Privacy Policy — Allanfa

Effective date: 25 August 2026 · Package: ai.saifullah.allanfa

Allanfa uses no named account, advertising, analytics, location, contacts, or device advertising identifier.

1) Who we are

Allanfa is provided by Saifullah Ahad (“we”, “us”, “our”). Contact www.saifullah.ai@gmail.com or visit saifullah.ai.

2) What Allanfa does

Allanfa combines separate structured exit-route observations into a shared capacity-planning estimate after a cryptographic threshold is reached. It is a planning aid, not an alarm, code certificate, official inspection, or replacement for emergency guidance or qualified professionals.

3) Floor records sent through the relay

When you create, join, contribute to, refresh, or delete a floor, Allanfa communicates with our Cloudflare Worker and R2 relay over HTTPS. The relay stores independent fixed-size 4,096-byte encrypted records under random mailbox addresses. It also stores hashed capability values and technical lifecycle metadata needed to update, retrieve, expire, or delete those records.

Structured values can include approximate occupied headcount, a fixed route reference, usable widths, confidence selections, and blocked-route selections. Allanfa encrypts these on the device before transmission. The relay has no dedicated field for a person’s name, workplace, company, address, floor name, participant list, or group membership. Cloudflare may process ordinary network metadata, such as an IP address, as part of delivering the service.

4) Threshold protection

Measurements and the capacity model remain encrypted until six valid records from nine separate invite slots can reconstruct the floor key. The stock app permits one slot per installation for a floor. A non-exportable random Android Keystore HMAC key produces a different 32-byte installation tag for each floor; that tag stays inside the encrypted record and lets Allanfa reject duplicate installation contributions after opening without linking the device across floors. A local hash of random floor material retains the claimed slot so clearing a floor does not let the same installation claim a second slot.

Each slot must be refreshed in at least two coarse hourly activity buckets spanning 24 hours. Those buckets remain inside the encrypted record. Installation records with identical activity histories are conservatively treated as one cohort, and duplicate installation tags count once. New floors also remain sealed for at least 24 hours, and that time is cryptographically bound to the floor key.

During invitation sharing, the creator's encrypted local pack contains the eight one-time colleague shares it must display. When the creator chooses Erase invite pack and continue, Allanfa permanently removes those colleague shares and retains only the creator's own share plus share-free mailbox deletion capabilities. The app cannot display the erased invitations again.

Before the threshold, the app does not display a contribution count or participant list. After the threshold, reconstruction, installation-tag checking, route-match proposals, and modelling occur on the device.

5) Camera

Camera access is optional and requested only when you choose to scan an Allanfa invite QR code. Camera frames are processed on your device and are not saved, uploaded, or added to a floor record. You can instead enter a full invite code without camera access.

6) Local security and settings

A floor invite or creator pack is stored locally in encrypted storage backed by Android Keystore. If a relay request fails after sealing, the fixed-size encrypted record is retained in that protected store for explicit retry or removal; the readable form values are not persisted as a queue. App preferences and the random-group participation guard are stored locally. If you set an Allanfa App PIN, the app stores a random salt and salted SHA-256 hash, not the plain PIN. Biometric unlock uses Android BiometricPrompt; Allanfa does not receive or store fingerprint or face data. The Allanfa App PIN is separate from the device PIN. Android backup is disabled for the app.

7) Optional feedback

If you choose Send feedback in About Developer, Web3Forms transmits your message to the developer. You may optionally provide an email address for a reply. The app attaches app version, Android version, device manufacturer, and device model to help diagnose the issue. It does not attach a floor record, measurement, invite, contact list, or advertising identifier. See the Web3Forms privacy policy.

8) How information is used and shared

Encrypted floor records are used only to provide the shared floor workflow. Optional feedback is used only for support and product improvement. We do not sell personal information or use it for advertising. Cloudflare processes relay traffic and stored ciphertext on our behalf; Web3Forms processes only feedback that you deliberately submit. Information may be disclosed if required by applicable law or to protect safety and legal rights.

9) Retention and deletion

10) Security and international processing

We use HTTPS, client-side authenticated encryption, unguessable capabilities, fixed-size relay records, local Keystore-backed encryption, and restricted backend validation. No system is perfectly secure. Cloudflare and Web3Forms may process data in countries other than yours under their own infrastructure and safeguards.

11) Children and content safety

Allanfa is intended for adults and is not directed to children. Structured observations must not contain names, contact details, addresses, photographs, allegations, sexual content, or other personal narratives. We do not knowingly collect children’s personal information. Our separate Child Safety Standards prohibit child sexual abuse and exploitation and explain how to report a concern.

12) Your choices

You can deny camera permission, avoid optional feedback, withdraw your own slot, remove an unsent sealed record, ask the creator to delete a floor, or contact us about access, correction, or deletion where applicable.

13) Changes and contact

We may update this policy when Allanfa’s practices or legal obligations change. The effective date above will be updated. Questions and requests: Saifullah Ahad, www.saifullah.ai@gmail.com, https://saifullah.ai.