initiate a legal consultation through the LawYeti module.
Billing and Payment Processing: To facilitate Stripe payment transactions for subscriptions, Booster Pack purchases, the On-Demand Access Pass, the Technology & Connectivity Fee, and attorney consultation fees.
Referral Program Administration: To track referral eligibility, verify referral authenticity, and award Access Pass unlocks or other referral incentives.
Platform Security and Fraud Prevention: To detect and prevent misuse, account circumvention, billing fraud, referral fraud, SOS abuse, and unauthorized access. This includes monitoring IP addresses, device fingerprints, and usage patterns for anomalous activity.
COPPA Compliance: To enforce age-based feature restrictions, process parental consent workflows, and maintain records of verifiable parental consent for minor users.
Platform Improvement: To analyze aggregated, de-identified usage data to debug issues, improve features, optimize the CDE's jurisdiction detection, and develop new capabilities. We will not use your personally identifiable information for model training purposes without your express consent.
Legal and Regulatory Compliance: To comply with applicable laws, court orders, government investigations, and legal process, including data breach notification obligations and data preservation requirements.

We do not sell your personal information to any third party for their own marketing or commercial use. We do not share your personal information for cross-context behavioral advertising purposes.

Section 4 — AI Triage and Automated Processing

4.1 Privilege Warning and Scope of AI Processing.

The AI Triage feature is an automated intake and issue-spotting tool designed to collect general information about your legal matter and route it to appropriate attorneys. Before you begin an AI Triage session, the platform displays a clear notice that conversations with the AI are not protected by attorney-client privilege and are not a substitute for actual legal advice. The AI Triage system collects: your free-text description of your legal issue; the legal category you select; your jurisdiction; any follow-up responses you provide during the session; and session metadata.

4.2 AI Processing and Data Handling.

AI Triage session data is processed by RestfulSync's automated systems to generate informational issue-spotting responses and to route your inquiry to available attorneys in the appropriate practice area. A limited number of authorized RestfulSync staff may review selected AI Triage transcripts for quality assurance, safety monitoring, or in response to reported issues.

4.3 Third-Party AI Providers.

To the extent RestfulSync utilizes third-party AI services to power the AI Triage chatbot or other AI features, we transmit only the minimum information necessary for the AI functionality to operate. Our agreements with such providers expressly prohibit them from using RestfulSync user data to train, fine-tune, or improve their general AI models, or from retaining or selling your data.

4.4 AI Output Limitations.

AI Triage outputs are for general informational purposes only. They may not be accurate, current, or applicable to your specific jurisdiction or circumstances. The AI may not be aware of recent legal developments. You should not rely on AI Triage outputs as legal advice and should consult a licensed attorney for advice specific to your situation.

Section 5 — Evidence Vault: Data Handling, Encryption, and Integrity

5.1 Encryption Architecture.

All media and data stored in the Evidence Vault is protected by the following encryption layers:

At Rest: All Evidence Vault data is encrypted at rest using AES-256 encryption. Encryption keys are managed by RestfulSync under strict key management procedures with role-based access controls.
In Transit: All data transmitted between your device and RestfulSync servers is encrypted using TLS (Transport Layer Security) 1.2 or higher.
End-to-End for Evidence Wizard Third-Party Data: Third-party Sensitive Information entered through the Evidence Wizard (witness information, scanned IDs) is encrypted on your device before transmission, providing an additional layer of protection for this especially sensitive category.

5.2 Per-Chunk Integrity Checksum Records.

Each 5–10 second media segment is individually hashed using integrity checksum. The following metadata is stored alongside each hash: the integrity checksum value; recording timestamp; GPS coordinates at time of recording (if location services active); device identifier; and server-side upload receipt timestamp. This approach provides a per-chunk integrity record without employing hash chaining, Merkle trees, blockchain, or distributed ledger technology.

5.3 long-term evidence preservation Immutability and Long-Term Retention.

Evidence stored in the 7-Year Legal Vault for Premium and Family tier subscribers is written to long-term evidence preservation (restricted-access evidence preservation) immutable storage hosted on DigitalOcean infrastructure. Once evidence is committed to restricted-access long-term storage, it cannot be altered, deleted, overwritten, or modified by RestfulSync, Inc., LawYeti, Inc., any employee, or any user through any platform interface for the duration of the 7-year retention period. This immutability is a core design feature intended to preserve evidentiary integrity.

5.4 The 60-Second Exception Window.

SOS media is committed to long-term restricted-access long-term storage only if the SOS alarm is not cancelled within 60 seconds of activation. If cancelled within this window, the media session will not be automatically committed to long-term storage. If you cancel an SOS alarm that was a genuine emergency event, you should manually commit the evidence through the Post-Incident Evidence Wizard before it is purged from temporary storage.

5.5 Role-Based Access to Evidence Vault.

Access to Evidence Vault contents is governed by strict role-based access controls (RBAC). Your stored evidence is accessible to: you (the account holder and submitter); authorized RestfulSync engineering and security personnel on a need-to-know basis for system maintenance, security investigations, or legal compliance; and, in the case of minor users, the parent or guardian who holds the verified parental consent on the account. No other party — including participating attorneys, other users, RestfulSync sales or marketing personnel, or any external party — has access to your Evidence Vault contents, except as required by law or compelled by valid legal process.

5.6 Evidence Vault and Legal Process.

RestfulSync may be required to disclose Evidence Vault contents in response to valid legal process, including court orders, subpoenas, search warrants, or governmental requests. RestfulSync will, to the extent legally permissible, provide you with prior notice of any such disclosure request so that you may seek a protective order or other appropriate relief. RestfulSync will disclose only the minimum evidence necessary to comply with the specific legal process.

Section 6 — How We Share Your Information

6.1 With Participating Attorneys (LawYeti Module).

When you initiate a legal consultation or submit a legal inquiry through the LawYeti module, we share relevant intake information — including your legal category selection, issue description, jurisdiction, and AI Triage session summary — with participating attorneys who are eligible to respond to your inquiry. This sharing is necessary to enable attorneys to evaluate and respond to your request. Attorneys are bound by professional confidentiality obligations and by RestfulSync's attorney platform rules, which prohibit them from using intake information for any purpose other than responding to your inquiry.

6.2 With Emergency Contacts.

Upon your SOS activation, we transmit plain-text SMS alerts to your designated Emergency Contacts. These messages contain only human-readable safety notification text. No personal profile data, account information, or tracking links are shared with Emergency Contacts. Emergency Contact phone numbers are not shared with any other party.

6.3 With the Third-Party Emergency Support Service.

Upon SOS activation, we transmit relevant safety event data — including activation timestamp, GPS coordinates (if available), and account identifiers — to our third-party emergency support service partner. This partner's human operators use this information to verify the alert and, if appropriate, contact emergency services on your behalf. By activating the SOS feature, you consent to this data transfer. The dispatch service operates under its own privacy policy and terms of service; RestfulSync is not responsible for the dispatch service's data handling practices.

6.4 With the Third-Party Location / Telematics SDK.

Your real-time GPS coordinates are transmitted through a third-party telematics and location SDK during active, user-initiated Live Map or Safe Trip sessions. This transmission occurs only with your explicit consent and for the duration of the active session only. The SDK provider does not retain your precise GPS data beyond the active session for purposes other than delivering the location-sharing functionality. By activating a location-sharing session, you consent to this data transmission.

6.5 With Service Providers and Infrastructure Vendors.

We share personal data with carefully selected service providers and infrastructure vendors to the minimum extent necessary for them to perform their functions on our behalf. These providers include:

DigitalOcean: restricted-access long-term storage infrastructure for the 7-Year Legal Vault.
Stripe: Payment processing and Stripe customer identity management.
SMS delivery providers: Transmission of plain-text SOS alert messages to Emergency Contacts.
Video infrastructure providers: Support for the LawYeti attorney video consultation feature.
Cloud infrastructure providers: General application hosting and backend services.

All service providers are contractually prohibited from using RestfulSync user data for their own commercial purposes, from selling or sharing user data with additional third parties, and from retaining user data beyond what is necessary to perform their contracted services.

6.6 For Legal Compliance and Mandatory Disclosure.

We may disclose personal information as required by applicable law, court order, subpoena, search warrant, or governmental request. We may also disclose personal information where we believe in good faith that disclosure is necessary to protect the safety of any person, to investigate or prevent fraud or illegal activity, or to protect RestfulSync's legal rights. We will provide you with notice of any such disclosure to the extent legally permissible.

6.7 Business Transfers.

In the event of a merger, acquisition, asset sale, corporate reorganization, or similar transaction involving RestfulSync, Inc. or its parent company LawYeti, Inc., your personal information may be transferred to the acquiring or successor entity as part of the transaction. We will require the acquirer to honor this Privacy Policy, or provide you with notice and an opportunity to delete your data before the transfer takes effect.

6.8 What We Do NOT Do.

Data Sharing Commitments

We DO NOT sell your personal information to any third party for their own marketing or commercial use.

We DO NOT share your personal information for cross-context behavioral advertising or targeted advertising.

We DO NOT provide Emergency Contact phone numbers to any third party for marketing.

We DO NOT share Evidence Vault contents with any party other than as described in this Section.

We DO NOT allow participating attorneys to access Evidence Vault contents not related to their consultation.

We DO NOT use AI Triage data to train general-purpose AI models without your express consent.

Section 7 — Calls, Video Consultations, and Recording Metadata

7.1 Call and Video Session Recording Policy.

Calls and video consultations facilitated through the LawYeti attorney connection module are not recorded by default. If a recording feature is activated (subject to the Compliance Decision Engine's jurisdiction-based restrictions), the system will always require affirmative consent before recording begins. Any recordings made with consent are stored in encrypted form in the Evidence Vault and are treated as confidential.

7.2 Call and Session Metadata.

Regardless of whether a call or session is recorded, RestfulSync collects session metadata for all consultations facilitated through the platform, including: session start and end times; session duration; participant identifiers (account IDs, not raw personal information); practice area category; billing status (New Matter vs. Recurring Matter); and payment events. This metadata is retained for the period applicable to account data (generally 7 years) and is used for billing accuracy, dispute resolution, fraud prevention, and quality assurance.

7.3 Recording Compliance and Overt Notice.

As described in the RestfulSync Terms of Use (Article XI), the CDE automatically applies recording compliance profiles based on detected jurisdiction. In all-party consent jurisdictions (Profile B states), audio recording is only active if effective overt notice can be delivered to all parties. If overt notice cannot be confirmed, audio is automatically disabled. RestfulSync retains records of: the jurisdiction profile applied to each recording session; whether overt notice was successfully delivered; and whether audio was active or automatically disabled during the session. These records are maintained as part of RestfulSync's regulatory compliance documentation.

Section 8 — Cookies, Tracking Technologies, and Analytics

8.1 Types of Technologies Used.

RestfulSync uses the following types of cookies and tracking technologies:

Essential / Strictly Necessary: Required for the platform to function. These include session cookies that keep you logged in, authentication tokens, and security tokens. You cannot opt out of essential cookies without disabling the Services entirely.
Analytics and Performance: Used to understand how users interact with the platform, which features are most used, and where errors occur. Analytics data is aggregated and de-identified before analysis. We do not use third-party advertising analytics.
Fraud Detection: Device fingerprinting and session tracking used to detect fraudulent account creation, billing circumvention, and other abuse. This data is used solely for security purposes and is anonymized after 12 months.

8.2 No Advertising Cookies.

RestfulSync does not use third-party advertising cookies, cross-site tracking technologies, or behavioral advertising profiling of any kind. RestfulSync products are ad-free environments.

8.3 User Controls.

You may control analytics cookies through your device's operating system settings or browser settings. Disabling cookies may impair certain platform features. For mobile app analytics, you may opt out through your device's privacy settings. To opt out of all non-essential analytics tracking, contact privacy@restfulsync.com.

Section 9 — Data Retention Schedule

We retain personal information for specific, defined periods based on the nature of the data and the legal, business, and operational purposes for which it was collected. The following table sets forth our data retention schedule:

Data Category Retention Period Notes

Account & Profile Data 7 years from last interaction Or from account closure

Evidence Vault — 7-Year long-term evidence preservation (Premium/Family) 7 years from capture date Immutable; cannot be deleted early

Evidence Vault — 1-Year Cloud (Plus) 1 year from capture date May be deleted upon account closure

Device-Local Media (Essential) Not retained by RestfulSync User's sole responsibility

SOS Event Logs (Premium/Family) 7 years Tied to long-term evidence preservation vault retention

SOS Event Logs (Essential/Plus) 90 days Then deleted or de-identified

Precise GPS Session Data (Active Session) Duration of session only Not stored beyond active session

GPS Session Metadata (Paid Tiers) Up to vault retention period Route summary, times, not raw GPS track

Chat / AI Triage Transcripts 7 years Aligned with account retention

Call / Video Consultation Metadata 7 years Start/end time, duration, participants

Fraud Logs (IP / Device Fingerprint) 12 months, then anonymized/hashed Raw identifiers purged after 12 mo.

Referral Program Data Duration of program + 12 months Then deleted or de-identified

Non-Converted Inquiries 90 days Then deleted or de-identified

Payment Records (Stripe) 7 years Required for tax/financial compliance

Parental Consent Records Duration of minor's account + 3 years COPPA compliance

9.1 long-term evidence preservation Retention and Deletion Limitations.

Evidence stored in restricted-access long-term storage (Premium and Family tier users' 7-Year Legal Vault) cannot be deleted, altered, or overwritten during the 7-year retention period, even in response to a data deletion request. If you submit a data deletion request under Section 11 and you have data in restricted-access long-term storage, we will delete all other personal information associated with your account but will be legally and technically unable to delete long-term retention-stored evidence until the 7-year retention period expires. We will inform you of this limitation in our response to any deletion request.

9.2 Legal Hold and Preservation Obligations.

Notwithstanding the above retention schedule, RestfulSync may retain personal information beyond the standard retention period if: (a) it is subject to a legal hold or preservation order in connection with actual or reasonably anticipated litigation or legal proceedings; (b) it is required by applicable law or regulatory obligation; or (c) it is necessary to resolve an active dispute, investigation, or enforcement matter.

9.3 Secure Deletion.

Upon expiration of the applicable retention period (or upon a valid data deletion request for non-long-term evidence preservation data), personal information is securely deleted from active databases and, after an additional period for backup purging, from backup systems as well.

Section 10 — Security

10.1 Security Measures.

RestfulSync implements the following technical and organizational security measures to protect your personal information:

Encryption: AES-256 encryption for all data at rest in the Evidence Vault and databases; TLS 1.2+ for all data in transit; end-to-end encryption for third-party Sensitive Information in the Evidence Wizard.
Access Controls: Strict role-based access control (RBAC) limits internal access to personal data and Evidence Vault contents to authorized personnel on a documented need-to-know basis. Access is logged and audited.
Audit Logging: Detailed logs of all access to Sensitive Information and Evidence Vault contents are maintained and reviewed for anomalous activity.
Intrusion Detection and Prevention: Network monitoring, intrusion detection systems (IDS), and intrusion prevention systems (IPS) are deployed across RestfulSync infrastructure.
Long-Term Evidence Integrity Controls: restricted-access long-term storage technology prevents post-storage tampering, deletion, or modification of vaulted evidence at the infrastructure level.
Vulnerability Management: Regular security assessments, penetration testing, and dependency audits are conducted to identify and remediate vulnerabilities.
Employee Training: Authorized personnel with access to personal data receive privacy and security training and are bound by confidentiality obligations.

10.2 Security Incident Response.

RestfulSync maintains an internal Incident Response Plan for handling data security incidents efficiently. In the event of a suspected or confirmed security incident, we investigate promptly, contain the incident, assess the scope of any impact, and notify affected users and applicable regulatory authorities as required by law. Our security contact is security@restfulsync.com. We encourage security researchers and users to report any potential vulnerabilities or security concerns through this contact.

10.3 Your Role in Security.

While RestfulSync implements extensive security measures, you also play an important role in protecting your account. You are responsible for: maintaining the confidentiality of your account credentials; using a strong, unique password; enabling device-level security features (e.g., device PIN, biometric lock); and notifying RestfulSync immediately at security@restfulsync.com of any suspected unauthorized access to your account. RestfulSync is not liable for account security compromises caused by your failure to maintain adequate credential security.

Section 11 — Your Privacy Rights

RestfulSync honors privacy rights under all applicable U.S. state privacy laws. We apply the most stringent applicable standard to all users where those standards require broader protections. The following table summarizes applicable privacy rights:

Right Who Has It How to Exercise

Right to Know / Access All users; CCPA/CPRA mandated for CA residents Email privacy@restfulsync.com — "Right to Access"

Right to Delete All users; CCPA/CPRA mandated for CA residents Email privacy@restfulsync.com — "Right to Delete"

Right to Correct All users; CPRA mandated for CA residents Update in-app or email privacy@restfulsync.com

Right to Data Portability All users; required in VA, CO, CT, and others Email privacy@restfulsync.com — "Data Portability"

Right to Opt Out of Sale/Sharing All users (we do not sell data) See Section 11.4 — no action required

Right to Limit Sensitive Data Use CA residents (CPRA) Email privacy@restfulsync.com

Right to Non-Discrimination All users Automatically honored

Right to Appeal a Denial Required in VA, CO, CT, TX, and others Email privacy@restfulsync.com — "Appeal"

Parental Right to Access/Delete (Minors) Parents/guardians of minor users Email privacy@restfulsync.com

11.1 California Residents (CCPA / CPRA).

California residents have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

Right to Know / Access: You have the right to know what personal information we collect about you, for what purposes we use it, to whom we disclose it, and for how long we retain it. You may request a copy of the specific pieces of personal information we hold about you.
Right to Delete: You have the right to request that we delete personal information we have collected about you, subject to certain exceptions (such as long-term retention periods, legal hold obligations, or information necessary for an ongoing transaction). See Section 9.1 for long-term evidence preservation deletion limitations.
Right to Correct: You have the right to request correction of inaccurate personal information we maintain about you.
Right to Opt Out of Sale / Sharing: You have the right to direct us not to sell your personal information or share it for cross-context behavioral advertising. At this time, RestfulSync does not sell personal information and does not share it for advertising purposes. If that ever changes, we will provide a clear opt-out mechanism and update this Policy accordingly.
Right to Limit Use of Sensitive Personal Information: Under CPRA, you may have the right to limit our use of certain categories of sensitive personal information to only what is necessary to perform the Services. RestfulSync uses Sensitive Information only for the purposes disclosed in this Policy.
Right to Non-Discrimination: We will not discriminate against you for exercising any privacy right, including by denying Services, charging different prices, or providing a different level of service.

11.2 Other U.S. State Privacy Laws.

Users in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive consumer privacy laws have similar rights, including rights to access, delete, correct, and obtain a portable copy of their personal data, and to opt out of profiling and certain automated processing decisions. RestfulSync honors valid requests under these state laws in a manner consistent with each state's specific requirements. If we deny a request that you believe is valid, we will provide a written explanation and information about how to appeal the denial within the timeframes required by applicable law.

11.3 How to Exercise Your Rights.

To submit a privacy rights request, contact us by email at privacy@restfulsync.com with the subject line identifying your request (e.g., "Right to Access," "Right to Delete," "Data Portability," or "Appeal"). You may also mail a written request to RestfulSync, Inc., Attn: Privacy Rights, c/o Legal Department.

Identity Verification: For your security, we will verify your identity before fulfilling any rights request. Verification may involve confirming information on file, sending a verification code to your registered email or phone number, or requiring you to respond from your registered email address.
Authorized Agents: If you submit a request through an authorized agent, we may require proof of the agent's authorization (such as a signed power of attorney) and may still confirm your identity directly.
Response Timeframe: We will respond to valid privacy requests within 30 to 45 days of receipt, depending on the requirements of applicable state law. If we require additional time (up to a further 45 days in some jurisdictions), we will inform you of the reason and extension period in writing. We do not charge a fee to process privacy requests unless a request is excessive, repetitive, or manifestly unfounded, in which case we will explain why and may charge a reasonable fee or decline to act.

Section 12 — Children's Privacy and COPPA Compliance

12.1 Age Threshold and Data Collection Restrictions.

RestfulSync does not knowingly collect personal information from children under 13 years of age without verified parental consent (VPC) as required by the Children's Online Privacy Protection Act (COPPA). Our platform's onboarding flow requires all users to confirm their age. Access to all data-collecting features is blocked for users under 13 pending completion of the VPC workflow.

12.2 Teen Users (Ages 13–17).

Users between the ages of 13 and 17 may access a restricted set of features after verified parental or guardian consent is completed. For teen users, we collect only the personal information necessary to operate the permitted features (SOS, location sharing with Emergency Contacts, recording, and Emergency Contact management). The Attorney Connection module and all payment features are disabled for users under 18. Parental consent records for teen users are retained for the duration of the minor's account plus 3 years for COPPA compliance documentation purposes.

12.3 Parental Rights.

Parents or guardians of minor users who have completed the VPC process have the right to: review the personal information RestfulSync has collected about their minor child; request deletion of the minor's account and all associated personal information (subject to long-term retention limitations described in Section 9.1); revoke consent at any time; and receive notice of any material changes to our practices with respect to the minor's personal information. To exercise parental rights, contact privacy@restfulsync.com with the subject "Parental Rights Request."

12.4 Reporting Underage Accounts Without VPC.

If you believe a child under the applicable age threshold has created a RestfulSync account without verified parental consent, please notify us immediately at privacy@restfulsync.com. We will promptly investigate and, if confirmed, delete the account and associated personal information, and may notify the parent or guardian.

Section 13 — HIPAA-Adjacent Safeguards and Health-Sensitive Data

13.1 RestfulSync Is Generally Not a HIPAA Covered Entity.

RestfulSync, Inc. is generally not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA). However, users may submit information in the context of Evidence Wizard entries, legal inquiries, or AI Triage sessions that touches on health or medical circumstances. RestfulSync applies safeguards to any health-related or especially sensitive personal information consistent with the spirit of HIPAA's minimum necessary and security standards, even where HIPAA does not technically apply.

13.2 Applicable Safeguards for Health-Sensitive Information.

Minimum Necessary Access: Health-related information is treated as Sensitive Information and access is restricted to the minimum personnel necessary to perform the specified function.
Encryption: All Sensitive Information, including health-related content, is encrypted at rest and in transit as described in Section 10.1.
Audit Logging: Access to content containing health-sensitive information is logged and monitored.
Limited Retention: Tighter retention limits may apply to especially sensitive categories of data where technically and legally feasible.

Section 14 — Data Transfers and International Considerations

RestfulSync is operated by RestfulSync, Inc., a Delaware corporation, and the Services are hosted and operated primarily within the United States. If you access the Services from outside the United States, you acknowledge that your personal information will be processed and stored in the United States, which may have different data protection laws than your country of residence. Where required by applicable law, we implement appropriate safeguards for cross-border data transfers (such as Standard Contractual Clauses for transfers from the European Economic Area, where applicable). At this time, RestfulSync's Services are primarily designed for use within the United States.

Section 15 — Security Incidents and Breach Notification

Despite our best efforts to protect your personal information, data security incidents can occur. If RestfulSync experiences a data breach or security incident that compromises the privacy or security of your personal information, we will:

Contain the incident and assess its scope as quickly as possible.

Notify affected users as required by applicable law — all 50 U.S. states and Washington, D.C. have data breach notification laws. We will comply with the most stringent applicable requirements, targeting notification as quickly as feasible consistent with law enforcement needs and the requirements of the investigation.

Notify applicable regulatory authorities as required by law.

Provide you with information about what happened (to the extent known), what information was involved, what we are doing in response, and any steps you can take to protect yourself.

Breach notifications will be provided by email to your registered email address, by in-app notification, and/or by any other method required by applicable law. We will also fulfill any regulator or agency notification obligations, including notifying state Attorneys General or other officials where required.

To report a potential security vulnerability or incident, contact security@restfulsync.com. We appreciate responsible disclosure from security researchers and take all reports seriously.

Section 17 — Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or applicable laws. If we make any material changes to how we collect, use, share, or retain personal information, we will notify you by:

Sending an email notification to your registered email address;

Displaying a prominent in-app notification when you next open the application; and/or

Posting a notice on our website at least fourteen (14) days before the changes take effect.

The "Last Updated" date at the top of this Policy will always indicate when the most recent changes were made. By continuing to use the Services after a revised Privacy Policy takes effect, you are acknowledging and agreeing to the updated terms. If you do not agree with any changes, you should stop using the Services and may contact us to exercise your data rights.

Section 18 — Contact Us

If you have any questions, concerns, requests, or complaints regarding this Privacy Policy or our data practices, please contact us through one of the following channels:

Privacy and Data Rights: privacy@restfulsync.com
Security Incidents and Vulnerability Reports: security@restfulsync.com
Legal and Compliance: legal@restfulsync.com
General Support: support@restfulsync.com

For privacy requests, please include in your email: your full name; the email address associated with your RestfulSync account; the nature of your request (e.g., Right to Access, Right to Delete, Data Portability, Parental Rights Request, Security Report); and any relevant details that will help us process your request promptly.

We take all privacy inquiries seriously and will respond within the timeframes required by applicable law.

RestfulSync is formerly known as SafeZone. RestfulSync and LawYeti are products of LawYeti, Inc. and its affiliates.