Privacy
Last updated 19 August 2026
Used without an account, LeaveSafe reaches no server at all. The open-source daemon watches your machine and talks to your phone over your own network, and nothing on this page applies to it. Everything below is about the optional account, which exists so that a device can be reached from somewhere other than the same room.
Who is responsible
The data controller is SoftBlock Solutions Ltd, a company registered in England and Wales. Anything on this page can be asked about at support@softblocksolutions.com.
What an account is
An account is a sixteen-digit key and nothing else. There is no e-mail
address, no user name, no password and no recovery question — there is
nothing to recover an account to. What is stored is a keyed hash of
the key, for looking it up, and an argon2id verifier, for
checking it. The key itself cannot be reconstructed from either.
What is stored
| Record | Contents | Why |
|---|---|---|
| Account | A keyed hash of the master key, an argon2id verifier, status, device limit, creation and last sign-in times | To recognise the key you present without holding the key itself |
| Device | A name you chose, device type, platform, an installation identifier, the application version, a notification token, creation and last-seen times | To list your machines, and to let one be revoked without disturbing the others |
| Device state | Whether it is armed and one word about each sensor, with the time it was reported | So a watching device can see what an armed machine is doing. Written only while armed |
| Session | A hash of a refresh token, and its expiry | To keep you signed in without storing a password there is none of |
What is not stored
- No e-mail address, name, telephone number or postal address.
- No location. The open-source daemon has an optional location feature which is off by default and, when switched on, is not reported to this service.
- No analytics, no advertising identifier, no profiling, no automated decision-making.
- No third-party processor. There is no advertising network, no crash reporter and no analytics provider in the application or on this site.
- No cookie is set by this website, and it stores nothing in your browser.
What the phone application can reach
Nothing on your phone. The application asks for no camera, no location, no microphone, no Bluetooth, no contacts and no files, because it needs none of them: it is the end that watches. The six sensors belong to the program on the computer being watched, and no version of this application on any phone reads hardware of its own.
That is a fact about the product rather than a promise about our conduct, which is the more useful kind: a permission that is never requested cannot be misused.
Notifications
A device may hand the service a notification token so that a future version can reach it. No notification is sent today — nothing in the service delivers to that token yet. It is listed here because it is stored, not because it is used, and this page will say otherwise before that changes.
How long it is kept
Until you delete the account. Deleting it removes the account record and, with it, every device, session and device state belonging to it. There is no archive and no soft delete. See deleting your account.
Where it is
On a rented server in the European Union. The controller is in the United Kingdom, so that is a transfer out of the UK, and it is covered by the adequacy decision the UK maintains for the EEA. Nothing is transferred onward from there, because there is nobody to transfer it to: no processor, no analytics provider, no advertising network.
Your rights
Under the UK GDPR you may ask whether your data is processed and get a copy of it, have it corrected or erased, restrict or object to processing, and ask for it in a portable form. There is no automated decision-making here to object to, and no profiling.
If you are in Türkiye, Article 11 of Law No. 6698 gives you the same substance and we answer requests on that footing too: whether your data is processed, what and why, who it has been passed to at home or abroad, correction or deletion, notification of that to anyone it was passed to, objection to a conclusion drawn by automated analysis alone, and compensation for unlawful processing.
You can also complain to a regulator. Ours is the UK Information Commissioner's Office at ico.org.uk; in Türkiye it is the KVKK. We would rather you wrote to us first, but it is your right either way.
Write to support@softblocksolutions.com. Because an account carries no name and no address, we cannot identify you from one: a request has to be made from the application, or accompanied by the account key. We will say so rather than answer a request we cannot attribute — guessing would be the privacy failure, not the caution.
Children
LeaveSafe is not directed at children under 13, and collects nothing that would identify one.
Changes
The date at the top of this page is the date it last changed. A change that widens what is collected will be announced in the application before it takes effect.