Corex SMS

Privacy Policy

Last updated August 5, 2026

This is a template, not a finished legal document. It describes how the CoreX SMS software actually handles data as of this writing, but it has not been reviewed by a lawyer and doesn't yet name a real legal entity, jurisdiction, or contact address. Replace the bracketed placeholders and have counsel review this before relying on it as your organization's binding policy.

1. Who this policy covers

CoreX SMS is safety management software that [Company Legal Name] licenses to individual aviation operators ("Organizations"). Each Organization is a separate, isolated tenant: your data is never visible to another Organization's users.

For most of the personal data described below, your Organization is the data controller — they decide who gets an account, what roles they hold, and how long records are kept beyond any regulatory minimum. [Company Legal Name] acts as a data processor, operating the software on the Organization's behalf. If you have a question about how your specific employer uses your data, your Organization's safety manager or admin is the right first contact.

2. What we collect

  • Account & profile data — name, email, phone, date of birth, job position, mailing address, and up to two emergency contacts (their name, phone or email, and address), if your Organization's admin or you choose to fill them in. These are collected to help pre-fill external regulatory report forms (such as ASAP or ASRS submissions) that ask for this information. Emergency contact details are personal data about someone else that you're providing on their behalf — only share them if you're comfortable doing so.
  • Safety records — the content of safety reports, hazard entries, audits, and any free-text descriptions you or others enter, including names of people mentioned in report narratives.
  • Activity data — bulletin acknowledgements, report participation, and sign-in timestamps, used to track compliance obligations like "has this bulletin been read."
  • AI feature usage — if your Organization has enabled an AI-assisted feature (for example, the AI-assisted investigation support available today, or any AI-assisted feature we add later), the content sent to it and the response received are logged against your account for cost and audit purposes.
  • Files you upload — attachments on reports and bulletin images.

3. Why we process it

To operate the safety reporting, hazard tracking, audit, and safety-performance features your Organization has licensed; to meet the safety record-keeping obligations aviation regulators impose on your Organization (for example, ICAO Annex 19-aligned SMS documentation requirements); and, where you've given it, to send account-related notifications like report reminders.

4. How long we keep it

Safety reports, hazard records, and their audit trails are retained as long as your Organization's applicable safety record-keeping regulations require, even if the person who filed them later leaves or asks to have their personal data erased — the underlying safety record stays, but see Section 5 for what erasure does to your personal identity within it.

5. Your rights: export and erasure

You can download a copy of the personal data tied to your account at any time from My Profile. You can also request your account be erased there, or ask your Organization's admin to do it on your behalf.

Erasure removes your name, phone number, date of birth, and job title from your profile, and permanently locks the account, but it does not delete safety reports, hazards, or audits you filed — those remain as anonymized compliance records ("Deleted User") for the reasons in Section 4. Free-text content you wrote inside a report (which may reference your own name) is not automatically redacted, since it may be part of a retained safety record; contact your Organization's admin if you need help with that.

6. Who else sees it (sub-processors)

  • Supabase — hosts the application database, authentication, and file storage.
  • Anthropic — processes content only when your Organization has explicitly enabled an AI-assisted feature, and only for the record you ask it to help with.

We don't sell personal data, to these providers or anyone else.

7. Security

Access to your Organization's data is isolated from every other Organization on the platform, and restricted within your Organization by role (reporter, safety manager, admin, audit manager). Files and signed download links expire after a few minutes rather than being permanently public.

8. Changes to this policy

If this policy changes materially, we'll update the "Last updated" date above. [Describe how your Organization will notify users of material changes — e.g. a system message banner, email, etc.]

9. Contact

Questions about this policy, or a data request that isn't covered by the self-service export/erase tools above, can be sent to [privacy contact email].