Privacy Policy
Effective June 21, 2026 · Version v1-2026-06-21
1. Who we are and what this covers
Aegis Safety LLC ("Aegis", "we", "us") provides a field safety platform to organizations and their workers. This policy covers the personal information we handle through the Service and our public pages. The inspection data your organization submits is controlled by your organization, meaning your employer or the account administrator, and we process it on their behalf and under our agreement with them. We are the controller of the account, security, and billing information needed to operate the Service.
2. Information we collect
We collect: account and organization details you provide, such as name, work email, company name, role, and language preference; inspection data your crews submit, including checklist responses, comments, scores, and photos; communications you send us, such as support requests and referrals; and basic usage, device, and log information generated when you use the Service, such as IP address, browser type, and actions taken, used to keep the Service secure and reliable. We do not intentionally collect special categories of personal data, and you should not submit them unless necessary for a legitimate safety purpose.
3. How we use information
We use this information to: provide, operate, secure, and support the Service; generate safety intelligence such as summaries, scores, and coaching from the data your organization submits; authenticate users and enforce access controls and usage limits; communicate with you about your account, security, and support; comply with law and enforce our Terms; and improve the reliability and quality of the Service. We do not sell your personal information, we do not use it for third-party advertising, and we do not use your data to train third-party AI models.
4. AI processing of your data
To generate safety intelligence, the inspection data, comments, and photos your organization submits are processed by our AI provider, Anthropic, through its commercial API, solely to return results to your organization. Under Anthropic’s commercial terms, your data is not used to train Anthropic’s or any third party’s foundation models. AI output is generated from the data you submit and is provided to your organization for review by its qualified safety professionals before any field or compliance use.
5. Legal bases for processing
Where data protection law requires a legal basis, we rely on: performance of our contract with you or your organization to provide the Service; our legitimate interests in operating, securing, and improving the Service in a way that does not override your rights; compliance with our legal obligations; and consent where it is required, which you may withdraw at any time. Your organization is responsible for the legal basis of the inspection data it submits about its workers.
6. How we share information
We share personal information only as needed to run the Service: with the service providers and sub-processors listed below, who act on our instructions; with your own organization and its authorized administrators, who can see the workspace data; when required by law or to respond to lawful requests; to protect the rights, safety, and security of Aegis, our customers, and the public; and in connection with a merger, acquisition, or sale of assets, with continued protection of your information. We do not sell your personal information.
7. Service providers and sub-processors
We rely on a small set of vendors to deliver the Service, each acting as a processor on our behalf: Anthropic (AI processing of inspection data), Supabase (database hosting and authentication), Vercel (application hosting and delivery), and Resend (transactional email such as confirmations and notices). Each provider receives only the data needed for its role and is bound by confidentiality and data-protection obligations. We may update this list as our providers change and will reflect changes on this page.
8. Data retention
We retain account and organization data for as long as your account is active and as needed to provide the Service, then for a reasonable period to meet legal, security, and recordkeeping obligations. Inspection photos are retained for 90 days and then automatically deleted; the analysis and findings derived from a photo may be kept as part of your safety records after the image itself is deleted. When your account is closed, we delete or de-identify Customer Data within a reasonable period, except where we must retain it to comply with law or resolve disputes. You can export Customer Data before closing your account.
9. Security
We use technical and organizational measures to protect personal information, including encryption in transit, authenticated access, role-based and tenant-level access controls that keep each organization’s data isolated, and least-privilege access for our systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to notify you of incidents as required by law.
10. International data transfers
Aegis and its providers are based in the United States, and your information is processed there. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your location. Where required, we use appropriate safeguards for such transfers.
11. Your privacy rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the use of your personal information, to object to certain processing, and to not be discriminated against for exercising these rights. Because your organization controls its inspection data, please direct requests about that data to your organization, and we will support them in responding. For information we control, you can submit a request using the contact below, and we will respond within the time required by applicable law after verifying your identity. We do not sell personal information, so there is no sale to opt out of. You may have a request submitted on your behalf by an authorized agent, and you may appeal a decision we make about your request by replying to our response.
12. Children’s privacy
The Service is a workplace tool. Account holders must be adults, as stated in our Terms, and the Service is not directed to children. We do not knowingly collect personal information from children under 16, and we do not collect it directly from any minor. Where an organization lawfully employs and submits inspection data about workers under 18, such as apprentices aged 16 or 17, it is responsible for doing so in compliance with applicable labor and privacy laws. If you believe a child has provided us personal information, please contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the version and effective date on this page and, where appropriate, notify you. Your continued use of the Service after an update takes effect means you accept the updated policy.
Privacy contact
Reach us at timothy.smedile@gmail.com

