RiskFree ("we", "our", "us") is committed to protecting your privacy. This policy explains how we collect, use, and protect your data when you use the RiskFree iOS application and website (riskfree.site).
1. Data We Collect
Account Information
- Email address (for account creation and communication)
- Name and company details (for document branding)
- Subscription and billing information (processed by RevenueCat)
Document Data
- Voice recordings (processed for transcription, not stored permanently)
- Photos of work areas (used for hazard detection, stored with your documents)
- Location data (GPS coordinates for site location and nearest A&E identification)
- Generated RAMS documents and associated metadata
- Company branding assets (logos, colour preferences)
Usage Data
- App usage patterns (features used, session duration)
- Device information (iOS version, device model)
- Crash reports and performance data
2. How We Process Your Data
On-Device Processing
Voice transcription is performed on your device using Apple's Speech framework. Audio recordings are processed locally and are not sent to our servers unless required for AI generation.
Cloud-Based AI Generation
When you generate a RAMS document, your transcribed text and uploaded photos are sent to our secure cloud infrastructure for AI processing. We use third-party AI services (currently Anthropic's Claude) to generate risk assessments. Your data is processed in accordance with our data processing agreements with these providers.
Important: Your data is NOT used for AI model training.
Neither RiskFree nor our AI processing partners use your documents, photos, voice recordings, or any other personal data to train or improve AI models.
3. Data Storage & Security
- All data is encrypted at rest and in transit (TLS 1.3)
- Document data is stored on Supabase infrastructure (EU/UK data centres)
- Authentication is handled via Supabase Auth with secure token management
- We follow industry-standard security practices including regular security audits
4. Data Retention
- Active accounts: Data is retained for the duration of your subscription
- Free tier: Document history is retained for 30 days
- Pro/Team: Full document history retained while subscription is active
- Account deletion: All personal data is permanently deleted within 30 days of account deletion request
- Voice recordings: Temporary recordings are deleted immediately after transcription
5. Third-Party Processors
We work with the following third-party data processors:
- Supabase — Database hosting, authentication, and file storage
- Anthropic (Claude) — AI document generation
- RevenueCat — Subscription billing and management
- Apple — App distribution, in-app purchases, crash reporting
Each processor is bound by data processing agreements that ensure compliance with applicable data protection laws.
6. Your Rights (GDPR)
Under the UK General Data Protection Regulation (UK GDPR), you have the right to:
- Access — Request a copy of your personal data
- Rectification — Correct inaccurate personal data
- Erasure — Request deletion of your personal data
- Portability — Receive your data in a machine-readable format
- Object — Object to processing of your personal data
- Restrict — Request restriction of processing
To exercise any of these rights, contact us at privacy@riskfree.site. We will respond within 30 days.
7. Cookies
The RiskFree website (riskfree.site) does not use tracking cookies or third-party analytics in its current version. If this changes, we will update this policy and implement appropriate consent mechanisms.
8. Terms of Service
By using RiskFree, you agree to use the service responsibly and in accordance with applicable health and safety legislation. Generated documents are AI-assisted drafts and must be reviewed by a competent person before use on site.
9. Disclaimer
RiskFree is designed to assist with the creation of safety documentation. Generated assessments are produced using AI and should be reviewed by a competent person before use on site. RiskFree does not replace professional health and safety advice. Users are responsible for ensuring all documentation is accurate, complete, and appropriate for their specific site conditions and work activities.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes via email or in-app notification. The "Last updated" date at the top of this page indicates when the policy was last revised.
11. Contact Us
For privacy-related enquiries or data requests:
- Email: privacy@riskfree.site
- General support: support@riskfree.site