§1Who we are, and who this policy covers
TrainedResponder is operated by InformaDev LLC, d/b/a TrainedResponder ("TrainedResponder", "we", "us"). We build training and qualification management software for emergency services agencies and volunteer organizations.
This policy covers two different relationships, and which one you are in decides who answers a request about your information.
If you signed your organization up, we hold your information on our own behalf. If your organization added you as a member, your organization decides what is in your record — we hold it for them, and we act on their instructions.
- Visitors and account holders — we are the business
- When you browse this site, request a demo, start a trial, or administer an organization's subscription, we decide how that information is used. California law calls us the business; other state laws call us the controller.
- Members of a customer organization — we are the service provider
- The training records, contact details, ranks, qualifications, and activity of an organization's members belong to that organization. It decides what is collected, who sees it, and how long it is kept. We process it only to provide the service under our contract with them. California law calls us the service provider; other state laws call us the processor. See §9 for how requests work in that case.
§2The information we collect
The categories below use the labels California's privacy law puts on them, so you can match this table against the statute. This is also our notice at collection: it describes everything we collect at or before the point we collect it.
| Category | What that means here | Where it comes from | Why we have it |
|---|---|---|---|
| Identifiers | Name, email address, mobile and other phone numbers, postal address, account and organization identifiers, IP address. | You, your organization's administrators, and automatically from your browser. | Creating and securing accounts, signing you in, sending service messages. |
| Customer records | Emergency contact name, relationship and phone; a government-issued responder, emergency worker, or badge number where your organization records one. | You, or a coordinator entering or importing a roster. | Rosters, callouts, and printing your state's activity and reimbursement forms. |
| Professional or training information | Unit, rank, role, course progress, exam results, practical evaluations, ratings and qualifications, certificates, event attendance, volunteer hours, mileage, and equipment issued to you. | Your activity in the platform, plus records entered by your organization. | Running training, tracking qualifications, and producing the reports your organization is accountable for. |
| Commercial information | Subscription plan, modules, billing contact, invoice and payment history. We never receive or store full payment card numbers. | Your organization's Owner, and our payment processor. | Billing, subscription management, and support. |
| Internet or network activity | Pages requested, timestamps, sign-in and sign-out events, error and security logs, and administrative actions recorded in your organization's audit trail. | Automatically, as you use the service. | Security, troubleshooting, abuse prevention, and the audit trail your organization relies on. |
| Content you upload | Documents, images, certificates, course material, and any file attached to a record. | You and your organization's administrators. | Storing and displaying it inside your organization. |
| Custom fields | Whatever additional member data fields your organization chooses to create. | Your organization. | Your organization's own purposes. We do not ask for these and we do not decide what goes in them. |
| Sensitive personal information | Your account log-in and password, and — where your organization records one — a government-issued identification number. | You and your organization. | Signing you in, and completing the government forms that ask for that number. Nothing else. |
What we do not collect
We do not collect precise geolocation, biometric information, or the contents of your email or messages. We do not build advertising profiles, and we draw no inferences about your characteristics, preferences, or behavior. We do not use sensitive personal information to infer anything about you — only to deliver the service described above — so the right to limit its use in §7 does not restrict anything we actually do. We will honor a request to limit it regardless.
§3Why we use it
We use personal information for these business purposes, and no others:
- Operating the service — accounts, training, exams, qualifications, scheduling, activations, and reporting.
- Communicating with you about your account, your training, and your organization's activity.
- Billing and subscription management.
- Support and troubleshooting, including diagnosing a problem an administrator reports.
- Security, fraud and abuse prevention, and maintaining the audit trail.
- Meeting our legal obligations and enforcing our terms.
- Improving the service, using aggregated or de-identified information that does not identify anyone.
If we ever want to use your information for a purpose that is not on this list and is not compatible with it, we will tell you first.
§5We do not sell or share personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in California's privacy law. We have not done so in the preceding twelve months, including for anyone we know to be under 16. There is nothing to opt out of, which is why you will not find a "Do Not Sell or Share My Personal Information" link on this site.
We run no advertising network tags, no analytics trackers, and no third-party marketing pixels on this site or in the application. The same statement satisfies Nevada's opt-out right under NRS 603A: we do not sell covered information.
California Shine the Light
California Civil Code §1798.83 lets California residents ask about personal information disclosed to third parties for their own direct marketing. We do not make those disclosures.
§6How long we keep it
We keep personal information for as long as it is needed for the purpose it was collected for, and then delete or de-identify it.
| Record | How long we keep it |
|---|---|
| Member accounts and training records | For as long as the organization's account is open. Your organization controls its own roster and can deactivate or delete a member at any time. |
| An organization's data after it closes its account | Deleted or de-identified within 60 days of the end of the subscription term, unless the organization asks for an export first or the law requires us to keep something. |
| Audit trail | Kept for the life of the organization's account. The audit trail is append-only by design — it survives a progress reset, because a record that can be quietly rewritten is not an audit trail. |
| Source material uploaded for AI course generation | Deleted when the course is finished. We keep only the citation behind each chapter, including the passage it quoted. |
| Server, security, and error logs | Up to 90 days, then removed automatically. |
| Text message opt-in and delivery records | As long as needed to evidence consent and troubleshoot delivery. Our SMS provider keeps its own records under its policy. |
| Invoices and payment records | Seven years, as tax and accounting rules require. |
Copies may persist briefly in encrypted backups after deletion; those age out on our hosting provider's rotation and are not used for anything else.
§7Your privacy rights
If you live in California, or in another state with a comprehensive privacy law — Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing list of others — you have the rights below. We extend them to everyone who asks, wherever you live, because operating two standards is a good way to get one of them wrong.
- Know and access
- Ask what personal information we hold about you, where it came from, why we have it, and who we disclosed it to — and get a copy in a portable format.
- Correct
- Ask us to fix information that is wrong. Members can correct much of their own profile directly in the app.
- Delete
- Ask us to delete personal information we hold about you. We may keep what the law requires us to keep, and we will tell you what and why.
- Opt out of sale, sharing, or targeted advertising
- We do none of these, so there is nothing to opt out of. See §5.
- Limit the use of sensitive personal information
- We already limit it to performing the service. See §2.
- No profiling or automated decisions
- We do not profile you, and no decision producing a legal or similarly significant effect about you is made by automated processing on our side. Rank advancement inside the platform follows the rules your own organization configures, and an administrator can override it.
- No retaliation
- We will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights.
- Appeal
- If we turn a request down, you can appeal. See §8.
§8How to exercise your rights
Email [email protected] with the subject line Privacy request. Tell us what you want us to do, and give us the email address and organization your record is under so we can find it. We operate entirely online and this is our designated method for privacy requests.
What happens next
- We confirm receipt within 10 business days and tell you how we will handle the request.
- We verify it is you by matching what you send against what we already hold. For a sensitive request we may ask for more; we use what you send only to verify you and then discard it. If we cannot verify you, we will say so rather than guess.
- We respond within 45 days. If a request is complex we may take one additional 45 days, and we will tell you before we do.
- It is free, unless a request is manifestly unfounded or repetitive, in which case we will explain the charge before doing the work.
Authorized agents
Someone may make a request for you. We will ask for written permission signed by you, and we will still verify your identity directly. A parent or guardian may act for a member under 18.
Appeals
If we decline, reply to our decision with Appeal in the subject line. A different person than the one who made the original decision will review it, and we will respond within 60 days with our conclusion and the reasons for it. If we deny the appeal, we will tell you how to contact your state's attorney general.
§9If you are a member of a customer organization
Your training record belongs to your agency, not to us. Ask them first — they can act immediately, and we will help them do it.
For member records we act as a service provider. That has a practical consequence worth stating plainly: if you ask us to delete or change your training record, we will forward the request to your organization's administrators rather than act on it ourselves, because that record is theirs and other people — a state program, an incident, a reimbursement claim — may depend on it. We will tell you that we have done so.
We will always answer directly about what we hold and how we handle it, and we act on your organization's deletion and correction instructions promptly.
§10Global Privacy Control and Do Not Track
Some browsers send an opt-out preference signal such as Global Privacy Control (GPC), and California law requires businesses to honor it as a valid opt-out of sale and sharing. We do not sell or share personal information, so there is nothing for the signal to switch off — but we treat it as a standing instruction and it costs you nothing to send one.
There is no consensus standard for older "Do Not Track" browser headers. We do not track you across other websites, with or without one.
§11Cookies and similar technologies
We set only strictly necessary cookies — the ones that sign you in, keep your session alive, protect forms against cross-site request forgery, and remember which organization a shared check-in device belongs to. There are no analytics, advertising, or profiling cookies on this site or in the application, which is why you are not being asked to accept any.
Every cookie we set is listed by name, purpose, and lifetime in the Cookie & Tracking Notice, along with the third-party endpoints a page contacts.
§12Text messages (SMS)
If your organization uses our scheduling and activation features, you may choose to provide a mobile number and opt in, in your member profile, to receive text messages — emergency activation alerts sent by your organization through the service, and confirmations of your own replies to them. Message frequency varies with your organization's activity. Message and data rates may apply. Consent to receive text messages is never a condition of participation or purchase.
Opt out at any time by replying STOP to any message, or by turning SMS off in your member profile; a confirmation is sent when you do. Reply HELP for help. We use a third-party SMS provider to send and receive these messages on our behalf; your mobile number and opt-in status are shared with that provider solely to deliver them. We do not share mobile information with third parties for promotional or marketing purposes, and no mobile opt-in data is sold or shared with anyone.
The full program disclosure is on the SMS Policy page.
§13AI course generation
When an administrator uses AI generation, the material they upload and the text of the lessons are sent to a third-party AI provider — Google (Gemini) or Anthropic (Claude), depending on which is active — so it can draft content. Your material is not used to train any model.
We store uploaded source documents only while the course is being built, because each lesson is generated separately and every generation sends the source material again. When the course is finished we delete the uploaded files and keep only the citations behind each chapter, including the passage each one quoted.
Member records are never sent to an AI provider. Only the course material an administrator submits for generation is.
§14Security
Traffic is encrypted in transit with TLS. Passwords are stored hashed and salted, never in readable form. Access is scoped by organization and by role, and administrative actions are written to an append-only audit trail. Platform credentials are held encrypted, not in configuration files.
No system is perfectly secure. If a breach affects your personal information we will notify you and the authorities as state law requires, without unreasonable delay. If you believe an account has been compromised, email [email protected] immediately.
§15Children
TrainedResponder is a workplace and volunteer-program tool sold to organizations, not a service directed to children, and we do not knowingly collect personal information from anyone under 13.
Some organizations run youth programs — explorer posts, teen CERT, cadet units. If yours enrolls members under 18, you are responsible for obtaining the parental consent your program and applicable law require before adding them, and for deciding what is in their records. We do not sell or share the personal information of anyone under 16, and we do not use it for advertising of any kind. If you believe a child under 13 has an account with us, email [email protected] and we will remove it.
§16Changes to this policy
We review this policy at least once a year. When we change it, we update the effective date at the top. If a change materially affects how we handle your information, we will notify account holders by email before it takes effect.
Questions or requests
InformaDev LLC d/b/a TrainedResponder — [email protected]
Members of a customer organization: your organization's administrators can answer most questions about your record faster than we can. See §9.