Privacy notice
What we hold, and what we do not
ThreeSafe is built so that helping a lost child does not require anyone to learn who your family is. This page explains exactly what that means in data terms.
Last reviewed 8 August 2026.
The short version
We hold no readable name, age, date of birth, photo or description of any child. The only child-related thing we store is a one-way check built from the first name your child would say if asked. It is never displayed, never returned by any part of the service, and cannot be turned back into a name from our database alone.
Your three words are stored the same way. The plain phrase is shown only to you, in your own account and on your own printed card.
Every lookup is logged, matched or not, with the address it came from stored only as a one-way check. That log is what lets us see somebody probing. It is deleted after 12 months.
We never track a child’s location. There is no device, no tag and no map. If a product ever offers you that, it is a different product with a different risk profile.
Who we are
ThreeSafe is the data controller for the information described here. That means we decide what is collected and why, and we are the ones you complain to if we get it wrong.
- Registered name
- — to be confirmed before launch —
- Company number
- — to be confirmed before launch —
- Registered address
- — to be confirmed before launch —
- ICO registration
- — to be confirmed before launch —
- Data protection contact
- privacy@threesafe.org
We have not appointed a Data Protection Officer. At our size and scope the statutory tests for appointing one are not met. The address above reaches the person who is accountable for this notice.
What we hold
This is the whole inventory. If something is not in this table, we do not have it.
| What | Form it is stored in | Why |
|---|---|---|
| Your email address | As you typed it | To sign you in and to reach you about your account |
| Your three words | A one-way check, plus a readable copy visible only inside your own account | The one-way check is what a lookup matches against. The readable copy is what your card prints |
| Your child’s first name | Two one-way checks — one exact, one of how it sounds | So a finder typing the name your child says can be matched without us ever holding the name |
| A label for each child, such as “Child 1” | As you typed it | So you can tell your own entries apart. It is not the name, and we never ask for one |
| Your emergency contacts: a display name such as “Mum”, and a mobile number or email | As you typed it | So we can send the alert. Only contacts who confirmed their own number or address are ever messaged |
| Your family story, if you write one | As you typed it | A sentence you write to help your child remember. Shown only to you, never on any lookup |
| Alerts: the finder’s name and number, where they said they were, and the name they typed | As they typed it | So you can call them back. This is information about the finder, given by the finder |
| Lookup attempts: matched or not, and the address they came from | The address as a one-way check only | To detect somebody guessing at phrases. This is the abuse control |
We do not collect a date of birth, a photograph, a school, a home address, a description, or any location of any kind. There is no analytics profile, no advertising identifier, and nothing is sold or shared for marketing.
Children’s data, specifically
ThreeSafe is used by children, so we treat the ICO’s Age Appropriate Design Code as binding on us. Three points matter more than the rest.
- A child never has an account. There is nothing for a child to sign into, nothing for a child to consent to, and no way for a child to give us anything. The account belongs to a parent or carer.
- We hold a check, not a name. A first name is a weak secret — it is spoken aloud all day. It is useful to us only as a second factor alongside the words, so we store it in a form that can confirm a guess but cannot produce the name. The transformation uses a secret key held outside the database, so a stolen database alone does not reveal it.
- Nothing is optimised for engagement. There are no notifications designed to bring anyone back, no streaks, no profiling, and no nudges. The best outcome for a family is that they never use this service at all.
Why we are allowed to hold it
| What we do | Lawful basis | In plain terms |
|---|---|---|
| Run your account and hold your phrase | Contract (UK GDPR Art. 6(1)(b)) | You asked us to give you a phrase. We cannot do that without holding it |
| Send an alert to your contacts when a lookup matches | Vital interests (Art. 6(1)(d)), and contract | A child is separated from their family. This is the one thing the service exists to do |
| Message a contact you added | Legitimate interests (Art. 6(1)(f)) | They confirmed their own number before we would ever use it, and they can remove it at any time |
| Log lookups and rate-limit them | Legitimate interests (Art. 6(1)(f)) | Without this, somebody could sit and guess at phrases and nobody would notice |
We do not rely on consent for any of the above, so there is no consent to withdraw. You can delete your account instead, and everything goes with it.
How long we keep it
- Your account, phrase, contacts and children
- Kept until you ask us to delete it. When you delete it, everything above goes with it.
- Alerts and the messages sent for them
- 12 months. A venue may need to evidence a reunification afterwards, and an inspector may ask months later.
- Lookup logs
- 12 months. Long enough to see a slow, patient attacker; short enough not to be a standing liability.
- Sign-in links
- 15 minutes, then deleted
- Alert links sent to a parent
- 24 hours, then deleted
- The sign-in cookie
- 30 days, or until you sign out.
Deletion is enforced by a scheduled job rather than by anybody remembering to run it.
Your rights
Under UK GDPR you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete your account and everything attached to it;
- stop using your data in a particular way, or object to it;
- hand your data to you in a portable form.
Ask at privacy@threesafe.org. We will respond within one month, free of charge. We may ask you to confirm you control the email address on the account — we will not ask you for a passport or a utility bill.
One honest limit: we cannot show you your child’s stored name, because we do not have it. We can confirm that a check exists and delete it.
If you are unhappy with how we handle a request, you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We would rather you came to us first, but you do not have to.
To make a request or a complaint, email privacy@threesafe.org. Tell us what you want and which email address your account uses — we do not need anything about your child, and please do not send it.
How it is protected
- Phrases and child name checks are stored as keyed one-way digests. The key lives in the runtime environment, never in the database, so a database copy on its own cannot be worked backwards.
- Sign-in uses a single-use link rather than a password, so there is no password of yours for us to lose.
- Sign-in links, alert links and session tokens are stored hashed, are single-use, and expire.
- Lookups are rate-limited per address and challenged, and every attempt is logged whether it matched or not.
- A failed name check never blocks an alert. It marks it as unconfirmed and tells you so. Getting a child home outranks every other consideration here.
If we ever suffer a breach that is likely to be a risk to you, we will tell the ICO within 72 hours and tell you without undue delay.
Changes to this notice
If we change what we collect or why, we will update this page and, if the change matters to you, email you about it. We do not make changes retroactive.