ThreeSafe

Privacy notice

What we hold, and what we do not

ThreeSafe is built so that helping a lost child does not require anyone to learn who your family is. This page explains exactly what that means in data terms.

Last reviewed 8 August 2026.

The short version

We hold no readable name, age, date of birth, photo or description of any child. The only child-related thing we store is a one-way check built from the first name your child would say if asked. It is never displayed, never returned by any part of the service, and cannot be turned back into a name from our database alone.

Your three words are stored the same way. The plain phrase is shown only to you, in your own account and on your own printed card.

Every lookup is logged, matched or not, with the address it came from stored only as a one-way check. That log is what lets us see somebody probing. It is deleted after 12 months.

We never track a child’s location. There is no device, no tag and no map. If a product ever offers you that, it is a different product with a different risk profile.

Who we are

ThreeSafe is the data controller for the information described here. That means we decide what is collected and why, and we are the ones you complain to if we get it wrong.

Registered name
— to be confirmed before launch —
Company number
— to be confirmed before launch —
Registered address
— to be confirmed before launch —
ICO registration
— to be confirmed before launch —
Data protection contact
privacy@threesafe.org

We have not appointed a Data Protection Officer. At our size and scope the statutory tests for appointing one are not met. The address above reaches the person who is accountable for this notice.

Pre-launch. The registration details above are not yet filled in, and ICO registration is outstanding. ThreeSafe must not process real family data publicly until both are complete. See the data protection impact assessment for the full list of what is still open.

What we hold

This is the whole inventory. If something is not in this table, we do not have it.

WhatForm it is stored inWhy
Your email addressAs you typed itTo sign you in and to reach you about your account
Your three wordsA one-way check, plus a readable copy visible only inside your own accountThe one-way check is what a lookup matches against. The readable copy is what your card prints
Your child’s first nameTwo one-way checks — one exact, one of how it soundsSo a finder typing the name your child says can be matched without us ever holding the name
A label for each child, such as “Child 1”As you typed itSo you can tell your own entries apart. It is not the name, and we never ask for one
Your emergency contacts: a display name such as “Mum”, and a mobile number or emailAs you typed itSo we can send the alert. Only contacts who confirmed their own number or address are ever messaged
Your family story, if you write oneAs you typed itA sentence you write to help your child remember. Shown only to you, never on any lookup
Alerts: the finder’s name and number, where they said they were, and the name they typedAs they typed itSo you can call them back. This is information about the finder, given by the finder
Lookup attempts: matched or not, and the address they came fromThe address as a one-way check onlyTo detect somebody guessing at phrases. This is the abuse control

We do not collect a date of birth, a photograph, a school, a home address, a description, or any location of any kind. There is no analytics profile, no advertising identifier, and nothing is sold or shared for marketing.

Children’s data, specifically

ThreeSafe is used by children, so we treat the ICO’s Age Appropriate Design Code as binding on us. Three points matter more than the rest.

  • A child never has an account. There is nothing for a child to sign into, nothing for a child to consent to, and no way for a child to give us anything. The account belongs to a parent or carer.
  • We hold a check, not a name. A first name is a weak secret — it is spoken aloud all day. It is useful to us only as a second factor alongside the words, so we store it in a form that can confirm a guess but cannot produce the name. The transformation uses a secret key held outside the database, so a stolen database alone does not reveal it.
  • Nothing is optimised for engagement. There are no notifications designed to bring anyone back, no streaks, no profiling, and no nudges. The best outcome for a family is that they never use this service at all.

Why we are allowed to hold it

What we doLawful basisIn plain terms
Run your account and hold your phraseContract (UK GDPR Art. 6(1)(b))You asked us to give you a phrase. We cannot do that without holding it
Send an alert to your contacts when a lookup matchesVital interests (Art. 6(1)(d)), and contractA child is separated from their family. This is the one thing the service exists to do
Message a contact you addedLegitimate interests (Art. 6(1)(f))They confirmed their own number before we would ever use it, and they can remove it at any time
Log lookups and rate-limit themLegitimate interests (Art. 6(1)(f))Without this, somebody could sit and guess at phrases and nobody would notice

We do not rely on consent for any of the above, so there is no consent to withdraw. You can delete your account instead, and everything goes with it.

Who else sees it

We use other companies to run parts of the service. Each one is named here, with what it can see. None of them may use your data for their own purposes.

CompanyWhat it does for usWhat it can seeWhere
VercelHosting and delivery of the website and its server functionsIP address and request metadata, in transitEU and US, under the EU-US Data Privacy Framework and SCCs
NeonThe databaseEverything described in “What we hold”, at restEU (London or Frankfurt region)
TwilioSending the alert text messageA contact’s mobile number and the message bodyUS, under SCCs
ResendSending sign-in links and alert emailsA contact’s email address and the message bodyUS, under SCCs
CloudflareTurnstile, the check that a lookup is being made by a personIP address and a challenge token. No cookie is set for this.Global edge, under SCCs
UpstashRate limiting, to detect somebody probing the lookupA one-way hash of an IP address and a counterEU

Where a company is outside the UK, the transfer is covered by the UK’s international data transfer agreement or the equivalent standard clauses.

Beyond that: we will disclose information if we are legally required to, or where a police force or local authority requests it as part of a child protection enquiry. We log every such disclosure.

A person doing a lookup is told nothing about your family. Not your name, not your number, not how many contacts you have, not where you are. They are told that a family has been reached, and to find a member of staff.

How long we keep it

Your account, phrase, contacts and children
Kept until you ask us to delete it. When you delete it, everything above goes with it.
Alerts and the messages sent for them
12 months. A venue may need to evidence a reunification afterwards, and an inspector may ask months later.
Lookup logs
12 months. Long enough to see a slow, patient attacker; short enough not to be a standing liability.
Sign-in links
15 minutes, then deleted
Alert links sent to a parent
24 hours, then deleted
The sign-in cookie
30 days, or until you sign out.

Deletion is enforced by a scheduled job rather than by anybody remembering to run it.

Your rights

Under UK GDPR you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct anything that is wrong;
  • delete your account and everything attached to it;
  • stop using your data in a particular way, or object to it;
  • hand your data to you in a portable form.

Ask at privacy@threesafe.org. We will respond within one month, free of charge. We may ask you to confirm you control the email address on the account — we will not ask you for a passport or a utility bill.

One honest limit: we cannot show you your child’s stored name, because we do not have it. We can confirm that a check exists and delete it.

If you are unhappy with how we handle a request, you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We would rather you came to us first, but you do not have to.

To make a request or a complaint, email privacy@threesafe.org. Tell us what you want and which email address your account uses — we do not need anything about your child, and please do not send it.

How it is protected

  • Phrases and child name checks are stored as keyed one-way digests. The key lives in the runtime environment, never in the database, so a database copy on its own cannot be worked backwards.
  • Sign-in uses a single-use link rather than a password, so there is no password of yours for us to lose.
  • Sign-in links, alert links and session tokens are stored hashed, are single-use, and expire.
  • Lookups are rate-limited per address and challenged, and every attempt is logged whether it matched or not.
  • A failed name check never blocks an alert. It marks it as unconfirmed and tells you so. Getting a child home outranks every other consideration here.

If we ever suffer a breach that is likely to be a risk to you, we will tell the ICO within 72 hours and tell you without undue delay.

Changes to this notice

If we change what we collect or why, we will update this page and, if the change matters to you, email you about it. We do not make changes retroactive.