Skip to content

Privacy Policy

Privacy Policy

This Privacy Policy explains how CalSafe collects, uses, stores, and shares personal data, including Google user data from Sign in with Google. It applies to the public site at calsafe.io and www.calsafe.io, to facility workspaces, and to billing, reminders, and support.

  • CalSafe collects account data; Google user data (your Google account name, email address, and profile photo) when you Sign in with Google; credential files and confirmed calendar fields; billing identifiers; reminder settings; support messages; and technical logs.
  • We use this information to create and secure your account, run the facility calendar, send invites and expiry reminders, process subscriptions, prevent abuse, and comply with law.
  • We store it with our processors listed below. We do not sell personal information or Google user data. We do not use Google user data for advertising or to train AI or ML models.
  • You may request access, a copy, or deletion by writing support@calsafe.io from the email on the account.

CalSafe

Privacy Policy

Effective
September 13, 2026
Controller
CalSafe, for site and account data
Google Sign-In
Name, email, and profile photo

01

Who we are

This is the Privacy Policy for CalSafe, the healthcare compliance calendar at calsafe.io and www.calsafe.io. CalSafe (“CalSafe,” “we,” “us,” “our”) operates the application. For the public site and for account records (name, email, Google account identifiers, facility name, role), CalSafe is the controller. For files and fields inside a facility workspace, the facility is the controller and CalSafe processes that data to provide the service.

Write support@calsafe.io. The rules for using the product are in the Terms of Service.

02

What this policy covers

This Privacy Policy covers how CalSafe collects, uses, stores, shares, retains, and deletes personal data when you visit the public site, create an account, Sign in with Google, upload credentials, invite teammates, pay for a plan, receive reminders, or email support.

It does not cover third-party sites we link to, including medical boards, DEA, CMS, carriers, or vendors. Those organizations have their own policies.

03

Data collection and use at a glance

CalSafe collects the personal data you provide, the Google user data you authorize when you Sign in with Google, the credential files you upload, and technical data created by using the service. We use that data only to provide and improve CalSafe’s user-facing features: signing you in, running the facility calendar, sending transactional email, and processing subscriptions.

  • We collect: name, email, password or Google Sign-In details, facility name, role, uploaded credential files and extracted fields, reminder addresses, billing identifiers, support messages, IP address, and product-usage events.
  • We use this data to create and authenticate your account, operate the workspace, send expiry reminders, invoice the facility, keep the service secure, and meet legal duties.
  • We store this data with the processors named in this policy. Account and workspace data stay until you delete them or we close the workspace, subject to legal retention.
  • We share this data with those processors, with teammates you invite, and when the law requires it. We do not sell personal information. We do not share it for cross-context behavioral advertising.
  • You may request access, correction, export, or deletion at support@calsafe.io.

04

Information we collect

We collect the following categories of personal data when you use or interact with CalSafe.

Account data. Full name, email address, password (stored by our authentication provider as a hash, not in plain text), facility name, and role (admin, manager, or staff). If you Sign in with Google, we also collect Google user data as described in the next section.

Workspace data. Uploaded credential files (PDF or photo). Extracted and confirmed fields: document type, entity name, issuing authority, issue date, expiry date, file name, and status. Team invites (email and role). Reminder settings (notify addresses and lead times) and reminder delivery logs.

Billing data. Plan, status, trial end, and identifiers from our payments provider. We do not store full card numbers. Cards are entered on Dodo Payments’ checkout.

Support data. The contents of emails you send us, including any facility name you include so we can find the workspace.

Technical data. IP address for rate limiting and security, device and browser data, pages viewed, and product events (for example sign-in, checkout, upload started or finished). Those events are configured without names, emails, or document contents.

If you do not provide account information, you cannot use a workspace. You can read the public site without an account.

05

Google user data

CalSafe offers Sign in with Google as an optional way to create an account or sign in. When you choose that option, CalSafe accesses Google user data from your Google account. We request only the basic profile and email scopes needed to authenticate you. We do not request access to Gmail, Google Drive, Google Calendar, Contacts, or any other Google product.

The Google user data we access is:

  • Your Google account name (the name on the Google profile).
  • Your Google account email address.
  • Your Google account profile photo, if one is provided.
  • A Google user identifier used to recognize the same Google account on later sign-ins.

How CalSafe uses Google user data. We use Google user data only to provide and improve user-facing features of CalSafe:

  • Create your CalSafe account, or sign you in to an existing account that uses the same email.
  • Display your name in the facility workspace.
  • Send transactional email (invites, password-related messages, and expiry reminders) to the Google account email.
  • Match an invite to the Google account email so the right person joins the facility.
  • Keep the account secure and prevent abuse.

How CalSafe stores Google user data. Your Google account name and email are stored with our authentication provider (Supabase) and in your CalSafe profile. The Google user identifier is stored as part of the authentication record so we can sign you in again. Profile photos from Google, when present, are held by the authentication provider. We do not keep a separate marketing database of Google user data.

How CalSafe shares Google user data. We do not sell Google user data. We do not transfer or disclose Google user data to third parties for advertising, data brokerage, credit decisions, or any purpose other than operating CalSafe. We share Google user data only:

  • With Supabase, which authenticates the Google sign-in and stores the account record.
  • With Vercel, which hosts the application that completes the sign-in.
  • With Resend, when we send transactional email to the Google account email and email sending is configured.
  • With teammates in your facility workspace, who can see your name and (for some roles) your email.
  • When you direct us to, or when the law requires it.

Limited Use. CalSafe’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve user-facing features that are prominent in the requesting application. We do not use Google user data for targeted advertising, personalized or interest-based ads, selling to data brokers, credit-worthiness, lending, or to develop, improve, or train generalized or non-personalized AI or ML models.

You can stop Sign in with Google by disconnecting CalSafe in your Google Account permissions, and by asking us to delete the CalSafe account. Deletion of Google user data follows the retention section below.

06

How we use information

We use the personal data we collect, including Google user data, to provide the services you requested and to operate CalSafe. Specifically, we use it to:

  • Create, secure, and operate the facility workspace.
  • Authenticate you with a password or with Sign in with Google.
  • Extract printed fields, show them for review, and hold confirmed dates on the calendar.
  • Send invites, password-reset messages, and expiry reminders.
  • Process subscriptions and tax-inclusive invoices.
  • Fix problems you report, prevent abuse, and enforce rate limits.
  • Understand product use through analytics when analytics is enabled on the site.
  • Comply with law and with valid legal process.

We do not sell personal information. We do not use credential files or Google user data for advertising. We do not train CalSafe’s own models on your uploads or on Google user data. We will not use Google user data for a new purpose without updating this Privacy Policy and, where required, asking for your consent.

07

How we store information

Account records, Google user data used for Sign in with Google, workspace fields, reminder settings, and billing identifiers are stored in our hosted database. Credential files are stored in private object storage scoped to your facility. Session cookies keep you signed in on your browser.

These systems run on our processors (currently Supabase for authentication, database, and files; Vercel for hosting). Data is stored in the United States and in the regions those processors use. Encryption in transit (HTTPS/TLS) is used for the site and APIs. Files are not publicly listed. One facility cannot read another facility’s rows through the product.

08

When we share information

We share personal data, including Google user data, with processors who help us run CalSafe, only as needed for that job. We do not transfer or disclose your information to third parties for purposes other than the ones in this Privacy Policy.

  • Supabase: authentication (including Sign in with Google), the facility database, and private file storage.
  • Google: Sign in with Google, when you choose that option. Google Analytics 4 for site and product measurement, when a measurement ID is configured. Google’s own use of data is governed by Google’s policy.
  • OpenAI: document extraction. The uploaded credential file is sent so printed fields can be returned. This is workspace data, not Google Sign-In data.
  • Dodo Payments: checkout, subscriptions, and tax, as merchant of record.
  • Resend: reminder and other transactional email, when email sending is configured.
  • Vercel: hosting the application.
  • Upstash: durable rate limits, when that store is configured.

We may share information if the law requires it, to protect the service or a person from harm, or with your direction (for example a teammate you invite). If CalSafe is sold or merged, workspace data and account data would transfer under this policy, and we would still expect the buyer to honor it.

09

Uploaded credentials

Credentials often contain names, license numbers, DEA numbers, addresses, and other personal data of clinicians and staff. Treat them as confidential. Teammates you invite can see workspace files according to their role. Files are stored privately and scoped to your facility.

Do not upload patient medical records or other protected health information. CalSafe is not an EHR. We do not offer a HIPAA business associate agreement unless we have signed one with your facility in writing.

10

AI processing

When you upload a PDF or photo, we send it to our extraction provider to read entity, authority, document type, and dates. A person on your team still has to confirm those fields before they reach the calendar.

We do not use your credentials or Google user data to train CalSafe’s own models. We do not use Google Workspace APIs or Google user data to develop, improve, or train non-personalized AI or ML models. The extraction provider’s terms govern whether it retains API inputs. Do not upload a file you are not willing to have processed that way.

11

Cookies

Essential cookies keep you signed in. Preference cookies remember light or dark theme, and whether the sidebar is collapsed. If Google Analytics is enabled, analytics cookies measure visits and events.

You can block non-essential cookies in your browser. Blocking essential cookies will prevent sign-in. We do not currently show a separate cookie banner. This page is the disclosure.

12

Analytics

When analytics is turned on for calsafe.io, Google Analytics 4 records page views and events such as sign-in, sign-up, checkout, upload, and coverage print. Event parameters are configured without personal names, emails, Google user identifiers, or file contents.

If analytics is not configured, those tags are not loaded. Browser controls and industry opt-outs for Google Analytics still apply when the tags are present. Analytics measurement is separate from Sign in with Google. We do not send your Google Sign-In profile contents into analytics events.

13

Retention and deletion

We store personal information, including Google user data used for Sign in with Google, for as long as needed to fulfill the purposes in this Privacy Policy, unless a longer period is required or permitted by law.

  • Account and Google Sign-In records stay until you delete the account or we close the workspace.
  • Workspace files and confirmed fields stay until you delete the record or we close the workspace.
  • Reminder logs stay so you can see what was sent.
  • Billing records stay as long as tax and accounting rules require.
  • Security and rate-limit logs stay for a short period to prevent abuse.

When the retention period ends for a given type of data, we delete it or de-identify it. You may request deletion of your CalSafe account and associated personal data, including Google user data we stored for Sign in with Google, by writing support@calsafe.io from an admin email on the account. We will delete or de-identify facility files and personal data within 30 days, except copies we must keep for security, dispute, or legal retention. Host backups roll off on our host’s schedule after that.

You can also delete individual credential records in the product. Disconnecting CalSafe from your Google Account stops future Sign in with Google; it does not by itself erase the CalSafe workspace. Ask us if you want both.

14

Security

Security procedures are in place to protect the confidentiality of your data, including Google user data. We use encryption in transit (HTTPS/TLS) to protect information sent between your browser and CalSafe. Credential files sit in private object storage. The database uses tenant isolation so one facility cannot read another’s rows. Passwords are hashed. Sign in with Google uses Google’s OAuth flow rather than a CalSafe-held Google password. Access to a workspace is limited to signed-in members of that facility.

No method is perfect. Use a strong password or a Google account only you control. Invite only people who should see the credentials. Tell us if you see a security problem at support@calsafe.io.

15

Your rights

Depending on where you live, including California under the CCPA/CPRA and the EEA or UK under the GDPR, you may have rights to access, correct, delete, or export personal data (including Google user data we hold), to restrict or object to certain processing, and to opt out of sale or sharing. CalSafe does not sell personal information and does not share it for cross-context behavioral advertising.

Workspace admins can correct many fields in the product. For access, export, or deletion of an account or facility, write support@calsafe.io from the email on the account. We will verify the request. You may have an authorized agent make a California request. We will not discriminate against you for exercising privacy rights.

If we process workspace files for your facility, we will point facility-level requests to a facility admin when that is the right path. You may also have the right to complain to a data protection authority.

16

Children

CalSafe is for adult facility staff. We do not knowingly collect personal data from children under 16. If you believe we have, write support@calsafe.io and we will delete it.

17

International transfers

We host and process in the United States, and in the regions our processors use. If you access CalSafe from elsewhere, you understand your data, including Google user data used for Sign in with Google, may be processed in the United States, which may have different protection rules than your country.

18

Changes

We will post updates on this page and change the effective date. If we change how CalSafe uses Google user data, we will update this Privacy Policy before that new use, and we will notify users where the law or Google’s policy requires it. Continued use of the service after the new date means the updated policy applies. If you need a copy of a prior version, write support.

19

Contact

Privacy questions, including questions about Google user data: support@calsafe.io. A person on the team reads every message. If you need our legal entity name or mailing address, use that same address.

Questions about this document.

A person reads every message. Include the facility name if it is about a workspace.

Write support@calsafe.io. The other posted document is the Terms of Service.