Privacy Policy
Last updated 7 August 2026
This explains what GuideOps Platform, Inc. collects, why, and who else touches it. It covers the GuideOps app and the Operator Console.
What we collect
- Account — your name, email address, and which sign-in method you used. If you sign in with Google we receive your name, email and profile picture from Google; we never receive your Google password.
- Operational — the observations, reports, photographs, voice recordings, zone boundaries and notes you create, along with the device timestamps attached to them.
- Location — GPS coordinates attached to observations and, while a day is open, your position shared with your own operation. See below.
- Billing — handled entirely by Stripe. We store a Stripe customer reference and your subscription status. We never see or store your card number.
- Technical — server logs (IP address, timestamp, which endpoint was called) kept to operate and secure the service.
Location data
This is the most sensitive thing here, so it gets its own section. Location is collected in two ways: attached to an observation, so the record says where it was made; and while a day is open, so the people in your own operation can see where their team is. It is tied to your operation and visible to that operation’s members. It is not visible to the public, it is not shared with other operations as your track, and it is never sold or used for advertising. Where another operation sees anything of yours, it is because your operating zones overlap on the map — the match is spatial, never by a shared identifier.
How we use it
- To run the service: store your work, sync it between your devices, and show it to your team.
- To produce the drafts and briefings you asked for.
- To bill you, and to send transactional email such as invites and account notices.
- To keep the service secure and diagnose faults.
We do not sell personal information, we do not run advertising, and we do not use your content to train AI models.
Who else processes it
- Supabase (United States) — database, file storage, authentication.
- Vercel (United States) — hosting for the web applications.
- Anthropic (United States) — AI processing of observation text and briefing content. Operator keys and identifiers are stripped before anything is sent, and Anthropic does not train on it.
- Stripe (United States) — payment processing.
- Resend (United States) — transactional email delivery.
If you use the service from outside the United States, your data is transferred to and stored in the United States.
Sharing outside GuideOps
Nothing leaves the platform on its own. An observation reaches InfoEx or any other external system only when a person in your operation explicitly approves that submission. We will disclose data if the law compels us, and we will tell you unless we are prohibited from doing so.
Retention
We keep your content while your account is active. After an account is closed we delete its content within 90 days, except where we must retain records for tax or legal reasons. Backups roll off within 30 days. Observations you have already submitted to InfoEx live in InfoEx too, under their retention rules, not ours.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Email privacy@guideops.app and we will respond within 30 days. Depending on where you live you may have further rights under the GDPR, the CCPA, or Canadian privacy law; we honour those requests regardless of where you are.
Security
Data is encrypted in transit and at rest. Access between operations is enforced in the database itself, not only in the application. We keep the number of people who can reach production data as small as possible.
Children
The service is for working guides and is not directed at anyone under 18. We do not knowingly collect information from children.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect.
Contact
GuideOps Platform, Inc. — privacy@guideops.app