---
title: "Privacy Policy"
url: "https://staging.bepreparedsolutions.co/privacy"
description: "How BePreparedSolutions.co collects, uses, and protects your data, including the address and household details behind your alerts and your plan."
source: "BePrepared Solutions"
---

# Privacy Policy

Last Updated: October 6, 2026

### Table of Contents

## [1\. Introduction](#introduction)

📌 Key Points (Plain English)

This Privacy Policy explains how Be Prepared, Inc. collects, uses, and protects your personal information. We are committed to transparency and protecting your privacy rights, including GDPR rights for EU users and CCPA/CPRA rights for California residents.

Welcome to Be Prepared, operated by Be Prepared, Inc., incorporated in the State of Delaware and operating in New Jersey ("we," "us," "our"). We are committed to protecting your personal information and your right to privacy.

This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our website and application (collectively, the "Service"). Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

**Contact Information:**
Be Prepared, Inc.
Email: [privacy@bepreparedsolutions.co](mailto:privacy@bepreparedsolutions.co)

## [2\. Information We Collect](#data-collection)

📌 Key Points (Plain English)

We collect information you provide directly (account details, household data, addresses, payment info), automatically through cookies and analytics (only after consent), and via third-party services that help us operate. The list of subprocessors is in Section 12. We do NOT sell your personal information.

### 2.1 Information You Provide

We collect information that you provide directly to us, including:

-   **Account Information:** Email address, password (hashed), optional phone number, optional Google profile data if you use Google Sign-In
-   **Profile Information:** Name, optional birth year, gender, timezone, location, preparedness level, family size, scenarios of interest, communication preferences
-   **Household Data (BeReady):** Family member details (names, ages or age ranges, relationship, special needs, mobility considerations, pets and service animals), **medical conditions, medications, disabilities, and other health-related details you choose to provide**, disaster scenarios selected, budget preferences. This information is used by our AI providers to generate personalized plans (see Section 5).
-   **Location Data (BeAware):** Residential and other monitored addresses, geocoded by Google to latitude/longitude coordinates with street-level precision. We may also store county, FIPS codes, and PostGIS geometry derived from your address for utility-territory matching and hazard overlays.
-   **Session Booking Data (BeAdvised):** Selected consultation topic, preferred date/time, intake questionnaire responses (questions, concerns, desired outcomes). Calendly processes scheduling on our behalf.
-   **Purchase Data (BeEquipped):** Product selections, quantities, variant choices, shipping address, billing address, order history
-   **Payment Information:** Processed by Stripe. We store the Stripe customer ID, subscription ID, invoice IDs, and transaction metadata; we do not store full card numbers or CVCs.
-   **Communication Data:** Messages you send us, support requests, feedback, survey responses
-   **User-Generated Content:** Plans you create, inventory you track, notes and customizations
-   **Acknowledgement Records:** When you accept in-product safety disclaimers (for BeReady plans, evacuation routes, BeAdvised sessions, and similar surfaces), we record the disclaimer version, time of acceptance, and IP address.

### 2.2 Information Collected Automatically

When you access our Service, we automatically collect certain information:

-   **Usage Data:** Pages viewed, features used, time spent, click patterns, navigation paths, in-product actions (login, plan generation, kit purchase, etc.)
-   **Device Information:** Browser type, operating system, device identifiers, screen resolution
-   **Analytics and Session Replay Data:** If you consent to analytics/marketing cookies, we load Microsoft Clarity (session replay, heatmaps), Google Ads conversion tracking, and any analytics scripts then in use. These tools record anonymized interaction data and may associate it with your hashed user ID after consent is granted. Sensitive fields are masked by default. We do not load any of these scripts before consent.
-   **Log Data:** IP address, access times, referring URLs, error logs, and request metadata. Application logs may be captured by our hosting provider (Render) and by background-task vendor (Trigger.dev).
-   **Cookies:** See our [Cookie Policy](https://staging.bepreparedsolutions.co/cookies) for detailed information

### 2.3 Information from Third Parties

We receive limited information from third parties acting on your behalf or ours, including: your basic profile (name, email, profile picture) from Google when you use Google Sign-In; payment and dispute status from Stripe; calendar event data from Calendly when you book a BeAdvised session; email delivery and bounce status from Resend.

A complete list of subprocessors with the purpose of each is set out in Section 12.

## [3\. Sensitive Categories of Personal Information](#sensitive-data)

📌 Key Points (Plain English)

The household questionnaire used for BeReady can include health information (medications, medical conditions, disabilities), precise location, and information about other household members including children. We treat these categories with extra care and process them only to deliver the Service. We do not use them for advertising and we do not sell them.

Because Be Prepared helps users plan for emergencies, the Service can collect categories of personal information that are treated as sensitive under U.S. state laws (including the CPRA in California) and as "special category" data under the EU/UK GDPR. You are never required to provide this information — you may use much of the Service without it — but providing it allows our AI to tailor plans to your household.

### 3.1 Categories

-   **Health-related information:** medications, medical conditions, disabilities, mobility considerations, and similar details you choose to enter for yourself or other household members. **Be Prepared is not a HIPAA-covered entity; do not provide information you consider medically privileged.**
-   **Precise geolocation:** latitude/longitude coordinates derived from monitored addresses
-   **Information about other household members, including children:** only as provided by an adult account holder who represents they have authority to share it for the purpose of household preparedness planning. See Section 13 for children-specific limits.
-   **Login credentials and security data:** hashed passwords, OTP codes, session tokens
-   **Financial / billing information:** Stripe customer IDs and transaction metadata (full card numbers are processed and stored by Stripe, not by Be Prepared)

### 3.2 How We Limit Use of Sensitive Data

-   Used only to provide the requested Service (e.g., AI plan generation, BeAware monitoring, BeEquipped fulfillment)
-   Not used to advertise to you and not used to infer additional sensitive characteristics
-   Not sold or shared for cross-context behavioral advertising
-   Not used to train AI models — our AI providers’ API terms prohibit training on API input data; see Section 5
-   You may request deletion of sensitive data without deleting your whole account by emailing the address in Section 16

### 3.3 CPRA Right to Limit Use of Sensitive Personal Information

California residents have the right under CPRA to limit our use of sensitive personal information to what is necessary to perform the Service. Because we already restrict our use of sensitive information to providing the Service (and do not use it for advertising, profiling for material decisions, or selling), we honor this limit by default. You may confirm or extend this limit at any time by contacting us at the address in Section 16.

## [4\. How We Use Your Information](#how-we-use)

📌 Key Points (Plain English)

We use your information to provide the Service (AI plan generation, outage monitoring, order processing, session scheduling), improve our Service, communicate with you, process payments, and comply with legal obligations. We do NOT use your information for advertising to third parties.

We use the information we collect for the following purposes:

### 4.1 Provide and Maintain the Service

-   Generate AI-powered emergency preparedness plans by sending your household and location data to AI language models
-   Create and manage your account
-   Process subscription payments and manage billing
-   Store your plans, inventory, and preferences
-   Monitor utility outages and emergency alerts for your registered addresses
-   Generate baseline location reports using federal data sources
-   Process BeEquipped orders and manage shipping
-   Schedule and facilitate BeAdvised consultation sessions
-   Send emergency alert notifications based on your monitored addresses
-   Provide customer support and respond to inquiries

### 4.2 Improve and Optimize the Service

-   Analyze usage patterns to understand how users interact with our Service
-   Develop new features and improve existing functionality
-   Fix bugs and optimize performance
-   Conduct research and testing to improve AI-generated content quality

### 4.3 Communication

-   Send transactional emails (account verification, password resets, subscription updates)
-   Send service announcements and important updates
-   Send newsletters and educational content (with your consent, you can opt out anytime)
-   Respond to your comments, questions, and support requests

### 4.4 Legal and Security

-   Comply with legal obligations and respond to legal requests
-   Enforce our Terms of Service and other agreements
-   Protect against fraud, unauthorized access, and security threats
-   Protect the rights, property, and safety of Be Prepared, our users, and the public

**Important:** We do NOT sell your personal information to third parties. We do NOT use your information for advertising purposes beyond our own Service.

## [5\. AI Data Processing](#ai-data-processing)

📌 Key Points (Plain English)

Be Prepared uses AI to generate preparedness plans, baseline reports, evacuation routes, and other content. We route requests through OpenRouter to large language models from Anthropic, OpenAI, and Google. The data sent includes your household details, addresses, and any medical conditions or medications you have entered. We rely on each provider's API terms, which prohibit training on API input data; we do not have direct control over their internal handling beyond that contractual commitment.

Be Prepared uses artificial intelligence to generate preparedness plans, baseline location reports, evacuation routes, image content, and other personalized output. This section explains what we send, where it goes, and what is and is not promised by the providers we use.

### 5.1 What Data Is Sent to AI Providers

We deliberately minimize what each AI call sees. The fields below are the ones that may be included in the prompt sent to an AI provider, depending on the feature you are using:

-   The monitored address you are generating a report for (street, city, state, ZIP, county, lat/lon)
-   Household composition (relationships, ages, gender, pets) and any health-related details you have chosen to enter (medical conditions, medications, special needs, mobility considerations, power-dependent devices)
-   The first names or nicknames you choose to give household members — see Section 5.2
-   Selected disaster scenarios, household budget preferences, and free-text notes you typed into BeReady forms
-   Reference data needed by the prompt (federal hazard layers, climate normals, environmental thresholds, etc.)
-   An opaque account identifier (a random UUID) used for log correlation

What we never send to AI providers

We do not include your **account email address**, your **last name**, your **date of birth or birth year**, your **phone number**, your **password or one-time codes**, or your **payment-card data** in any prompt sent to an AI provider. These fields stay inside our own systems (and with the specific subprocessors that need them, such as Stripe for payment or Resend for email).

### 5.2 First Names Are Pseudonymized Before They Reach AI Providers

The household editor still encourages you to enter **first names or nicknames only**for the people in your household. The name field is optional — generic labels such as "Spouse," "Child A," or "Grandma" work too.

When we generate your BeReady preparedness plan, we go a step further: before any LLM call, we replace each household member’s first name with an opaque identifier (`Member_1`, `Member_2`, and so on). The AI model produces its plan using those identifiers; we then substitute the real names back in **locally, on our servers, after the model has returned its response**. The plan you read shows the names you entered — but OpenRouter, Anthropic, OpenAI, and Google never receive your household members’ first names during plan-generation steps.

The same scheme covers free-text fields where a real name might accidentally appear (for example, if you typed "Brian’s insulin" into a medication field): we scrub the known household names from those fields before the LLM call, and re-insert them on the way back. We never combine first names with email, last name, or date of birth on the same call.

One honest exception: the editorial polish step

After the plan is drafted, we run a final editorial pass that polishes voice and checks that each household member is referenced consistently across tabs. That step needs the real names to do its job — placeholders break consistency checks. So the editor stage **does** receive the rehydrated plan (with real first names) once. Every step before it — plan outlining, plan drafting, article-voice copy — sees only placeholders. The editor sees real names; no other LLM call does. We may close this gap in a future update if we can verify the editor can preserve voice without them.

A separate limitation: if you provided an out-of-state emergency contact, that person’s name (a different individual from your household) is sent to the LLM that drafts your family’s "Who Does What When" communication grid. Our pseudonymization map covers your household members; we’re evaluating extending it to out-of-state contact names in a future update.

### 5.3 Per-Feature Data Composition

Different features of the Service make different LLM calls. Some calls receive only your address, some receive only household details, some combine both, and BeReady plan generation is now split across several smaller calls each scoped to the minimum data it needs. The current state is:

| Feature / LLM Call | Address? | Household identity + health info? |
| --- | --- | --- |
| **BeReady plan — Outline stage (3 parallel calls + 1 synthesis call)** | Yes | Pseudonymized first names (`Member_N`) + health info; full health detail only for the Profile and Kit sub-calls, not the Phases sub-call |
| **BeReady plan — Drafting stage (3 parallel calls)** | Yes | Pseudonymized first names + health info; same scoping as the outline stage |
| **BeReady plan — Article voice copy** | City and state only | Pseudonymized first names only (no health info) |
| **BeReady plan — Editorial polish (3 parallel calls)** | Yes | **Real first names** + health info — see 5.2 for why this one step is the exception |
| **BeAware baseline location report** (summarizer + synthesis calls) | Yes | **Yes** — combined so the report can flag special-needs considerations for your location |
| **Emergency contacts lookup** | Yes | No |
| **Evacuation route generation** | Yes (start address) | No |
| **Image generation** (article and kit imagery) | No | No |

BeReady plan generation used to be a single large LLM call that received your full address and full household identity together. As of May 2026 we split it into the steps shown above, with first names pseudonymized before every call except the final editorial polish (see 5.2). Each sub-call also receives only the fields it needs — for example, the Phases sub-call sees city and state rather than your precise address, and does not receive your full medical free-text. BeAware baseline reports still combine address and household details in one call because the report’s value is naming local hazards in the context of specific household considerations; we are evaluating the same kind of split for that feature.

### 5.4 Providers and Routing

AI requests are sent through **OpenRouter**, which routes them to one of several underlying model providers. Active providers currently include:

-   **Anthropic** (Claude family of models)
-   **OpenAI** (GPT family, including for image generation)
-   **Google** (Gemini family)

The exact provider and model for a given feature may change at any time as we improve quality, add new features, or respond to availability. The current routing for a feature can be viewed by contacting us. Each provider has its own privacy policy, retention practices, and processing locations (generally the United States).

### 5.5 No Training on Your Inputs

OpenRouter, Anthropic, OpenAI, and Google each publish API terms or enterprise terms stating that data submitted via their APIs is not used to train their general-purpose models. We rely on those terms. We do not have direct visibility into the internal handling, logging windows, or abuse-monitoring processes of each provider; please review their public policies for those details:

-   [OpenRouter Privacy Policy](https://openrouter.ai/privacy)
-   [Anthropic Privacy Policy](https://www.anthropic.com/legal/privacy)
-   [OpenAI Privacy Policy](https://openai.com/policies/privacy-policy)
-   [Google Privacy Policy](https://policies.google.com/privacy)

### 5.6 Trigger.dev and Background Processing

AI plan generation runs as a background task on **Trigger.dev**. The task payload (which includes the same data described in Section 5.1) is logged in the Trigger.dev dashboard for debugging and retry purposes and is subject to Trigger.dev’s retention practices.

### 5.7 Your Choices

-   You can omit optional household, medical, or medication fields and still use BeReady; plans will be more generic.
-   You can ask us to delete previously generated plans or the household data used to produce them by contacting the address in Section 16.
-   If you are an EU/UK or California resident, your withdrawal of consent, deletion, or limit-of-use rights described in Sections 3, 7, and 8 also apply to AI processing.

⚠️ AI Content Disclaimer

AI-generated content may contain inaccuracies, hallucinations, or guidance that conflicts with official emergency instructions. Please refer to our Terms of Service for the full disclaimer regarding AI-generated content. You should always verify critical information with authoritative sources, and in any emergency call 911 (or your local emergency number) and follow official instructions.

## [6\. Google Sign-In and Google User Data](#google-signin)

📌 Key Points (Plain English)

Be Prepared offers Google Sign-In as an optional authentication method. If you choose to sign in with Google, we receive your name, email address, Google account ID, and profile picture. We use this information solely to create and authenticate your Be Prepared account. We comply with the Google API Services User Data Policy, including the Limited Use requirements.

Be Prepared offers Google Sign-In as an optional way to create and access your account. Using Google Sign-In is entirely voluntary; you may also sign in with an email address and one-time password.

### What Google User Data We Access

When you choose to sign in with Google, we request the following basic profile information from your Google account via the standard OAuth scopes (`openid`, `email`, `profile`):

-   **Email address** — used as your account identifier and for transactional communications
-   **Full name** — used to personalize your account and communications
-   **Google account ID (sub)** — an opaque identifier used to link your Google identity to your Be Prepared account
-   **Profile picture URL** — displayed in the app as your avatar

We do **not** request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google service or Restricted Scope.

### How We Use Google User Data

-   Creating and authenticating your Be Prepared account
-   Displaying your name and avatar within the Service
-   Sending you transactional emails related to your account and the Service

We do **not** use Google user data for advertising, we do **not** sell or share it with third parties for their own purposes, and we do **not** use it to train artificial intelligence or machine learning models.

### How We Store and Protect Google User Data

Google user data is stored alongside other account data in our Supabase-hosted PostgreSQL database, encrypted in transit (HTTPS/TLS) and at rest. Access is restricted to authorized personnel and subject to the security measures described in Section 10.

### How to Revoke Access and Delete Google User Data

You can disconnect Google Sign-In from your Be Prepared account at any time by:

-   Revoking Be Prepared’s access from your Google Account at [Google Account third-party access settings](https://myaccount.google.com/permissions)
-   Deleting your Be Prepared account from your account settings, which removes all associated Google profile data within 30 days
-   Emailing [privacy@bepreparedsolutions.co](mailto:privacy@bepreparedsolutions.co) to request deletion of Google user data associated with your account

Google API Services User Data Policy — Limited Use

Be Prepared’s use and transfer of information received from Google APIs to any other app will adhere to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

## [7\. Your Privacy Rights (GDPR)](#gdpr-rights)

📌 Key Points (Plain English)

EU users have specific rights under GDPR: access your data, correct errors, request deletion, export your data, restrict processing, object to processing, and withdraw consent. Submit requests by email to privacy \[at\] bepreparedsolutions.co. We respond within 30 days.

If you are a resident of the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR):

### Your Rights Include:

-   **Right to Access:** You can request a copy of the personal data we hold about you
-   **Right to Rectification:** You can correct inaccurate or incomplete personal data
-   **Right to Erasure ("Right to be Forgotten"):** You can request deletion of your personal data
-   **Right to Data Portability:** You can receive your personal data in a structured, machine-readable format and transfer it to another service
-   **Right to Restrict Processing:** You can request that we limit how we use your data
-   **Right to Object:** You can object to our processing of your personal data for certain purposes
-   **Right to Withdraw Consent:** Where processing is based on consent, you can withdraw consent at any time without affecting the lawfulness of processing before withdrawal
-   **Right to Lodge a Complaint:** You can file a complaint with your local data protection authority

### How to Exercise Your Rights:

To exercise any of these rights, please contact us at [privacy@bepreparedsolutions.co](mailto:privacy@bepreparedsolutions.co). You can also download a copy of your data at any time from your profile ("Export My Data"). We will respond to your request within 30 days.

**Identity Verification:** To protect your privacy, we may require identity verification before fulfilling data requests. We may ask for additional information to confirm your identity.

**Limitations:** Some requests may be limited by legal obligations. For example, we may retain certain information as required by law or for legitimate business purposes (such as completing transactions or resolving disputes).

## [8\. California Privacy Rights (CCPA/CPRA)](#ccpa-rights)

📌 Key Points (Plain English)

California residents have rights under CCPA/CPRA: right to know, delete, opt-out, non-discrimination, and correction. We do NOT sell your personal information. Contact privacy \[at\] bepreparedsolutions.co to exercise your rights. We respond within 45 days.

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

### Your California Privacy Rights:

-   **Right to Know:** You have the right to know what personal information we collect, use, and disclose about you
-   **Right to Delete:** You can request deletion of your personal information
-   **Right to Opt-Out:** You can opt out of the "sale" or "sharing" of personal information. Note: we do NOT sell your personal information
-   **Right to Non-Discrimination:** We will not discriminate against you for exercising your privacy rights
-   **Right to Correct:** You can request correction of inaccurate personal information

To exercise these rights, contact us at [privacy@bepreparedsolutions.co](mailto:privacy@bepreparedsolutions.co). We will respond within 45 days as required by law.

ℹ️ We Do Not Sell Personal Information

Be Prepared does not sell, rent, or share your personal information with third parties for their own marketing purposes. We have not sold personal information in the preceding 12 months.

## [9\. Cookies and Tracking](#cookies)

📌 Key Points (Plain English)

We use essential cookies (authentication, session management) and optional analytics cookies (Google Analytics). You can manage cookie preferences through our cookie consent banner. See our Cookie Policy for full details.

We use cookies and similar tracking technologies to collect and store information. For detailed information about the cookies we use and your choices, please see our [Cookie Policy](https://staging.bepreparedsolutions.co/cookies).

### Types of Cookies and Tracking Scripts:

-   **Essential Cookies:** Required for authentication and core functionality (cannot be disabled without affecting the Service)
-   **Analytics:** Help us understand how users interact with the Service. Includes **Microsoft Clarity** (session replay and heatmaps, sensitive fields masked by default) and Google Analytics if enabled. **These scripts are not loaded until you grant analytics or marketing consent.**
-   **Marketing:** Google Ads conversion tracking, used to measure advertising effectiveness. Loaded only after marketing consent is granted. If you are logged in and have granted consent, we may send your hashed user ID to attribute conversions to campaigns.

### Photos Loaded from News Publishers:

Some Alert Pulse reports show a news photo at the top of a story. We do not host or store these photos: your browser loads each one directly from the publisher's website or the image service it uses, and the caption links to the page the photo came from. As with any image loaded from another website, that server receives your IP address and browser details when the photo loads, and it may set its own cookies under its own privacy policy. This happens whether or not you accept cookies on our site, because the photo is part of the page rather than tracking we add. We send no referrer, so the publisher is not told which of our pages you were reading. Photos we are free to reuse, such as public-domain images, are served from our own storage instead.

### Managing Cookies:

You can manage your cookie preferences through:

-   **Cookie Consent Banner:** Accept or decline non-essential cookies when you first visit our Service
-   **Browser Settings:** Most browsers allow you to refuse or delete cookies
-   **Cookie Policy Page:** Visit our [Cookie Policy](https://staging.bepreparedsolutions.co/cookies) for instructions on clearing consent and updating preferences

**Note:** Disabling certain cookies may limit some features of the Service.

## [10\. Data Security and Retention](#data-security)

📌 Key Points (Plain English)

We use industry-standard security measures (encryption in transit and at rest, secure servers, access controls) to protect your data. Some sensitive plan records are also encrypted at the application layer; monitored addresses are not. We retain different categories of data for specific periods.

### Security Measures:

We implement appropriate technical and organizational measures to protect your personal data:

-   **Encryption:** Data encrypted in transit (HTTPS/TLS) and at rest in databases
-   **Application-Layer Encryption:** Certain sensitive records, such as your plan questions and plan customizations, are additionally encrypted at the application layer. Monitored addresses are not encrypted at the application layer, because they must be matched against alert areas; they are protected by encryption at rest and access controls.
-   **Secure Authentication:** Industry-standard authentication via Supabase Auth
-   **Access Controls:** Strict access controls limiting who can access user data
-   **Regular Security Audits:** Ongoing security assessments and updates
-   **PCI-DSS Compliance:** Payment data processed by PCI-DSS compliant providers (Stripe)
-   **Secure Infrastructure:** Hosted on secure, SOC 2 compliant infrastructure

### Data Retention:

We retain your personal data according to the following schedule:

| Data Category | Retention Window | Notes |
| --- | --- | --- |
| User account & profile | Active account; deleted within 30 days of account deletion | Some fields may be retained longer if required by law |
| Household data (BeReady) | Until you delete it or your account | Soft-deleted plans recoverable for 30 days |
| Preparedness plans | Until you delete them | Soft-delete, recoverable for 30 days |
| Addresses & geocoded coordinates | Until removed or 30 days after account deletion | Encrypted at rest in the database; not encrypted at the application layer |
| BeAware baseline location reports | Auto-expire after 1 year | Cached up to 30 days for re-use |
| Utility outage events | 30 days after resolution | Pseudonymized for product analytics |
| FEMA IPAWS alerts | Until alert expiry + 7 days | Government source data |
| BeAdvised bookings | 3 years from session date | For service-history and dispute purposes |
| Order & payment records | 7 years | Required by tax / financial recordkeeping; pseudonymized after account deletion where possible |
| User activity log (analytics) | 24 months | IP address rotated/truncated where feasible |
| System / error logs | 12 months | Used for security, fraud prevention, debugging |
| Trigger.dev background-task logs | Per Trigger.dev policy (typically 30 days) | Includes AI prompt payloads |
| Render hosting logs | Per Render policy (typically 30 days) | May include IP and request metadata |
| Microsoft Clarity recordings | Per Microsoft policy (typically 13 months) | Loaded only after analytics/marketing consent |
| Disclaimer-acceptance records | 7 years | Used to evidence acknowledgement of safety notices; retained longer than the underlying plan |
| Marketing-email opt-in / opt-out | 3 years after opt-out | To honor opt-out across re-registration |

**Account Deletion:** When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as fraud prevention or financial record-keeping). Order and transaction records are pseudonymized and retained as required by tax law.

⚠️ Security Disclaimer

While we strive to protect your personal data using industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. You use the Service at your own risk.

## [11\. Sharing Your Information](#data-sharing)

📌 Key Points (Plain English)

We share your information only with trusted service providers necessary to operate the Service, when required by law, or with your explicit consent. We do NOT sell your data to third parties.

We share your personal information only in the following circumstances:

### 11.1 Service Providers

We share information with third-party service providers who perform services on our behalf. The complete current list, with the purpose of each, is in Section 12 (Subprocessor List). Each provider is contractually obligated to protect your information and use it only for the purposes we specify.

ℹ️ User ID Tracking for Marketing Attribution

If you are logged in and have granted marketing cookie consent, we send your anonymized user ID to Google Ads. This allows us to measure which marketing campaigns lead to signups and conversions. Your user ID is a random alphanumeric string that does not contain any personally identifiable information. You can withdraw consent at any time by updating your cookie preferences, which will immediately stop user ID tracking.

### 11.2 Legal Requirements

We may disclose your information if required to do so by law or in response to:

-   Valid legal requests (subpoenas, court orders, government inquiries)
-   Enforcement of our Terms of Service or other agreements
-   Protection of the rights, property, or safety of Be Prepared, our users, or the public
-   Investigation of fraud, security issues, or other illegal activities

### 11.3 Business Transfers

If Be Prepared is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service before your information is transferred and becomes subject to a different privacy policy.

### 11.4 With Your Consent

We may share your information for other purposes with your explicit consent or at your direction.

🔒 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. Your data is used solely to provide and improve our Service.

## [12\. Subprocessor List](#subprocessors)

📌 Key Points (Plain English)

A current list of service providers (subprocessors) that may receive your personal information to help us run the Service, with the purpose of each. We update this list as our stack changes.

We use the following service providers (subprocessors) to operate the Service. Each receives only the personal information needed for the stated purpose and is bound by a written agreement requiring appropriate security and confidentiality.

| Provider | Purpose | Categories Shared | Location |
| --- | --- | --- | --- |
| Supabase, Inc. | Authentication, PostgreSQL hosting | Account, profile, household, plans, addresses | USA |
| Render | Web and worker hosting, runtime logs | Request metadata, IP, error logs | USA (Oregon) |
| Stripe, Inc. | Payment processing, subscription billing | Name, email, billing address, payment instrument | USA + global |
| OpenRouter | Routes AI requests to model providers | Prompt payload (see Section 5) | USA |
| Anthropic, PBC | Claude LLM for plans, reports, chat | Prompt payload | USA |
| OpenAI | GPT LLM (text + image generation) | Prompt payload | USA |
| Google LLC (Gemini API) | Gemini LLM | Prompt payload | USA + global |
| Google LLC (Maps Platform) | Address autocomplete, geocoding, Places, Routes | Addresses, coordinates | USA + global |
| Google Ads | Marketing measurement (consent-gated) | Hashed user ID, conversion events | USA + global |
| Microsoft (Clarity) | Session replay, heatmaps (consent-gated) | Interaction recordings, hashed user ID | USA + global |
| Trigger.dev | Background-task orchestration, retries | Task payloads (incl. AI prompt data) | USA |
| Resend | Transactional and marketing email delivery | Email address, message content | USA |
| Calendly | BeAdvised session scheduling | Name, email, scheduling answers | USA + global |
| Firecrawl | Web research / scraping for content workflows | No user PII; outbound only | USA |
| SerpAPI | Search-engine results for research workflows | No user PII; outbound only | USA |
| Decodo (proxy) | Outbound proxy for selected scrapers | No user PII; outbound only | Global |
| WeatherAPI | Weather data for monitored locations | Coordinates only | USA + global |
| AirNow (US EPA) | Air-quality data | Coordinates only | USA |
| FEMA IPAWS, USGS, NOAA, NWS, USFS, HIFLD, NFIP | Government data sources for hazard analysis and alerts | Coordinates only; public APIs | USA |

This list may change as our infrastructure evolves. Material changes will be reflected in the "Last Updated" date and, where required by law, communicated to you directly.

## [13\. Children's Privacy](#childrens-privacy)

📌 Key Points (Plain English)

Our Service is intended for adults. Account holders must be 18 or older. Adult account holders may include information about other household members, including children, solely for household preparedness planning. We do not knowingly let children under 13 create accounts (COPPA), do not allow users under 18 to create accounts at all, and never use information about children for advertising or for AI model training.

### 13.1 Adult-Only Accounts

Be Prepared accounts are intended for individuals aged 18 and over. Our Terms of Service require users to be at least 18 years old to create an account. We do not knowingly let individuals under 18 register, and we do not knowingly direct marketing to people under 18.

### 13.2 Information About Household Members

BeReady plans can be more useful when they reflect your full household, which often includes minors. An adult account holder may choose to enter limited information about a child — such as first name, age, special needs, and medical considerations — for the sole purpose of household preparedness planning. By providing this information you represent that you are the parent or legal guardian of the child (or otherwise have authority to share it) and that you consent on the child's behalf to its processing for that purpose.

We treat information about minors in the household as sensitive personal information (Section 3): used only to deliver the Service to you, never used for advertising, never used to train AI models, and never sold or shared for cross-context behavioral advertising.

### 13.3 COPPA

We do not knowingly collect personal information directly from children under 13 in the United States in a manner that requires verifiable parental consent under the Children's Online Privacy Protection Act (COPPA). Information about a child entered by an adult account holder is collected from the adult, not from the child. If you are a parent or guardian and believe a child under 13 has interacted with the Service in a way that collected personal information directly from them, contact us at [privacy@bepreparedsolutions.co](mailto:privacy@bepreparedsolutions.co) and we will promptly delete it.

### 13.4 Deleting Information About a Child

At any time, an adult account holder may remove information about a child from their household profile through the in-product editor or by contacting us at the address in Section 16.

## [14\. International Data Transfers](#international-transfers)

📌 Key Points (Plain English)

Be Prepared is a U.S. business. Your information is stored and processed primarily in the United States. For users in the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms with our subprocessors.

Be Prepared, Inc. is incorporated in the State of Delaware and operates in New Jersey, United States. Your information is stored and processed primarily on infrastructure located in the United States, and is also accessible from any country where our subprocessors operate (see Section 12).

### 14.1 Transfers from the EEA, UK, and Switzerland

When personal information is transferred from the European Economic Area, United Kingdom, or Switzerland to a country that has not received an adequacy decision from the European Commission or relevant supervisory authority, we rely on one or more of the following safeguards:

-   The European Commission’s **Standard Contractual Clauses (SCCs)**, incorporated by reference into our agreements with subprocessors that need them
-   The **UK International Data Transfer Addendum** to the SCCs, where applicable
-   The **EU–US Data Privacy Framework** (and UK/Swiss extensions) for participating subprocessors
-   Supplemental measures, including encryption in transit and at rest and access controls, where appropriate

You may request a copy of the safeguards applicable to a specific transfer by emailing the address in Section 16.

### 14.2 Acknowledgement

If you access the Service from outside the United States, you understand that data protection laws in the destination jurisdiction (the United States and others) may differ from those of your country of residence. By using the Service, you agree to the international transfer of your information as described above.

## [15\. Changes to This Privacy Policy](#changes)

📌 Key Points (Plain English)

We may update this Privacy Policy periodically. We will notify you of significant changes via email or prominent notice on our Service. Continued use after changes indicates acceptance.

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last Updated" date at the top of this Privacy Policy.

We will notify you of any material changes by:

-   Sending an email to the address associated with your account
-   Posting a prominent notice on our Service
-   Requiring you to accept the updated Privacy Policy before continuing to use the Service (for significant changes)

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree to the updated Privacy Policy, you should stop using the Service and may delete your account.

## [16\. Contact Us](#contact)

📌 Key Points (Plain English)

For privacy questions or to exercise your rights, contact us at privacy \[at\] bepreparedsolutions.co. You can also export your data from your profile at any time. We respond within 30 days (45 days for CCPA requests).

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Be Prepared, Inc.

**Privacy Inquiries:** [privacy@bepreparedsolutions.co](mailto:privacy@bepreparedsolutions.co)

**Export Your Data:** Available any time from your profile ("Export My Data")

We will respond to your inquiry within 30 days. For GDPR requests, we will respond within 30 days as required by law. For CCPA/CPRA requests, we will respond within 45 days as required by law.

[Privacy Policy](https://staging.bepreparedsolutions.co/privacy)|[Terms of Service](https://staging.bepreparedsolutions.co/terms)|[Cookie Policy](https://staging.bepreparedsolutions.co/cookies)|[Back to Home](https://staging.bepreparedsolutions.co/)

---

_Guidance here is general and cannot account for your circumstances. In an active emergency, official instructions from local authorities take precedence over anything published by BePrepared Solutions._
