Book 15 min

Privacy Policy

Last updated: July 9, 2026

This Privacy Policy explains how Franklysafe.ai LLC (“FranklySafe,” “we,” “us”) collects, uses, and shares information in connection with the FranklySafe website (https://www.franklysafe.ai) and application (the “Service”).

1. Our role: controller vs. processor

2. Information we process

Provided by the Customer / Authorized Users:

Collected automatically:

AI processing inputs and outputs: safety records, text prompts, and uploaded documents sent to our AI providers — Anthropic (Claude), Google (Gemini), and xAI (Grok) — for analysis, and the summaries and recommendations they return. Before this data is sent, direct identifiers such as employee names and emails are removed or replaced with internal references, so the models process anonymized safety content.

3. How we use information

We use information to: provide, operate, secure, and improve the Service; authenticate users and administer accounts; generate AI analyses and recommendations; provide support and send service and alert communications; process subscriptions; and comply with legal obligations. AI outputs, including summaries of OSHA/MSHA regulations, are informational and are described further in our Terms of Use.

We do not sell Customer Data, we do not share Customer Data for cross-context behavioral advertising, and we do not use Customer Data to train third-party AI models. (Website-visitor analytics and advertising cookies are addressed separately in Sections 2 and 7.)

4. How information is shared — sub-processors and infrastructure

We share information with service providers (“sub-processors”) that help us run the Service, under contracts that limit their use of the data:

Vercel
Application and website hosting and serverless functions.
Supabase
PostgreSQL database, authentication, and file storage — the primary hosting of Customer Data, with row-level security.
Anthropic (Claude)
AI processing of anonymized safety records and documents.
Google (Gemini)
AI processing and document search over anonymized content.
xAI (Grok)
AI processing of anonymized safety records and patterns.
Resend
Delivery of sales and system notification emails only. Does not process sensitive safety or health data.

Resend is used only to deliver sales and system notification emails, for example task assignments, alerts, and account messages. It does not receive incident, inspection, injury, or other sensitive safety or health records.

We may also disclose information to comply with law or legal process, to protect rights and safety, or in connection with a corporate transaction (merger, acquisition, or asset sale), subject to appropriate safeguards. A current list of sub-processors is available on request; we will provide a mechanism to notify Customers of material changes.

5. Security

We use technical and organizational measures designed to protect information, including encryption in transit and at rest through our infrastructure providers, tenant isolation via database row-level security, and role-based access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

6. Data retention

We retain Customer Data for the duration of the Customer’s subscription and as directed by the Customer. Because Customers use the Service to meet their own recordkeeping obligations (for example OSHA’s multi-year injury-record retention), the Customer controls how long records are kept. On termination or verified request, we delete or return Customer Data within thirty (30) days, subject to legal retention requirements and routine backups.

7. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or port your personal data, to opt out of certain processing, and to non-discrimination for exercising these rights:

Because the Customer is the controller of employee data, individuals should generally submit requests to their employer (the Customer); we will assist the Customer as its processor. For data we control, contact support@franklysafe.ai and we will respond as required by law.

8. Data location

FranklySafe is a United States company serving United States customers. We process and store data in the United States.

9. Children’s privacy

The Service is a business tool not directed to children and not intended for individuals under 16. We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy with a new “Last updated” date and, for material changes, provide additional notice.

11. Contact

Privacy questions or requests: support@franklysafe.ai. Franklysafe.ai LLC.