CalSafe
Privacy Policy
- Effective
- September 13, 2026
- Controller
- CalSafe, for site and account data
- Google Sign-In
- Name, email, and profile photo
- Related
- Terms of Service
- Contact
- support@calsafe.io
Privacy Policy
This Privacy Policy explains how CalSafe collects, uses, stores, and shares personal data, including Google user data from Sign in with Google. It applies to the public site at calsafe.io and www.calsafe.io, to facility workspaces, and to billing, reminders, and support.
CalSafe
Privacy Policy
01
This is the Privacy Policy for CalSafe, the healthcare compliance calendar at calsafe.io and www.calsafe.io. CalSafe (“CalSafe,” “we,” “us,” “our”) operates the application. For the public site and for account records (name, email, Google account identifiers, facility name, role), CalSafe is the controller. For files and fields inside a facility workspace, the facility is the controller and CalSafe processes that data to provide the service.
Write support@calsafe.io. The rules for using the product are in the Terms of Service.
02
This Privacy Policy covers how CalSafe collects, uses, stores, shares, retains, and deletes personal data when you visit the public site, create an account, Sign in with Google, upload credentials, invite teammates, pay for a plan, receive reminders, or email support.
It does not cover third-party sites we link to, including medical boards, DEA, CMS, carriers, or vendors. Those organizations have their own policies.
03
CalSafe collects the personal data you provide, the Google user data you authorize when you Sign in with Google, the credential files you upload, and technical data created by using the service. We use that data only to provide and improve CalSafe’s user-facing features: signing you in, running the facility calendar, sending transactional email, and processing subscriptions.
04
We collect the following categories of personal data when you use or interact with CalSafe.
Account data. Full name, email address, password (stored by our authentication provider as a hash, not in plain text), facility name, and role (admin, manager, or staff). If you Sign in with Google, we also collect Google user data as described in the next section.
Workspace data. Uploaded credential files (PDF or photo). Extracted and confirmed fields: document type, entity name, issuing authority, issue date, expiry date, file name, and status. Team invites (email and role). Reminder settings (notify addresses and lead times) and reminder delivery logs.
Billing data. Plan, status, trial end, and identifiers from our payments provider. We do not store full card numbers. Cards are entered on Dodo Payments’ checkout.
Support data. The contents of emails you send us, including any facility name you include so we can find the workspace.
Technical data. IP address for rate limiting and security, device and browser data, pages viewed, and product events (for example sign-in, checkout, upload started or finished). Those events are configured without names, emails, or document contents.
If you do not provide account information, you cannot use a workspace. You can read the public site without an account.
05
CalSafe offers Sign in with Google as an optional way to create an account or sign in. When you choose that option, CalSafe accesses Google user data from your Google account. We request only the basic profile and email scopes needed to authenticate you. We do not request access to Gmail, Google Drive, Google Calendar, Contacts, or any other Google product.
The Google user data we access is:
How CalSafe uses Google user data. We use Google user data only to provide and improve user-facing features of CalSafe:
How CalSafe stores Google user data. Your Google account name and email are stored with our authentication provider (Supabase) and in your CalSafe profile. The Google user identifier is stored as part of the authentication record so we can sign you in again. Profile photos from Google, when present, are held by the authentication provider. We do not keep a separate marketing database of Google user data.
How CalSafe shares Google user data. We do not sell Google user data. We do not transfer or disclose Google user data to third parties for advertising, data brokerage, credit decisions, or any purpose other than operating CalSafe. We share Google user data only:
Limited Use. CalSafe’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve user-facing features that are prominent in the requesting application. We do not use Google user data for targeted advertising, personalized or interest-based ads, selling to data brokers, credit-worthiness, lending, or to develop, improve, or train generalized or non-personalized AI or ML models.
You can stop Sign in with Google by disconnecting CalSafe in your Google Account permissions, and by asking us to delete the CalSafe account. Deletion of Google user data follows the retention section below.
06
We use the personal data we collect, including Google user data, to provide the services you requested and to operate CalSafe. Specifically, we use it to:
We do not sell personal information. We do not use credential files or Google user data for advertising. We do not train CalSafe’s own models on your uploads or on Google user data. We will not use Google user data for a new purpose without updating this Privacy Policy and, where required, asking for your consent.
07
Account records, Google user data used for Sign in with Google, workspace fields, reminder settings, and billing identifiers are stored in our hosted database. Credential files are stored in private object storage scoped to your facility. Session cookies keep you signed in on your browser.
These systems run on our processors (currently Supabase for authentication, database, and files; Vercel for hosting). Data is stored in the United States and in the regions those processors use. Encryption in transit (HTTPS/TLS) is used for the site and APIs. Files are not publicly listed. One facility cannot read another facility’s rows through the product.
08
We share personal data, including Google user data, with processors who help us run CalSafe, only as needed for that job. We do not transfer or disclose your information to third parties for purposes other than the ones in this Privacy Policy.
We may share information if the law requires it, to protect the service or a person from harm, or with your direction (for example a teammate you invite). If CalSafe is sold or merged, workspace data and account data would transfer under this policy, and we would still expect the buyer to honor it.
09
Credentials often contain names, license numbers, DEA numbers, addresses, and other personal data of clinicians and staff. Treat them as confidential. Teammates you invite can see workspace files according to their role. Files are stored privately and scoped to your facility.
Do not upload patient medical records or other protected health information. CalSafe is not an EHR. We do not offer a HIPAA business associate agreement unless we have signed one with your facility in writing.
10
When you upload a PDF or photo, we send it to our extraction provider to read entity, authority, document type, and dates. A person on your team still has to confirm those fields before they reach the calendar.
We do not use your credentials or Google user data to train CalSafe’s own models. We do not use Google Workspace APIs or Google user data to develop, improve, or train non-personalized AI or ML models. The extraction provider’s terms govern whether it retains API inputs. Do not upload a file you are not willing to have processed that way.
11
Essential cookies keep you signed in. Preference cookies remember light or dark theme, and whether the sidebar is collapsed. If Google Analytics is enabled, analytics cookies measure visits and events.
You can block non-essential cookies in your browser. Blocking essential cookies will prevent sign-in. We do not currently show a separate cookie banner. This page is the disclosure.
12
When analytics is turned on for calsafe.io, Google Analytics 4 records page views and events such as sign-in, sign-up, checkout, upload, and coverage print. Event parameters are configured without personal names, emails, Google user identifiers, or file contents.
If analytics is not configured, those tags are not loaded. Browser controls and industry opt-outs for Google Analytics still apply when the tags are present. Analytics measurement is separate from Sign in with Google. We do not send your Google Sign-In profile contents into analytics events.
13
We store personal information, including Google user data used for Sign in with Google, for as long as needed to fulfill the purposes in this Privacy Policy, unless a longer period is required or permitted by law.
When the retention period ends for a given type of data, we delete it or de-identify it. You may request deletion of your CalSafe account and associated personal data, including Google user data we stored for Sign in with Google, by writing support@calsafe.io from an admin email on the account. We will delete or de-identify facility files and personal data within 30 days, except copies we must keep for security, dispute, or legal retention. Host backups roll off on our host’s schedule after that.
You can also delete individual credential records in the product. Disconnecting CalSafe from your Google Account stops future Sign in with Google; it does not by itself erase the CalSafe workspace. Ask us if you want both.
14
Security procedures are in place to protect the confidentiality of your data, including Google user data. We use encryption in transit (HTTPS/TLS) to protect information sent between your browser and CalSafe. Credential files sit in private object storage. The database uses tenant isolation so one facility cannot read another’s rows. Passwords are hashed. Sign in with Google uses Google’s OAuth flow rather than a CalSafe-held Google password. Access to a workspace is limited to signed-in members of that facility.
No method is perfect. Use a strong password or a Google account only you control. Invite only people who should see the credentials. Tell us if you see a security problem at support@calsafe.io.
15
Depending on where you live, including California under the CCPA/CPRA and the EEA or UK under the GDPR, you may have rights to access, correct, delete, or export personal data (including Google user data we hold), to restrict or object to certain processing, and to opt out of sale or sharing. CalSafe does not sell personal information and does not share it for cross-context behavioral advertising.
Workspace admins can correct many fields in the product. For access, export, or deletion of an account or facility, write support@calsafe.io from the email on the account. We will verify the request. You may have an authorized agent make a California request. We will not discriminate against you for exercising privacy rights.
If we process workspace files for your facility, we will point facility-level requests to a facility admin when that is the right path. You may also have the right to complain to a data protection authority.
16
CalSafe is for adult facility staff. We do not knowingly collect personal data from children under 16. If you believe we have, write support@calsafe.io and we will delete it.
17
We host and process in the United States, and in the regions our processors use. If you access CalSafe from elsewhere, you understand your data, including Google user data used for Sign in with Google, may be processed in the United States, which may have different protection rules than your country.
18
We will post updates on this page and change the effective date. If we change how CalSafe uses Google user data, we will update this Privacy Policy before that new use, and we will notify users where the law or Google’s policy requires it. Continued use of the service after the new date means the updated policy applies. If you need a copy of a prior version, write support.
19
Privacy questions, including questions about Google user data: support@calsafe.io. A person on the team reads every message. If you need our legal entity name or mailing address, use that same address.
A person reads every message. Include the facility name if it is about a workspace.
Write support@calsafe.io. The other posted document is the Terms of Service.