Privacy Policy
Effective April 28, 2026 · Last updated July 27, 2026
Steel Toe Technologies, Inc. (“Thalos,” “we,” “us,” or “our”) operates the Thalos safety compliance platform, including our web application at app.thalostech.io and our iOS and Android mobile applications (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use it, and the rights you have over your data.
1. Information We Collect
Account information
When you or your employer creates an account, we collect your name, email address, organization, role, and authentication identifiers provided through our identity provider (Clerk).
Content you submit
To deliver compliance monitoring, we process images, videos, and documents you upload for hazard detection and regulatory analysis; task, violation, and site records you create; and natural-language questions you ask our AI assistant, Paulie.
To perform this analysis, the images and documents you submit, and the questions you ask Paulie, are sent to third-party AI providers that process them on our behalf to provide the Service — currently OpenAI (image hazard detection and Paulie responses) and Hugging Face (regulatory semantic search). We do not use your content to train AI models except with your separate, optional opt-in.
Device and usage data
We automatically collect device identifiers, operating system version, application version, IP address, and product usage events for security, diagnostics, and product improvement. On mobile we collect a push-notification token (APNs on iOS, FCM on Android) tied to your user account so we can deliver task and violation alerts. You can revoke notification permission at any time in your device settings.
Camera and photo library
Our mobile app requests access to your camera and photo library only to let you capture or select images for safety inspections, and to scan QR or barcode tags on equipment. Images are uploaded to our secure storage and processed for hazard detection. Scanned codes are stored as part of the inspection record. We do not access your camera in the background.
Microphone and voice input
Our mobile app requests microphone access only when you tap the voice-to-text microphone icon to dictate a hazard description or a message to our AI assistant. Your speech is converted to text by the operating system’s speech recognition service (Apple’s on iOS, Google’s on Android). On iOS this is a cloud service, so the audio is transmitted to Apple to produce the transcription; it is never sent to or stored by Thalos — we receive only the resulting text. The microphone is never accessed in the background.
Location
If you grant location permission, we associate coarse latitude and longitude with the inspection record at upload time so your organization can attribute the finding to a site. By default we use “while in use” permission only.
A future feature, Proximity Hazard Alerts (currently in development), requires “always” location permission so the app can warn you when you walk near an unresolved hazard on a jobsite. This feature is opt-in: even after you grant the permission at the operating system level, you must turn it on in Settings before any background location is collected. We will update this policy with a specific effective date when the feature ships.
Biometric authentication
If you enable Face ID, Touch ID, or Android fingerprint to unlock the app, the biometric data stays on your device and is verified by the operating system. Thalos never receives or stores your face or fingerprint data — we receive only a yes/no result from the OS.
2. How We Use Information
- To operate hazard detection, regulation lookup, and reporting features.
- To send operational notifications (task assignments, overdue reminders, violation alerts).
- To authenticate users, enforce organization permissions, and prevent abuse.
- To provide customer support and respond to requests.
- To improve model accuracy and product performance using aggregated and de-identified data.
- To comply with legal obligations and enforce our Terms of Service.
3. How We Share Information
We do not sell personal information. We share data only with:
- Your organization. Content you submit is visible to authorized members of the organization that owns your account.
- Service providers that operate our infrastructure and features, including Clerk (authentication), Amazon Web Services (hosting and storage), Neon (database), OpenAI (AI hazard detection, regulatory analysis, and Paulie responses), Hugging Face (regulatory semantic search), Stripe (billing), Resend (email delivery), PostHog and Sentry (product analytics and error monitoring), Firebase Cloud Messaging and Apple Push Notification service (push delivery), Apple and Google speech services (cloud voice-to-text when you use voice input), and OpenStreetMap (map tile rendering). Each provider is contractually bound to use data only to deliver its service.
- Legal and safety. When required by law, legal process, or to protect the rights, property, or safety of Thalos, our users, or the public.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy.
4. Data Retention
We retain account and content data for as long as your organization maintains an active subscription, plus a reasonable period for backups, audit, and legal compliance. You or your organization administrator can request earlier deletion at privacy@thalostech.io.
5. Security
We encrypt data in transit using TLS and at rest using industry-standard encryption. Access to production systems is restricted, logged, and audited. No system is perfectly secure; we encourage you to use a strong password and enable multi-factor authentication through your identity provider.
On mobile, photos you capture offline are queued in your device’s local storage (IndexedDB) and uploaded automatically when connectivity returns. The queue is scoped to your active organization and cleared if you switch organizations or sign out.
6. Your Rights
Depending on your jurisdiction (including the EU/EEA under GDPR and California under CCPA/CPRA), you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. To exercise these rights, contact us at privacy@thalostech.io. We will respond within the time required by applicable law.
7. Children
The Service is intended for workplace use by adults. We do not knowingly collect personal information from children under 16.
8. International Transfers
Our infrastructure is operated in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the United States under appropriate safeguards.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide in-product notice. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
10. Contact Us
Questions or requests regarding this Privacy Policy can be sent to privacy@thalostech.io.