Privacy Policy

What we collect, where it lives, and what we will never do with it

Safety Lab Aero, Inc. ("we", "us") operates safetylabaero.com and the Safety Lab Aero software. This policy explains how we handle personal data and customer data. Effective 23 September 2026.

The short version

1. Who this policy covers

This policy applies to visitors of safetylabaero.com, to people who create an account or use the software (including trial users), and to people who contact us by email. Where you use Safety Lab Aero through your employer's account, your employer decides what data is entered into the software and is the controller of that data; we process it on their behalf under the End User License and Subscription Agreement.

2. What we collect

Account data. Name, work email address, organization, the authentication method you use (email and password, or single sign-on through your identity provider), and the version of the license agreement you accepted and when.

Usage and security records. Sign-in events (time, IP address, user agent), sealed revisions, review sign-offs and the append-only ledger that records who changed what and when inside a project. These records exist so that certification evidence is tamper-evident; they are part of the product, not a marketing feed.

Customer data. Everything you put into a project: functions, hazards, fault trees, FMEAs, requirements, attachments, documents and exports. In a hosted deployment this is stored on our infrastructure to provide the service. In a customer-hosted or local-only deployment it never reaches us.

AI requests. When you use an AI drafting feature in a hosted deployment, the request (the relevant project content and your prompt) is sent through our proxy to the language-model provider named below, and the request and response are logged for audit. Your corrections to AI drafts are kept in your own browser, not on our systems.

Billing. Subscriptions are processed by Stripe. We receive your billing status and the last four digits of a card; we never see or store full card numbers.

Correspondence. Emails you send us, and the transactional emails we send you (sign-up confirmation, trial expiry, review requests).

What we do not collect. No advertising identifiers, no cross-site trackers, no third-party analytics scripts, no browser fingerprinting. The marketing site loads no third-party scripts at all.

3. Why we use it

4. What we will never do

We do not use your customer data, your documents or your corrections to AI drafts to train or fine-tune any machine-learning model. Our language-model providers are contractually bound not to retain or train on your prompts or outputs. We do not sell personal data, and we do not share customer data with anyone other than the processors below acting on our instructions. If we ever wanted to use customer data for model training we would ask for separate, explicit, written opt-in consent, and declining would not affect your service.

5. Who processes data on our behalf

ProcessorPurposeLocation
SupabaseDatabase, authentication, storage for hosted deploymentsUnited States (US-East)
CloudflareApplication hosting, content delivery, TLS, the AI proxyGlobal edge, US origin
AnthropicLanguage-model inference for AI drafting (no retention, no training on your data)United States
Voyage AIEmbeddings for knowledge retrieval in AI featuresUnited States
StripeSubscription billingUnited States
ResendTransactional email deliveryUnited States
Microsoft Entra IDSingle sign-on, when your organization uses itYour tenant

Projects flagged as export-controlled are never sent to a public-cloud AI provider. In a hosted deployment an AI request on such a project is refused; in a customer-hosted deployment it goes only to the endpoint you configure inside your own boundary. Details are on the trust and security page.

6. Where data is stored and for how long

Hosted customer data and account data are stored in the United States. Customer data is kept for as long as your account is active. When an account ends, we retain hosted customer data for 90 days so you can export it, then delete it; we will delete it sooner on written request. Account and billing records are kept as long as the law requires us to keep them (for example for tax purposes). Security and ledger records tied to a project are deleted with the project. Backups roll off on their own schedule and are not restored except to recover the service.

7. Security

Data is encrypted in transit and at rest. Every application table enforces row-level access control, so one customer's data is never visible to another. AI calls pass through a proxy we operate; the browser never holds a model-provider key. Sign-offs and revisions are recorded in a hash-chained ledger that any signed-in member can re-verify. More on the trust and security page. If you find a vulnerability, our disclosure policy is at /.well-known/security.txt.

8. Your rights and choices

Residents of the European Economic Area, the United Kingdom, California and other jurisdictions with data-protection statutes have the rights those laws provide, including the right to complain to a supervisory authority. We honor them for everyone; you do not need to tell us where you live to exercise them.

9. Cookies and local storage

The marketing site sets no cookies. The application uses browser storage for the session token that keeps you signed in, your interface preferences, and, if you use AI features, your own AI-draft corrections. None of it is used for advertising or shared with third parties. Clearing your browser storage signs you out and removes the local correction store.

10. Children

The service is for professional and academic use and is not directed at anyone under 18. We do not knowingly collect personal data from children.

11. Changes

When this policy changes we will post the new version here with a new effective date, and, for material changes, notify account holders by email or in the application before the change takes effect.

12. Contact

Safety Lab Aero, Inc., a Delaware corporation. Questions, requests and complaints: waqas.nafees@safetylabaero.com.