Stratum

Privacy Policy

Effective date: June 21, 2026  ·  Last updated: June 21, 2026

Stratum is a workplace safety inspection platform for sand, gravel, and aggregate mining operations. This policy explains what data we collect, how we use it, and your rights as a user.

1. Who We Are

Stratum is operated by Stratum LLC. For privacy questions, contact us at sethwindsor8@protonmail.com.

2. Who Uses Stratum

Stratum is an invite-only, B2B application for mining organizations. There is no open registration. Accounts are created by an organization administrator and are associated with a specific organization and one or more mine sites. Personal data is processed on behalf of the employing organization.

3. Data We Collect

3a. Account & Identity Data

Collected when an administrator creates your account or when you sign in:

3a-i. Location Data

Stratum collects your precise location only at the moment a contractor checks in to or out of a site, to timestamp and place that site visit. It is collected in the foreground, while you are actively using the app, and only when you tap check in or check out.

Location is also read once when you log a fugitive dust environmental reading, to fill in the current wind and weather conditions at the site — the conditions an MSHA inspector asks about when a dust reading is over the action level. The coordinates are sent from our server to our weather provider (Tomorrow.io) to look up conditions; nothing identifying you or your organization is sent with them. Declining location, or having no signal, simply leaves the weather field for you to type.

3b. Organization & Site Data

3c. Inspection Data

3d. Usage & Diagnostic Data

We do not collect background location (see §3a-i for the one foreground use). We do not collect microphone audio or video. We do not access your photo library. We do not use data for advertising, and we do not track you across other apps or websites.

4. How We Use Your Data

PurposeData used
Delivering the inspection serviceAll inspection data, photos, findings
AI-powered hazard analysis (see §5)Inspection photos
Authentication and account managementName, email, phone, auth tokens
Push notifications (sync status, findings)Device push token, associated org/site
In-app analytics for your organizationAggregated inspection and findings counts
Compliance recordkeepingInspection records, findings, corrective actions

5. AI Photo Analysis — Anthropic Claude

This is the most significant third-party data flow in Stratum. Inspection photos are sent to Anthropic's API for AI analysis.

When you complete an AI HSA Audit and sync, Stratum's backend sends inspection photos to Anthropic's Claude API (anthropic.com) for MSHA hazard analysis. The photos are transmitted as image data and analyzed by Claude's vision model to identify potential safety hazards relevant to the inspection type and applicable 30 CFR standards.

HSA Audits are never sent to Anthropic. When an examiner records findings themselves — writing the description and selecting the 30 CFR standard on the device — those photos are stored in your organization's private bucket and go no further. Reports state on their face which of the two produced their findings.

Anthropic processes this data according to their Privacy Policy and API usage terms. Under Anthropic's commercial API terms, photos and analysis outputs are never used to train Anthropic's models, and API inputs and outputs are automatically deleted from Anthropic's systems within 7 days (see Anthropic's data usage policy). We recommend reviewing Anthropic's current privacy terms before relying on this for compliance purposes, as terms may change.

Photos sent to Anthropic include: the image content and a label identifying the photo position (e.g., "front", "left side", "photo_1"). No personal identity information about the inspector is included in the API payload.

6. Third-Party Services

ServicePurposeData sharedTheir privacy policy
Clerk (clerk.com) Authentication, session management Name, email, phone, device tokens clerk.com/privacy
Supabase (supabase.com) Database and photo storage All app data including photos supabase.com/privacy
Tomorrow.io Current site weather when logging a fugitive dust reading Approximate coordinates only — no name, account, or inspection data. Sent from our server, not from your device, so Tomorrow.io never sees your device or identity. tomorrow.io/privacy-policy
Anthropic (anthropic.com) AI hazard analysis of inspection photos Inspection photos (see §5) anthropic.com/privacy
Cloudflare (cloudflare.com) Backend networking and transit Encrypted traffic in transit only cloudflare.com/privacypolicy
Expo / EAS (expo.dev) App build, delivery, and OTA updates App version, device info for updates expo.dev/privacy

7. Data Storage & Security

Inspection data and photos are stored in Supabase (hosted on AWS infrastructure). Data is encrypted in transit via HTTPS/TLS. Authentication tokens are stored on-device using the platform's secure enclave (iOS Keychain, Android Keystore).

Offline inspection data — photos and inspection details queued while you are on a remote site without connectivity — is held in the app's private storage area on your device, protected by your device's operating-system encryption and accessible only to Stratum. It uploads automatically when connectivity is restored, and the local copy is deleted once the upload is confirmed.

Access to your organization's data is restricted to users who belong to your organization. Data from one organization is not accessible to users of another organization.

8. Data Retention

Inspection records, findings, photos, and corrective actions are owned by the organization and retained for the lifetime of the organization's account. These records may be subject to MSHA recordkeeping requirements (30 CFR Part 50) that mandate minimum retention periods independent of this policy.

Account (personal) data — name, email, phone, auth credentials — is retained while your account is active and deleted or anonymized when you request account deletion (see §9).

Your organization can export its complete data set at any time from the web dashboard's Reports page in standard formats (PDF, CSV, JSON). If a subscription is terminated, organizational data is retained for a 90-day grace period so it can be exported before deletion. Stratum never sells, shares, or discloses customer data to any third party.

9. Account Deletion & Your Rights

You can delete your account yourself, in either place:

Both use the same process. When you delete your account:

If you are the sole administrator of an organization, you must transfer organization ownership to another user before your account can be deleted. If no other user exists, contact us at sethwindsor8@protonmail.com to wind down the organization and initiate full deletion.

A name you already signed onto a document — an inspection report, a toolbox talk attendance sheet, a signed form — stays on that document. That is what makes it a record, and it is retained under the same organizational-records rule above. No new documents can be signed in your name once your account is deleted.

If you cannot sign in, you may also request deletion by email: sethwindsor8@protonmail.com, subject line "Data Deletion Request", including the name and email address associated with your account. We will respond within 30 days.

10. Children's Privacy

Stratum is designed for use by adult employees of mining operations. We do not knowingly collect data from anyone under 18 years of age. This app is not directed at or suitable for children.

11. Changes to This Policy

We may update this policy periodically. When we do, we will update the "Last updated" date at the top of this page. Continued use of Stratum after an update constitutes acceptance of the revised policy. Material changes will be communicated via in-app notification or email.

12. Contact

For privacy questions, data requests, or to exercise your rights, contact:
Stratum LLC
sethwindsor8@protonmail.com