Privacy Policy
This Privacy Policy explains how Franklysafe.ai LLC (“FranklySafe,” “we,” “us”) collects, uses, and shares information in connection with the FranklySafe website (https://www.franklysafe.ai) and application (the “Service”).
1. Our role: controller vs. processor
- Customer and employee data. When an organization (“Customer”) uses the Service, the Customer decides what data to enter and why. For that data — including personal data about the Customer’s employees — the Customer is the data controller and FranklySafe acts as a service provider / data processor, processing it on the Customer’s behalf and instructions. If you are an employee of a Customer, please direct requests about your records to your employer.
- Account, website-visitor, and marketing data. For information we collect directly (for example when someone creates an account, contacts us, or visits our website), FranklySafe is the controller.
2. Information we process
Provided by the Customer / Authorized Users:
- Account and authentication data — name, work email, password (handled by our authentication provider), role (administrator or manager), and company affiliation.
- Company content — company profile, departments, and site locations (including addresses and, where entered, coordinates).
- Employee records — full names, work emails, job titles, hire dates, department/site assignment, and manager designation.
- Safety and health-related records — workplace incident and injury reports (which may include injury type, body part, severity, medical-treatment status, days away/restricted, and OSHA classification), inspections, safety observations, certifications and training history (including expirations/lapses), PPE assignments, and corrective actions. Some of this information is sensitive health-related data.
- Uploaded files — incident photos and attachments, certificates, safety data sheets (SDS) and SOP/knowledge documents, dataset files, and a company logo.
Collected automatically:
- Usage and log data, an audit trail of actions taken in the Service, and device/browser information.
- Cookies and similar technologies. In the application, we use essential cookies / local storage for authentication and session management and to remember preferences such as light/dark theme. On our marketing website (www.franklysafe.ai) we may use Google Analytics to measure site usage and the LinkedIn Insight Tag for advertising measurement and conversion tracking; these are enabled only when configured. See Section 7 for how to opt out.
AI processing inputs and outputs: safety records, text prompts, and uploaded documents sent to our AI providers — Anthropic (Claude), Google (Gemini), and xAI (Grok) — for analysis, and the summaries and recommendations they return. Before this data is sent, direct identifiers such as employee names and emails are removed or replaced with internal references, so the models process anonymized safety content.
3. How we use information
We use information to: provide, operate, secure, and improve the Service; authenticate users and administer accounts; generate AI analyses and recommendations; provide support and send service and alert communications; process subscriptions; and comply with legal obligations. AI outputs, including summaries of OSHA/MSHA regulations, are informational and are described further in our Terms of Use.
4. How information is shared — sub-processors and infrastructure
We share information with service providers (“sub-processors”) that help us run the Service, under contracts that limit their use of the data:
Resend is used only to deliver sales and system notification emails, for example task assignments, alerts, and account messages. It does not receive incident, inspection, injury, or other sensitive safety or health records.
We may also disclose information to comply with law or legal process, to protect rights and safety, or in connection with a corporate transaction (merger, acquisition, or asset sale), subject to appropriate safeguards. A current list of sub-processors is available on request; we will provide a mechanism to notify Customers of material changes.
5. Security
We use technical and organizational measures designed to protect information, including encryption in transit and at rest through our infrastructure providers, tenant isolation via database row-level security, and role-based access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data retention
We retain Customer Data for the duration of the Customer’s subscription and as directed by the Customer. Because Customers use the Service to meet their own recordkeeping obligations (for example OSHA’s multi-year injury-record retention), the Customer controls how long records are kept. On termination or verified request, we delete or return Customer Data within thirty (30) days, subject to legal retention requirements and routine backups.
7. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or port your personal data, to opt out of certain processing, and to non-discrimination for exercising these rights:
- California (CCPA/CPRA) and other US state privacy laws — rights to know, delete, and correct your personal information, and to opt out of any “sale” or “sharing.” We do not sell or share Customer Data. On our website, analytics and advertising cookies (Google Analytics, LinkedIn Insight Tag) may be considered a “sale” or “sharing” of website-visitor data under some state laws; you can opt out using your browser’s cookie controls, a Global Privacy Control signal, the Google Analytics opt-out, and LinkedIn’s ad settings, or by contacting us to exercise a “Do Not Sell or Share My Personal Information” request.
Because the Customer is the controller of employee data, individuals should generally submit requests to their employer (the Customer); we will assist the Customer as its processor. For data we control, contact support@franklysafe.ai and we will respond as required by law.
8. Data location
FranklySafe is a United States company serving United States customers. We process and store data in the United States.
9. Children’s privacy
The Service is a business tool not directed to children and not intended for individuals under 16. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy with a new “Last updated” date and, for material changes, provide additional notice.
11. Contact
Privacy questions or requests: support@franklysafe.ai. Franklysafe.ai LLC.