Privacy Policy
Stratum is a workplace safety inspection platform for sand, gravel, and aggregate mining operations. This policy explains what data we collect, how we use it, and your rights as a user.
1. Who We Are
Stratum is operated by Stratum LLC. For privacy questions, contact us at sethwindsor8@protonmail.com.
2. Who Uses Stratum
Stratum is an invite-only, B2B application for mining organizations. There is no open registration. Accounts are created by an organization administrator and are associated with a specific organization and one or more mine sites. Personal data is processed on behalf of the employing organization.
3. Data We Collect
3a. Account & Identity Data
Collected when an administrator creates your account or when you sign in:
- Name
- Full legal name (first, middle, last) — collected the first time you sign a document, and printed on the records you sign so a signature can be attributed to a specific person
- Email address
- Phone number (optional, used for notifications)
- Your handwritten signature, drawn on-screen and stored as an image, applied to inspection reports, toolbox talk attendance records, signed forms, and contractor orientation sign-offs
- Authentication tokens (stored encrypted on-device via iOS Keychain / Android Keystore)
- Push notification token, if you enable notifications
3a-i. Location Data
Stratum collects your precise location only at the moment a contractor checks in to or out of a site, to timestamp and place that site visit. It is collected in the foreground, while you are actively using the app, and only when you tap check in or check out.
- We do not collect location in the background.
- We do not track your location continuously or between visits.
- We do not collect location during inspections, photo capture, or any other part of the app.
- If you decline the location permission, check-in still works — the visit is simply recorded without coordinates.
Location is also read once when you log a fugitive dust environmental reading, to fill in the current wind and weather conditions at the site — the conditions an MSHA inspector asks about when a dust reading is over the action level. The coordinates are sent from our server to our weather provider (Tomorrow.io) to look up conditions; nothing identifying you or your organization is sent with them. Declining location, or having no signal, simply leaves the weather field for you to type.
3b. Organization & Site Data
- Organization name and structure (sites, crews, assignments)
- Site names and identifiers
- Employee records (name, role, site assignments) within your organization
3c. Inspection Data
- Inspection type, date, site, crew, and status
- Checklist responses
- Photos of equipment and work areas taken during inspections
- Findings: identified hazards, severity, applicable MSHA regulation citations (30 CFR)
- Corrective actions and their resolution status
3d. Usage & Diagnostic Data
- Aggregated counts of inspections and findings by site (used for analytics within your org)
- Sync status and upload queue state (stored locally, not transmitted separately)
We do not collect background location (see §3a-i for the one foreground use). We do not collect microphone audio or video. We do not access your photo library. We do not use data for advertising, and we do not track you across other apps or websites.
4. How We Use Your Data
| Purpose | Data used |
|---|---|
| Delivering the inspection service | All inspection data, photos, findings |
| AI-powered hazard analysis (see §5) | Inspection photos |
| Authentication and account management | Name, email, phone, auth tokens |
| Push notifications (sync status, findings) | Device push token, associated org/site |
| In-app analytics for your organization | Aggregated inspection and findings counts |
| Compliance recordkeeping | Inspection records, findings, corrective actions |
5. AI Photo Analysis — Anthropic Claude
When you complete an AI HSA Audit and sync, Stratum's backend sends inspection photos to Anthropic's Claude API (anthropic.com) for MSHA hazard analysis. The photos are transmitted as image data and analyzed by Claude's vision model to identify potential safety hazards relevant to the inspection type and applicable 30 CFR standards.
HSA Audits are never sent to Anthropic. When an examiner records findings themselves — writing the description and selecting the 30 CFR standard on the device — those photos are stored in your organization's private bucket and go no further. Reports state on their face which of the two produced their findings.
Anthropic processes this data according to their Privacy Policy and API usage terms. Under Anthropic's commercial API terms, photos and analysis outputs are never used to train Anthropic's models, and API inputs and outputs are automatically deleted from Anthropic's systems within 7 days (see Anthropic's data usage policy). We recommend reviewing Anthropic's current privacy terms before relying on this for compliance purposes, as terms may change.
Photos sent to Anthropic include: the image content and a label identifying the photo position (e.g., "front", "left side", "photo_1"). No personal identity information about the inspector is included in the API payload.
6. Third-Party Services
| Service | Purpose | Data shared | Their privacy policy |
|---|---|---|---|
| Clerk (clerk.com) | Authentication, session management | Name, email, phone, device tokens | clerk.com/privacy |
| Supabase (supabase.com) | Database and photo storage | All app data including photos | supabase.com/privacy |
| Tomorrow.io | Current site weather when logging a fugitive dust reading | Approximate coordinates only — no name, account, or inspection data. Sent from our server, not from your device, so Tomorrow.io never sees your device or identity. | tomorrow.io/privacy-policy |
| Anthropic (anthropic.com) | AI hazard analysis of inspection photos | Inspection photos (see §5) | anthropic.com/privacy |
| Cloudflare (cloudflare.com) | Backend networking and transit | Encrypted traffic in transit only | cloudflare.com/privacypolicy |
| Expo / EAS (expo.dev) | App build, delivery, and OTA updates | App version, device info for updates | expo.dev/privacy |
7. Data Storage & Security
Inspection data and photos are stored in Supabase (hosted on AWS infrastructure). Data is encrypted in transit via HTTPS/TLS. Authentication tokens are stored on-device using the platform's secure enclave (iOS Keychain, Android Keystore).
Offline inspection data — photos and inspection details queued while you are on a remote site without connectivity — is held in the app's private storage area on your device, protected by your device's operating-system encryption and accessible only to Stratum. It uploads automatically when connectivity is restored, and the local copy is deleted once the upload is confirmed.
Access to your organization's data is restricted to users who belong to your organization. Data from one organization is not accessible to users of another organization.
8. Data Retention
Inspection records, findings, photos, and corrective actions are owned by the organization and retained for the lifetime of the organization's account. These records may be subject to MSHA recordkeeping requirements (30 CFR Part 50) that mandate minimum retention periods independent of this policy.
Account (personal) data — name, email, phone, auth credentials — is retained while your account is active and deleted or anonymized when you request account deletion (see §9).
Your organization can export its complete data set at any time from the web dashboard's Reports page in standard formats (PDF, CSV, JSON). If a subscription is terminated, organizational data is retained for a 90-day grace period so it can be exported before deletion. Stratum never sells, shares, or discloses customer data to any third party.
9. Account Deletion & Your Rights
You can delete your account yourself, in either place:
- In the app — More → Delete account.
- On the web, without installing the app — sign in at My Account and choose Delete my account.
Both use the same process. When you delete your account:
- Personal data — name, full legal name, email, phone number, your stored signature image, push notification token, and authentication credentials — is deleted.
- Organizational data (inspections, findings, photos, corrective actions you authored) is retained as part of your organization's compliance records. This data belongs to the organization, not to your individual account, and may be subject to mandatory MSHA retention requirements.
If you are the sole administrator of an organization, you must transfer organization ownership to another user before your account can be deleted. If no other user exists, contact us at sethwindsor8@protonmail.com to wind down the organization and initiate full deletion.
A name you already signed onto a document — an inspection report, a toolbox talk attendance sheet, a signed form — stays on that document. That is what makes it a record, and it is retained under the same organizational-records rule above. No new documents can be signed in your name once your account is deleted.
If you cannot sign in, you may also request deletion by email: sethwindsor8@protonmail.com, subject line "Data Deletion Request", including the name and email address associated with your account. We will respond within 30 days.
10. Children's Privacy
Stratum is designed for use by adult employees of mining operations. We do not knowingly collect data from anyone under 18 years of age. This app is not directed at or suitable for children.
11. Changes to This Policy
We may update this policy periodically. When we do, we will update the "Last updated" date at the top of this page. Continued use of Stratum after an update constitutes acceptance of the revised policy. Material changes will be communicated via in-app notification or email.
12. Contact
For privacy questions, data requests, or to exercise your rights, contact:
Stratum LLC
sethwindsor8@protonmail.com