What We Will Not Build
A location product used during worship needs limits stated in advance, in public, before there is commercial pressure to cross them.
· 6 min read
Why state this at all
We are building a system that knows where a person is, continuously, during the most significant religious act of their life, and that shares that information with other people. That is not a neutral capability. The right time to state the limits is now, before there is a customer asking for something we should refuse and a revenue number attached to their request.
We will not sell location data
Not aggregated, not anonymised, not as "insights", not to advertisers, not to researchers without the explicit informed consent of the pilgrims concerned, and not to anybody for any price. This is the commitment most likely to be tested commercially, because location datasets of this specificity are valuable. There is no version of this product where we do it.
We will not build a band that cannot be removed
It is a strap with a clasp and it comes off whenever the wearer wants. Removal outside a registered charging window raises a low-priority notice to the group leader (because a band in a hotel drawer is a safety gap worth knowing about), not an emergency. Consent is captured at fitting and it can be withdrawn by taking the thing off. A safety device that a person cannot take off is a restraint, and that is a different product with different ethics.
We will not show pilgrims to each other
A pilgrim is visible to their registered group leader and to the next-of-kin they personally nominated. Not to other pilgrims in the group, not to other families, not to other operators. There is an obvious "find your friends" feature request here and we are not going to build it, because consent given to a leader for safety purposes is not consent to be visible to forty acquaintances.
We will not retain location history indefinitely
Default retention is the pilgrimage plus ninety days, then deletion. Operators on Fleet and Authority tiers can shorten it. Nobody can extend it indefinitely. The audit trail of alerts and responses (which is what an operator actually needs for accountability) is kept separately from the continuous position history, because those two things have very different retention justifications and conflating them is how location data quietly becomes permanent.
We will not claim to be an emergency service
Safe Daira raises an alert to people who are already responsible for the pilgrim. It does not dispatch anybody, it is not connected to Saudi emergency services, and it is not a medical device. Any marketing that blurs this would put someone in danger by encouraging reliance the product cannot support, so it is stated in the footer of every page and it will stay there.
Holding us to it
These commitments are in the repository history and in the privacy policy, both of which are dated. If we ever change them, the change will be visible, and you should ask why. That is the only enforcement mechanism a statement like this really has, so we are at least making it a real one.