Privacy Policy
Last updated: July 2026
This policy explains what data Sage EHS collects, how we store it, and what choices you have. We wrote it in plain language so everyone on your team can understand it.
Data We Collect
Sage EHS collects only what is needed to create and manage safety records:
- Worker names and email addresses
- Digital signatures drawn on screen (used for safety plan acknowledgment)
- Incident reports, which may include injury details, photos, and witness information
- Atmospheric and environmental readings
- Work descriptions, hazard assessments, and permit details
How Data Is Stored
Your safety records are stored primarily on your device using localStorage and IndexedDB. This means your data stays with you and works even when you have no internet connection.
If your organization enables sync, records can also be sent to Notion for centralized record management. This is optional and configured by your organization.
Digital Signatures
When crew members sign a pre-task plan or other safety document, the signature is captured as an image and stored locally on the device. When you sign a pre-trip equipment inspection, the signature image is also attached as a PNG to the inspection notification email sent to your EHS team through Resend. Signature images are not uploaded by Notion sync and are never sent to AI features. They are used solely to document that a worker reviewed and acknowledged the record.
Third-Party Services
Sage EHS integrates with the following services. All are optional and controlled by feature flags set by your organization:
- Anthropic Claude API -- Work descriptions, hazard information, incident descriptions, and safety-record context may be sent to Anthropic's Claude AI for analysis and suggestions. That context can include worker and supervisor names exactly as they appear on the record being analyzed. Data sent to Claude is subject to Anthropic's API data policy.
- Notion -- Safety records can be synced to your organization's Notion workspace for centralized access and record keeping.
- Resend -- Used to send email notifications as part of the EHS review workflow (for example, notifying a manager that a plan is ready for approval).
- Slack -- Optional notifications can be sent to a Slack channel when new safety records are submitted. A one-time notification containing your name and email is also sent the first time you sign in.
- Google -- Used for OAuth authentication so you can sign in with your Google account.
- Sentry -- Error monitoring. When something breaks, technical details of the error (stack trace, device and browser information) are sent to Sentry so we can diagnose and fix it.
- Upstash Redis (Vercel KV) -- Server-side storage for sign-in tracking (name and email, kept 90 days), beta program signups (180 days), EHS review submissions (7–30 days), and rate-limit counters.
- Vercel -- Hosts the application. Like any hosting provider, it processes requests to serve the app and keeps standard server logs.
Cookies
Sage EHS does not use tracking cookies, analytics cookies, or advertising cookies. The only cookie used is a single HTTP-only session cookie for authentication when you sign in.
AI Features
AI-powered features in Sage EHS (such as hazard suggestions, atmospheric analysis, and incident analysis) are opt-in and controlled by feature flags. All AI suggestions are advisory only and should be reviewed by qualified personnel.
When AI features are used, the request contains work-related context -- job descriptions, hazard lists, and atmospheric readings -- and can include worker and supervisor names as they appear on the safety record being analyzed (for example, a pre-task plan review includes the worker's name and which crew members have signed). Signature images and photos are never sent to the AI provider.
Data Retention
These are the retention periods the app actually implements:
- Safety records on your device that have synced to Notion are automatically removed from the device 90 days after creation (the archiver runs when the app loads). Records that have never synced stay on your device until you clear them.
- Unsubmitted form drafts are deleted after 7 days.
- Server-side records expire automatically: sign-in tracking after 90 days, beta signups after 180 days, EHS review submissions after 7 days (30 days once a decision is recorded).
- Records synced to Notion follow your organization's Notion workspace retention.
The app is not your organization's system of record: OSHA requires longer retention for some records (for example, incident reports must be kept five years) than a device keeps locally. Use Notion sync and CSV export to preserve durable copies. See the compliance & retention mapping for how app behavior relates to OSHA record-keeping requirements, and the store-by-store retention schedule for every place data lives.
Your Data Rights
You can export your safety records at any time using the CSV export feature built into the app.
Changes to This Policy
We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.