Privacy Notice
How your data is handled
This Notice explains what process_safety.ai (“we,” “us,” or “our”) processes when you visit the website or use the Cause Map tool, what stays on your device, and the choices available to you.
The short version: the current Cause Map has no user accounts, payments, advertising, or cloud map storage. Your investigation content and attachments remain in your browser unless you download an export. Public form submissions are sent to our form provider. Product analytics run automatically when configured and are designed not to include investigation content.
1. Scope and operator
This Notice applies to the process_safety.ai website, its public beta and feedback forms, and the Cause Map tool. It does not govern third-party websites or services that have their own privacy terms.
For privacy questions or requests, contact hello@process_safety.ai.
2. Information we process
Cause Map content stored on your device
The tool processes the information you enter so it can work in your browser. This may include a problem outline, cause nodes, solutions, timeline entries, process-map content, filenames, and evidence attachments such as images, videos, PDFs, Word documents, spreadsheets, text files, and CSV files.
We do not receive this content through the Cause Map tool. If you enable autosave, the content is stored in your browser’s IndexedDB on that device. Autosave is optional. Your autosave choice is stored in local storage.
Files you export or import
When you export a Cause Map, the browser creates a JSON file on your device. Evidence attachments are embedded in that file as encoded data. When you import a file, your browser reads it locally. The application does not upload imported or exported Cause Map files to us.
Forms and direct communications
If you submit a beta request or feedback form, we collect the fields shown on the form. These may include your name, company, work email address, and message. If you email us, we receive your email address, message, and any information you choose to include.
Our server validates and rate-limits form submissions, then forwards approved fields to Winterlude, our form-processing provider. The application does not maintain its own database of form responses.
Product analytics
When configured, every page automatically loads an Umami analytics tracker through our own website and records pageviews. The Cause Map also records allowlisted workflow events, such as opening a view, adding a cause or solution, adding an image, video, or document attachment, using map layout, enabling or clearing autosave, and importing or exporting a map.
Analytics events may include the event category, current page path, site hostname and title, browser user-agent, and preferred language. The default privacy-first server configuration does not forward your client IP address to Umami. Our hosting provider necessarily receives an IP address when it serves the website and may process it in ordinary security or access logs.
Analytics do not include Cause Map text, problem details, timeline descriptions, filenames, attachment names or contents, facility or equipment names, personal names, free-text form fields, URL search terms, or URL fragments. The tracker respects a browser’s Do Not Track setting.
Basic website and security data
When you request a page, our server and hosting or network providers may process standard request information such as IP address, date and time, requested resource, browser type, and error or security data. The form endpoint also uses an IP-based count in volatile server memory to limit submissions during a 15-minute window.
3. Why we use information
| Purpose | Information | Basis where required |
|---|---|---|
| Operate the site and Cause Map | Local Cause Map content, preferences, and basic request data | Provide the service you request and our legitimate interest in operating it |
| Respond to beta requests, feedback, and questions | Form and email information | Your request, consent where applicable, and our legitimate interest in product development |
| Understand feature adoption and improve the tool | Allowlisted Umami events | Our legitimate interest in product development |
| Prevent abuse and protect the service | IP-based rate-limit and security data | Our legitimate interests and legal obligations |
4. Cookies, local storage, and Do Not Track
The current site does not use advertising cookies. The Cause Map uses browser storage for autosave:
- Local storage records whether you enabled autosave.
- IndexedDB stores your Cause Map draft only when you enable autosave.
You can use the Cause Map toolbar to turn off autosave and delete the local draft, or clear local data. You can also clear site data in your browser settings. Blocking browser storage may prevent these preferences or autosave from working.
The analytics tracker honors Do Not Track. Because we do not use cross-site behavioral advertising, other browser-based opt-out signals do not change advertising behavior on this site.
6. Retention
- Local Cause Map drafts: autosaved drafts expire 30 days after the most recent save. The application removes an expired draft when the tool next opens. You may delete it sooner from the toolbar or browser.
- Exported files: remain wherever you save or share them until you delete them. We do not control their retention.
- Form and email information: is retained by the relevant form and communication systems for as long as reasonably needed to respond, manage beta participation, maintain business records, resolve disputes, or comply with law.
- Rate-limit data: is used for a 15-minute abuse-prevention window and kept only in volatile application memory.
- Analytics: is retained for the period reasonably necessary to measure feature adoption and product performance, then deleted or aggregated. Retention is governed by the administrative settings of the applicable Umami deployment.
- Infrastructure logs: may be retained by hosting and network providers under their operational and security schedules.
7. Security and sensitive information
We use measures intended to limit unnecessary collection and protect the site, including local-first Cause Map storage, analytics event allowlists, size and type validation for imports, form validation and rate limiting, restrictive browser security policies, and security response headers. No system is completely secure.
Cause Map exports and browser autosaves are not encrypted by this application. Protect your device and exported files, follow your organization’s information-handling requirements, and do not put trade secrets, incident reports, regulated personal data, health information, export-controlled information, or other confidential operational content into public feedback or beta forms. See our Data & Security notice for more detail.
8. Your privacy choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or an objection to certain processing. You may also withdraw consent. Withdrawing consent does not affect processing that occurred before withdrawal.
- Use a browser’s Do Not Track setting, which the analytics tracker honors.
- Clear the autosaved Cause Map using Clear local data or your browser settings.
- Ask us about or request deletion of form, email, or analytics information by emailing hello@process_safety.ai.
Because local Cause Map content is not sent to us, we cannot access, correct, restore, or delete it for you. We may need to verify your identity before acting on a request. You may also have the right to complain to your local privacy or data-protection authority. We will not discriminate against you for exercising applicable privacy rights.
9. International processing
Our providers may process information in countries other than yours. Where required, we use contractual or other recognized safeguards for international transfers. Local Cause Map content is not transferred by us because it remains in your browser unless you independently export and share it.
10. Children
The website and Cause Map are professional tools and are not directed to children under 16. We do not knowingly collect personal information from children through the service. Contact us if you believe a child submitted personal information.
11. Changes to this Notice
We may update this Notice as the product changes, including when accounts, paid features, or cloud services are introduced. We will post the updated version here and change the effective date. If a change materially affects a consent-based feature, we will request a new choice when appropriate.
12. Contact
Email privacy questions and requests to hello@process_safety.ai. Please do not include confidential investigation content in an unencrypted email.