FireCal Platform

Privacy policy

Effective date: August 28, 2026

FireCal LLC ("FireCal", "we", "us", "our") builds software for the fire service. This policy explains what our applications collect, why we collect it, who else processes it, and how you can have it deleted.

Which applications this policy covers

This policy governs the FireCal platform and the FireCal family of applications published by FireCal LLC, including:

  • TruckCheck, apparatus checks and work orders

  • TaskBook, competency task books and skill sign-offs

  • CertLocker, certification and credential tracking

  • Shifts, scheduling and shift coverage

  • Dispatch, incident intake and sighting reports

  • Training, training records, sessions, and coursework

  • RunReport, run and incident reporting

  • FireLine, department messaging

It also covers your FireCal account, which signs you in to all of them, and firecal.app.

This policy does not cover the legacy CertLocker application. The original CertLocker app, published before the FireCal platform, operates on separate infrastructure and remains governed by its own privacy policy at docs.certlocker.app. If you are a user of that app and have not moved to the FireCal platform, that policy is the one that applies to you.

Not every application listed above collects everything described below. Where a practice is specific to one application, this policy says so.

The short version

These are work tools for fire departments. We collect what is needed to run your account, place you in your department, and store the records you create. We do not sell your personal information. Our applications contain no advertising and no behavioral tracking. Only one application, Dispatch, uses your location, and only while you are actively reporting a sighting.

1. Information you provide

Account information. A FireCal account is required. We collect your email address and a password, handled by Google Firebase Authentication. We record the date, time, and version of the terms you accepted at sign-up.

Profile information. Your profile carries a display name and a profile photo. You may optionally add your first, middle, and last name and suffix, a separate notification email address, a phone number, a short bio, a birthday, and a mailing address. You may also save a signature image, which is applied to documents you sign.

Organization information. Our applications are used inside a department. We store your membership in one or more organizations and your role in each (member, officer, or administrator). If you create or administer an organization, we store what you enter for it: name, description, contact email, contact phone, mailing address, and any logo or document seal you upload.

Work records you create. We store the records you make, which vary by application and include apparatus check results, work orders and their status history, parts and mileage, competency task books and skill sign-offs, certifications and credentials and their expiration dates, training sessions, coursework, quiz attempts and scores, schedules and shift assignments, incident and run reports, sighting reports, and messages you send to others in your department.

Sign-offs and attestations. When you sign off on a record, we store your name as it stood at that moment, the time of signing, and your saved signature image if you have one.

Files you upload. You can attach photos, PDFs, and documents to records. You can also submit a photograph or document to our import features, described in section 4.

Support communications. If you write to us, we keep the correspondence.

2. Information collected automatically

Push notification tokens. If you enable push notifications, we store a device push token for each device you sign in on, with the device type, which FireCal application it belongs to, and when it was created and last seen. These deliver notifications to your devices and are removed for an application when you sign out of it.

Time zone. The applications detect and save your device's time zone so scheduled reminders arrive at a sensible local hour. This is an identifier such as "America/Denver". It is not a location.

Notification preferences. We store which channels and events you have enabled.

Diagnostics. When an application encounters an error it may send us a report containing the error message, a stack trace, the location in the code, the application name and version, the platform, and, if you were signed in, your user ID. These reports go to Google Cloud Logging so we can find and fix faults.

Our applications contain no advertising software, no analytics software, and no behavioral tracking or cross-application profiling. We do not use advertising identifiers. We do not build a profile of your behavior.

Abuse prevention. The applications use Google Firebase App Check to confirm that requests come from a genuine copy of the application rather than an automated script.

3. Camera, photos, microphone, motion, and location

We ask for device permissions only for features that need them, and only at the point you use one.

Camera and photo library. Used across the applications when you choose to set a profile photo, attach a photo to a record, upload an organization logo or seal, or photograph a paper form for import. We never access your camera or photo library in the background.

Microphone. Used in FireLine, when you choose to record a voice note in a message thread. Dispatch can also accept and process an audio clip you attach. No FireCal application records audio in the background or without you starting a recording.

Location. Dispatch is the only FireCal application that uses your location. When you capture a sighting report, Dispatch reads your position while the capture screen is open, so that the direction you report can be plotted from where you are standing and combined with other reports to help locate a fire. This happens in the foreground, during capture only. Dispatch does not track you in the background, and does not follow your movements between reports.

None of the other FireCal applications collect location data. You may notice that some of them declare location permission text on iOS. That text is present only because those applications link a shared mapping component that references location functions, and Apple's delivery process requires the declaration to be present. Those applications never request your location and never receive it.

Motion sensors. Dispatch reads device orientation and heading during sighting capture so that the bearing you report is accurate. This is device orientation data, not location.

4. Documents, photographs, and AI processing

Several FireCal applications include features that read a document or a photograph and turn it into a structured record. Examples include importing an existing check sheet or task book to create a template, filing a completed paper form back into the application by photographing it, and transcribing an attached audio clip in Dispatch.

How this works. When you use one of these features, the file, photograph, or audio clip you provide is uploaded to our storage on Google Firebase. It is then sent to our artificial intelligence processor, Anthropic PBC, through the Anthropic API, which reads it and returns structured text. Nothing is written to your records until you review the result and confirm it.

What this means for you. The full contents of anything you submit to these features, including any information written on the page, are transmitted to Anthropic for processing. Do not submit material containing information you are not willing to have processed this way. These features are enabled per organization, so your department controls whether they are available to you at all.

Accuracy. These features produce a draft for you to check. They are not a substitute for your review, and our terms of service require that a person review the output before it is relied on.

Retention. We retain the uploaded source file and an audit record of the import, so that a record's origin can be traced later. You can request deletion of these as described in section 8.

5. How we use information

We use the information described above to:

  • create and operate your account and authenticate you;

  • place you in your department and apply your role and permissions;

  • store, display, search, and export the records you create;

  • deliver notifications you have asked for, by in-app inbox, push notification, email, or text message;

  • generate PDF exports, including sign-off blocks, organization seals, and signature images;

  • process documents, photographs, and audio you submit to the import features, as described in section 4;

  • send you service messages about your account, your department, or material changes to this policy;

  • diagnose faults, maintain security, and prevent abuse;

  • comply with law.

We do not use your information for advertising, and we do not use it to make automated decisions that produce legal effects about you.

6. Who we share information with

We do not sell your personal information. We do not share it with third parties for their own marketing purposes. We do not disclose it to data brokers.

Within your organization. These are collaborative tools. Other members of your department can see the records you create there, your name and profile photo, and sign-offs you have performed, according to the permissions your department has set. Organization administrators can see and manage membership, and can see the records their organization hosts.

People you share a record with. You can invite a specific signed-in FireCal user to view an individual record, including someone outside your department, for mutual aid or a compliance request. They receive read-only access to that record and its attachments and sign-offs, until you or your organization administrator revokes it.

Between FireCal applications. Your FireCal account, your profile, and your department membership are shared across the FireCal applications. Joining a department in one application joins it in all of them. Records created in one application are not copied into another, though an application may read a record it is designed to work with.

Service providers. The following companies process data on our behalf, under contract, and only for the purposes below:

ProviderWhat it doesGoogle (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, App Check, Remote Config, Cloud Logging)Authentication, database and file storage, backend processing, push notification delivery, abuse prevention, error loggingAnthropic PBCReads documents, photographs, and audio you submit to the import and transcription featuresTwilioDelivers text message notifications, where you enable that channelSendGrid (a Twilio company)Delivers email notifications

Legal and safety. We may disclose information where we are required to by law or valid legal process, to enforce our terms, or to protect the rights, property, or safety of our users, our company, or the public.

Business transfers. If FireCal is involved in a merger, acquisition, or sale of assets, your information may transfer as part of that transaction. We will give notice before your information becomes subject to a different privacy policy.

7. Your department's role

Where you use a FireCal application as a member of a department, that department generally controls the records created there. It decides who joins, what roles they hold, which features are enabled, and what happens to the department's records.

This matters in two practical ways. First, a request to correct or delete a record that belongs to your department may need to go to your department rather than to us, and we may direct you there. Second, your department retains records it is legally required to keep, even after you leave it or delete your account. See section 8.

8. Retention and deletion

Deleting your account. You can delete your FireCal account from inside any of the applications, under the More tab, then Delete Account. You confirm with your current password and by typing your email address. Deletion then enters a 30-day grace period, during which you can sign in and cancel it. Administrators of departments you belong to are notified when deletion is scheduled, so they can capture any compliance evidence they are required by law to retain.

Deleting your account deletes it across the whole FireCal platform, not only in the application you started from.

You may also request deletion by writing to billy@firecal.app.

What deletion removes. Once the grace period ends:

  • personal records not hosted by a department are permanently deleted;

  • records hosted by a department are permanently deleted from your account, and your file attachments are removed from your storage;

  • templates and materials you authored are marked as owner-deleted, and department administrators decide whether to keep them;

  • your user record is tombstoned and your personal information is blanked;

  • your authentication account is deleted.

What deletion does not remove, and why. Fire service records are compliance records, and two categories persist by design. Please understand this before you delete:

  • Department snapshots. Where a department relied on a record of yours, a frozen snapshot is retained by that department for its own compliance and recordkeeping obligations. Certification, competency, and apparatus records are routinely subject to state and accreditation retention requirements.

  • Sign-offs. A sign-off you performed on a shared record continues to show your name as it stood at the time of signing. A sign-off is an attestation about what someone verified and when. Altering the record of who made it would defeat the purpose of having one.

Department deletion. When a department is deleted, its internal records are permanently deleted, and its archived member snapshots are retained for seven years by default. Members' personal records are not deleted; only that department's reference to them is removed.

Other retention. Diagnostic logs are retained under Google Cloud Logging's retention settings and are not used to profile you. Push tokens are removed when you sign out. We keep records we are required by law to keep, for as long as we are required to keep them.

9. Security

Data is encrypted in transit using TLS, between the applications and our backend and between our backend and our processors. Data is encrypted at rest by Google Cloud. Passwords are handled by Google Firebase Authentication and are never stored by us in readable form. Access to production systems is restricted to personnel who need it. Requests are attested by Firebase App Check to reduce automated abuse.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.

10. Children

The FireCal applications are workplace tools for fire service personnel. They are not directed to children, and we do not knowingly collect personal information from anyone under 13. Departments that operate explorer, cadet, or junior programs are responsible for obtaining any consent their program and local law require before enrolling a minor. If you believe a child has provided us information, write to billy@firecal.app and we will delete it.

11. Your rights and choices

In the applications. Your profile is editable at any time. Notification channels are opt-in and can be turned off individually. Account deletion is self-service. You can revoke a record you shared with someone.

On request. Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of the personal information we hold about you, to object to certain processing, and not to be discriminated against for exercising those rights. Write to billy@firecal.app and we will respond within the time your law requires. We may need to verify your identity before acting, and we may direct you to your department where the record belongs to them.

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in United States state privacy laws.

12. International users

FireCal LLC operates in the United States. Information is processed and stored in the United States. If you use a FireCal application from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.

13. Changes to this policy

If we make a material change to this policy we will update the effective date above, and where the change is significant we will notify you in the applications or by email before it takes effect. Continued use after a change takes effect means you accept the updated policy.

14. Contact us

FireCal LLC Email: contact@firecal.app

If you have a question about this policy, a request about your information, or a concern about how a department is using a FireCal application, write to us at the address above.