Privacy first
You own your record. It is private to you, it follows you rather than your department, and it is never sold or shared with insurers. The department view we are building will show aggregate trends only, never an individual’s file.
The commitments
No supervisor, chief, or officer can open your individual record. The department view we are building will only ever show department-level aggregates, never a name or a number tied to you.
Your Fire Exposure Score, Sleep Debt Index, biometrics, and call history are not sold and are not shared with insurers. Your record is yours to bring forward if and when you choose to.
The department view is designed so leadership only ever sees grouped trends, held to a minimum cohort size, so no individual can be reverse-engineered out of an aggregate.
It follows the firefighter, not the department. You can carry it across stations and across a career, because it was always yours.
How it holds
Your individual record is stored so that it is private to you by default. Database-level access rules keep it from other users, so your record is not something another member or an officer can browse.
As we build the department view, the only thing designed to cross into it is an aggregate, held above a minimum cohort size. We are building the boundary in from the start, rather than bolting a promise on at the end. That is the difference we are holding ourselves to as the product grows.
The legal document
The commitments above are how we describe our boundaries. The Privacy Policy is the complete legal document: every category of information we collect, how we use and disclose it, how long we keep it, your choices and state privacy rights, and how to reach us. It is the document our app store listings point to, and it governs.
Prefer a copy you can print or file? Download it as a PDF.
You own your record. Always.
Request access