The short version
- We collect what we need to run your account and the service: your name, work email, sign-in events, billing status, and the projects you create.
- Your projects, analyses and documents belong to you. We do not sell them, share them with anyone but the processors listed below, or use them to train any machine-learning model, ours or a third party's.
- No advertising trackers and no third-party analytics run on this site or in the application.
- Hosted data is stored in the United States. Customer-hosted and local-only deployments keep your data entirely inside your own environment; we never receive it.
- You can export your data at any time and ask us to delete it; we retain hosted data for 90 days after an account ends so you can export, then delete it.
1. Who this policy covers
This policy applies to visitors of safetylabaero.com, to people who create an account or use the software (including trial users), and to people who contact us by email. Where you use Safety Lab Aero through your employer's account, your employer decides what data is entered into the software and is the controller of that data; we process it on their behalf under the End User License and Subscription Agreement.
2. What we collect
Account data. Name, work email address, organization, the authentication method you use (email and password, or single sign-on through your identity provider), and the version of the license agreement you accepted and when.
Usage and security records. Sign-in events (time, IP address, user agent), sealed revisions, review sign-offs and the append-only ledger that records who changed what and when inside a project. These records exist so that certification evidence is tamper-evident; they are part of the product, not a marketing feed.
Customer data. Everything you put into a project: functions, hazards, fault trees, FMEAs, requirements, attachments, documents and exports. In a hosted deployment this is stored on our infrastructure to provide the service. In a customer-hosted or local-only deployment it never reaches us.
AI requests. When you use an AI drafting feature in a hosted deployment, the request (the relevant project content and your prompt) is sent through our proxy to the language-model provider named below, and the request and response are logged for audit. Your corrections to AI drafts are kept in your own browser, not on our systems.
Billing. Subscriptions are processed by Stripe. We receive your billing status and the last four digits of a card; we never see or store full card numbers.
Correspondence. Emails you send us, and the transactional emails we send you (sign-up confirmation, trial expiry, review requests).
What we do not collect. No advertising identifiers, no cross-site trackers, no third-party analytics scripts, no browser fingerprinting. The marketing site loads no third-party scripts at all.
3. Why we use it
- To provide, secure and support the service, including authentication, authorization and tamper-evident records.
- To bill you and to prevent abuse of the free trial.
- To send transactional email about your account (we do not send marketing email without your consent).
- To answer your questions and to improve the product from aggregated, anonymized usage statistics, where your agreement permits that and you have not switched it off.
- To comply with law, including export-control law, and with valid legal process.
4. What we will never do
We do not use your customer data, your documents or your corrections to AI drafts to train or fine-tune any machine-learning model. Our language-model providers are contractually bound not to retain or train on your prompts or outputs. We do not sell personal data, and we do not share customer data with anyone other than the processors below acting on our instructions. If we ever wanted to use customer data for model training we would ask for separate, explicit, written opt-in consent, and declining would not affect your service.
5. Who processes data on our behalf
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage for hosted deployments | United States (US-East) |
| Cloudflare | Application hosting, content delivery, TLS, the AI proxy | Global edge, US origin |
| Anthropic | Language-model inference for AI drafting (no retention, no training on your data) | United States |
| Voyage AI | Embeddings for knowledge retrieval in AI features | United States |
| Stripe | Subscription billing | United States |
| Resend | Transactional email delivery | United States |
| Microsoft Entra ID | Single sign-on, when your organization uses it | Your tenant |
Projects flagged as export-controlled are never sent to a public-cloud AI provider. In a hosted deployment an AI request on such a project is refused; in a customer-hosted deployment it goes only to the endpoint you configure inside your own boundary. Details are on the trust and security page.
6. Where data is stored and for how long
Hosted customer data and account data are stored in the United States. Customer data is kept for as long as your account is active. When an account ends, we retain hosted customer data for 90 days so you can export it, then delete it; we will delete it sooner on written request. Account and billing records are kept as long as the law requires us to keep them (for example for tax purposes). Security and ledger records tied to a project are deleted with the project. Backups roll off on their own schedule and are not restored except to recover the service.
7. Security
Data is encrypted in transit and at rest. Every application table enforces row-level access control, so one customer's data is never visible to another. AI calls pass through a proxy we operate; the browser never holds a model-provider key. Sign-offs and revisions are recorded in a hash-chained ledger that any signed-in member can re-verify. More on the trust and security page. If you find a vulnerability, our disclosure policy is at /.well-known/security.txt.
8. Your rights and choices
- Export. You can export your projects from the application at any time, in the formats the software produces.
- Access, correction and deletion. Email us and we will show you the personal data we hold about you, correct it, or delete it, subject to records we must keep by law.
- Aggregated statistics. The anonymized, aggregated statistics license in the agreement can be switched off on request without affecting any feature.
- Email. Transactional email is part of the service; we do not send marketing email without consent.
Residents of the European Economic Area, the United Kingdom, California and other jurisdictions with data-protection statutes have the rights those laws provide, including the right to complain to a supervisory authority. We honor them for everyone; you do not need to tell us where you live to exercise them.
9. Cookies and local storage
The marketing site sets no cookies. The application uses browser storage for the session token that keeps you signed in, your interface preferences, and, if you use AI features, your own AI-draft corrections. None of it is used for advertising or shared with third parties. Clearing your browser storage signs you out and removes the local correction store.
10. Children
The service is for professional and academic use and is not directed at anyone under 18. We do not knowingly collect personal data from children.
11. Changes
When this policy changes we will post the new version here with a new effective date, and, for material changes, notify account holders by email or in the application before the change takes effect.
12. Contact
Safety Lab Aero, Inc., a Delaware corporation. Questions, requests and complaints: waqas.nafees@safetylabaero.com.