Privacy Policy
Effective date: August 21, 2026
StationBay ("StationBay", "we", "us") is a station inventory management and training application for fire departments. This policy explains what information we collect, why we collect it, who processes it on our behalf, and the choices you have.
We wrote this in plain language on purpose. If something here is unclear, email support@stationbay.app and we will explain it.
1. Information you give us
Account information
- Email address (for email and password sign-in, and for password resets)
- Password (stored only as a cryptographic hash, never in readable form)
- Name: first name, last name, and the display name shown to your crew
- Badge or employee number, when you provide one
- Profile photo or avatar URL, when provided by you or your sign-in provider
Department and station information
- Department identifier (FDID) and state
- The station you join, including its name and street address
- Station geographic coordinates (latitude and longitude), derived from the address you enter when creating a station
- Your role within the department (guest, firefighter, or admin), your active status, and any qualification tags applied to your account
Verification information
- A single photograph taken during account verification, used by your department's admin to confirm you belong at that station. This photo is stored in restricted storage and is deleted once your verification is approved or rejected.
Legal acknowledgements
- The date and time you accepted the Terms of Service
2. Information collected automatically
- Usage and activity logs. Records of actions you take in the app, including inventory edits, catalog and kit changes, and equipment facts. Many records are stamped with your user identifier so your department can maintain accountability for equipment changes.
- Device language. Your operating system language code, used to generate study material in your language.
- On-device study history. Your drill performance (questions seen, answered correctly, and missed) is stored locally on your device to power study shuffling. This history stays on your device and is removed when you uninstall the app or clear its data.
- Technical and diagnostic data. Standard information needed to operate the service securely, such as authentication session records.
3. Sign-in with Google or Apple
If you sign in using Google or Apple, we receive the identity information those providers share with us, which typically includes a provider user identifier, your email address, your name, and an avatar URL. We use this to create and maintain your account. We never receive your password from these providers.
4. How we use your information
- Create and secure your account
- Place you in the correct department and station and apply the right permissions
- Enable department admins to verify personnel
- Let your crew maintain shared apparatus inventories and see who changed what
- Generate and improve training content and study drills
- Provide, bill, and support subscriptions
- Detect, investigate, and prevent abuse, fraud, and security incidents
- Comply with legal obligations
5. Visibility within your department
Apparatus, inventory, photos, and training data are private to your department. StationBay is not a public community, a social network, or a public feed, and nothing you enter is published to the internet or to other departments. The only content that can cross departments is a global catalog template that an administrator chooses to clone into their own catalog.
Within that boundary, StationBay is a shared workspace. Information such as your display name, badge number, role, and the inventory and equipment changes you make is visible to other authorized members and administrators of your department. Do not enter information into StationBay that you are not authorized to share with your department.
6. Service providers who process data for us
We use the following processors. Each receives only what it needs to perform its function.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication, database, file storage, and server-side functions | Account credentials, profile and department records, station data, uploaded photos, activity records |
| OpenAI | Generation of study questions and training material | Apparatus and equipment specifications, department-authored equipment facts, and your device language code |
| RevenueCat | Subscription and entitlement management | A pseudonymous account identifier (your authentication user ID) and purchase status |
| Google / Apple | Optional single sign-on and app store billing | Identity information you approve at sign-in; purchase and receipt data handled by the store |
| Operating system geocoding | Converting a station street address into coordinates | The station address you enter |
Payment card numbers are handled by the Apple App Store or Google Play and are never collected or stored by StationBay.
Study material generation sends equipment and apparatus data, not your name, email, or badge number.
7. We do not sell your data
StationBay does not sell your personal information to third-party data brokers. We do not sell, rent, or trade your personal information to advertisers, data brokers, list vendors, or any other third party for their own commercial purposes. We do not use your information to build advertising profiles, and we do not share it for cross-context behavioral advertising.
The only parties who receive your information are the service providers listed in Section 6, who act on our instructions, and recipients described in Section 8.
8. Other disclosures
We may disclose information when we reasonably believe it is necessary to:
- Comply with a valid legal obligation, court order, or lawful request
- Enforce our Terms of Service or investigate potential violations
- Protect the rights, property, or safety of users, the public, or StationBay
- Complete a merger, acquisition, or asset transfer, in which case we will provide notice before your information becomes subject to a different policy
9. Data retention and deletion
- Account and profile records are retained while your account is active.
- Verification photographs are deleted after your verification is approved or rejected.
- Inventory, catalog, and study records may be retained by your department for operational and accountability purposes even after your account is closed, since this data belongs to the department's records.
- You may request deletion of your account and associated personal information by using the in-app account deletion option, where available, or by emailing support@stationbay.app.
10. Security
We use industry-standard safeguards, including encrypted connections, hashed credentials, role-based access controls, and database-level row security policies that restrict data access to your own department. No system is perfectly secure, so we cannot guarantee absolute security.
11. Children's privacy
StationBay is intended for use by fire service personnel and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it.
12. International use
StationBay is operated from the United States. If you use the app from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate.
13. Your choices
- Update your display name, badge number, and profile details in Profile Settings
- Revoke camera and location permissions at any time in your device settings, though some features may stop working
- Email support@stationbay.app to request access to, correction of, or deletion of your personal information
- Depending on where you live, you may have additional rights under applicable privacy laws, including the right to know, delete, correct, and to not be discriminated against for exercising those rights
14. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you in the app. Continued use of StationBay after an update means you accept the revised policy.
15. Contact us
Questions, requests, or complaints about this policy can be sent to support@stationbay.app.