Legal

Privacy Policy

Effective: May 4, 2026

1. Overview

Safety Simple ("we", "us") provides an EHS compliance platform for small construction crews. This Privacy Policy explains what we collect, how we use it, and your rights. By using the Service, you consent to the practices described here.

2. Information We Collect

Account information: name, email address, password (hashed), company name, trade, employee count, and state.

Customer Content: safety programs, incident reports, training attendance, toolbox talks, SDS records, photos, and other data you upload.

AI conversation data: messages you send to Sully and other AI features, plus the AI's responses, are processed to deliver the feature and may be retained for quality assurance.

Usage data: log files, IP address, browser type, pages visited, and feature interactions used for diagnostics and product improvement.

Cookies: session cookies for authentication and minimal analytics. We do not use third-party advertising trackers.

3. How We Use Information

  • Provide, maintain, and improve the Service.
  • Authenticate users and protect against fraud or abuse.
  • Generate trade-specific compliance recommendations and AI responses.
  • Send service notices, security alerts, and (with consent) product updates.
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal information or Customer Content.

4. AI Processing

When you interact with Sully or other AI features, your messages are sent to third-party AI model providers (e.g., Google, OpenAI) via a secure gateway. These providers process the content solely to generate a response and do not use it to train their public models under our agreement. Avoid submitting personally identifying information about employees, customers, or third parties unless necessary.

5. Sharing of Information

We share information only as follows:

  • Service providers: hosting, database, email delivery, AI inference, and analytics — bound by confidentiality and data-processing agreements.
  • Within your company: data is visible to other authorized members of your company workspace based on their role.
  • Legal: when required by law, subpoena, or to protect rights, safety, and property.
  • Business transfer: in connection with a merger, acquisition, or asset sale, with notice to you.

6. Data Security

We use industry-standard safeguards including encryption in transit (TLS), encryption at rest, role-based access controls, and row-level security in our database. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

7. Data Retention

We retain Customer Content for the life of your account plus 30 days after termination, after which it is deleted or anonymized. You may request earlier deletion at any time. Backups may persist up to 90 days.

8. Your Rights

Subject to applicable law (including CCPA and GDPR where relevant), you may:

  • Access, correct, or export your personal data.
  • Request deletion of your account and associated data.
  • Object to or restrict certain processing.
  • Withdraw consent for marketing communications.

To exercise these rights, email privacy@safety-simple.app.

9. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal data from minors. If you believe we have, contact us and we will delete it.

10. International Users

The Service is operated from the United States. By using the Service, you consent to transfer of your information to the U.S. and processing under U.S. law.

11. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated by email or in-app notice. Continued use after the effective date constitutes acceptance.

12. Contact

Questions or requests? Email privacy@safety-simple.app.