โ† Back to Home

Privacy Policy

Last updated: August 25, 2026

1. Introduction

Safety For Generations LLC ("SFG," "we," "us," or "our") operates the Community Emergency Guide ("CEG") at ceg.sfg.ac. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and what rights you have.

By using CEG you agree to the practices described below. If you do not agree, please do not use the service.

2. Information We Collect

2.1 Account Information

  • Email address (required for account creation and authentication).

2.2 Emergency Check-In Data

  • Name and party size.
  • Selected safe-zone location and check-in status during an emergency event.
  • GPS coordinates (optional โ€” collected only with your explicit permission for emergency dispatch purposes).
  • Phone number, stored as a one-way SHA-256 hash for reunification lookups. The plaintext number is never persisted.
  • Only when the exact incident has an authorized medical-triage flag: the selected complaint/need category, urgency tier, and free-text details needed for that temporary incident workflow. These values are not sent to analytics or application logs.

2.3 Building Safety Card Data

If you create a Building Safety Card, you may provide site and preparedness information such as:

  • Address, access, egress, utility shutoff, and muster details.
  • Site hazards, pets or animals, and safety equipment.
  • Site or household emergency contacts.
  • Aggregate occupant count, without person-scoped medical detail.

CEG does not use Building Safety Cards to store named occupant medical notes or to embed PASS medical profiles.

2.4 Resident Registration Data

A public resident registration form โ€” used during drills and active incidents, and completed without creating an account โ€” may request the following information:

  • Support needs used for evacuation planning: mobility support, whether you need a ride, caregiver assistance, hearing support, vision support, communication support, service animal information, calming needs, and safety precautions.

Support-needs questions can be skipped and do not create a Medical Safety Card or emergency medical credential.

CEG no longer accepts medical profile payloads through resident registration. Requests that include a medical profile are refused and no new resident medical or medication row is written. PASS is the canonical system for persistent person-scoped medical safety data.

While you are filling the form in, your browser keeps a partial draft so you do not lose your place. That draft holds your name, phone number, address, household size, and emergency contacts, and it stays on your device until you finish registering. It does not include allergies, medications, or medical notes. Those are held only in the page while it is open, which matters if you are registering on a shared or borrowed device.

2.5 Medical Safety Card Boundaries

CEG exposes only a one-time local print helper and direct browser navigation into the PASS-owned managed-card flow.

One-Time Emergency Card โ€” Self-Reported

This is the card you can create without an account. It runs entirely inside your own browser. What you type is held in memory on your device, is never transmitted to us, and is not saved to your device either โ€” closing or reloading the page discards it. The card is meant to be printed and carried. Because we never receive it, we cannot update it, revoke it, or recover it for you, and it is lost if you lose the paper copy. It is self-reported and is not verified by SFG.

PASS-managed persistent cards and legacy CEG rows

PASS is the sole canonical owner of persistent person-scoped Medical Safety Cards, emergency profiles, medical consent and disclosure, and QR/NFC emergency credentials. Direct navigation to PASS does not send medical data, a credential, or a profile through CEG.

Historical CEG medical rows are migration inputs only. New writes and responder/public resolution are retired. Existing records are retained without active credential use so their owner can read, export, or delete them during reconciliation. They are not automatically copied to PASS.

We do not collect government identification numbers, advance directive or POLST documents, implanted device records, baseline vital signs, or clinically coded diagnoses.

Legacy owner access, export, and deletion events may be recorded for security and audit purposes. CEG does not record a PASS emergency bearer or PASS medical response.

2.6 CEG Site Tag Scan Logs

  • When a CEG site or Building Safety Card NFC/QR tag is scanned, we log the scan type, IP address, and user agent for security and audit purposes. Person-scoped CEG bands are retired and do not resolve.

2.7 Analytics and Diagnostics

  • Page views and Web Vitals collected via Vercel Analytics.
  • Error reports collected via Sentry. No protected health information (PHI) is transmitted to Sentry.
  • Structured application logs aggregated via Axiom.

2.8 Technical Data

  • IP addresses are logged temporarily for rate limiting via Upstash Redis and are not associated with your account long-term.

2.9 Offline Data

  • If you use CEG while offline, check-in data is stored locally in your browser's IndexedDB outbox. This data is automatically synced to our servers when connectivity returns and is then cleared from your device. A rejected request retains only a payload-free failure receipt so the interface can tell you it did not go through.

3. How We Use Your Information

  • Emergency operations: facilitating safe-zone check-ins, reunification, and incident coordination.
  • Household management: storing and displaying household preparedness and Building Safety Cards.
  • Communications: sending SMS alerts, temporary access codes, and transactional emails.
  • Billing: processing any CEG community or site-service purchases offered.
  • Security: rate limiting, abuse prevention, and audit logging of Band site-tag scans.
  • Improvement: analyzing anonymized analytics to improve CEG performance and usability.

4. Third-Party Services

We use the following third-party services to operate CEG. Each processes data only as necessary to provide its stated function:

ProviderPurpose
SupabaseDatabase (PostgreSQL with Row-Level Security), authentication, and file storage
VercelApplication hosting and privacy-friendly analytics
StripePayment processing for CEG services where offered
TwilioSMS alerts and temporary access codes
ResendTransactional email delivery
SentryError monitoring (no PHI transmitted)
AxiomStructured log aggregation
Upstash RedisRate limiting (IP addresses stored ephemerally)

5. Data Storage and Security

  • All data is stored in Supabase-managed PostgreSQL databases hosted in the United States.
  • Database access is enforced through PostgreSQL Row-Level Security (RLS) policies so users can only access their own data.
  • All connections use TLS encryption in transit.
  • Phone numbers used for reunification are stored as irreversible SHA-256 hashes.
  • Supabase Auth manages sessions and password hashing using industry-standard bcrypt.

6. Data Retention

We retain data only as long as necessary for emergency operations and then automatically reduce it:

Data TypeRetention
Legacy CEG medical rowsRead/export/delete-only pending migration disposition
Authorized incident medical/EMS detailsRedacted 30 days after the incident closes; related location and contact hashes are nulled after 90 days
LoRaWAN incident payloadsMedical fields redacted 30 days after the linked incident closes
GPS coordinatesNulled after 90 days
Phone number hashesNulled after 90 days
Analytics eventsDeleted after 180 days
Account dataRetained until you delete your account

7. Data Sharing

We do not sell your personal information to third parties.

We may share data in the following limited circumstances:

  • Incident partners: CEG-owned check-in, reunification, and site-preparedness data may be shared with authorized incident personnel for coordination.
  • Service providers: Third-party services listed in Section 4 process data solely to provide their stated functions.
  • Legal requirements: We may disclose information if required by law, subpoena, or court order.

8. SMS Communications

CEG may send you SMS messages for access alerts, temporary codes, and emergency notifications. Standard message and data rates apply.

You can opt out of SMS communications at any time by replying STOP to any message. Opting out of SMS will not affect your ability to use the CEG web application.

9. Your Rights

9.1 California Residents (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used.
  • Request deletion of your personal information.
  • Opt out of the sale of personal information (we do not sell your data).
  • Non-discrimination for exercising your privacy rights.

9.2 Account Deletion

You can delete your account at any time from your Settings page. Account deletion removes CEG account, household and Building Safety Card data, coordination records where legally permitted, site-tag registrations, access logs, and billing records. Legacy medical migration rows can also be requested for deletion.

10. Children's Privacy

CEG is not directed to children under 13. We do not knowingly collect personal information from children under 13. CEG does not create persistent medical profiles for minor dependents; those managed-card decisions belong to PASS and its consent controls.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will make reasonable efforts to notify you via email or an in-app notice.

12. Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:

Safety For Generations LLC

Email: Steven@sfg.ac

ยฉ 2026 Safety For Generations LLC. All rights reserved.