OSHA Research Assistant — Privacy Notice
This notice explains what the OSHA Research Assistant at dailysafetymoment.com/chat (the "Service") collects, how it is used, and who processes it. The Service is operated by RMZ Media, in Texas, United States ("we," "us"). It supplements the general website Privacy Policy; for the Service, this notice controls. It forms part of the Terms of Use.
1. What we collect
| Data | Details |
|---|---|
| Account | Email address; a salted hash of your password (never the password itself), or your Google account identifier if you use Google Sign-In; verification and password-reset tokens (stored hashed); account creation time. |
| Email choices | Whether you opted in to the Daily Safety Moment newsletter and to product updates about the Service (both optional and off unless you turn them on), and a record of each choice: what you chose, when, on which screen, and a one-way hash of your IP address. |
| Terms acceptance record | For everyone who uses the Service, including visitors who are not signed in: the version of the Terms accepted, the date and time, a one-way hash of the IP address, the browser's user-agent string, and a tamper-evident signature. Visitors who are not signed in are recognised by a random identifier kept in a cookie. |
| Conversations | The questions you ask, the answers generated, and the regulation paragraphs each answer cited, saved to your account so you can return to them. |
| Usage and billing status | How many questions you have used in the current period; your plan, subscription status, renewal or end date, and the subscription-management link issued by our payment provider. We never receive or store your card number. |
| Security data | A session cookie; short-lived rate-limit counters keyed to a one-way hash of your IP address; standard web-server logs (IP address, time, URL, browser) kept by our hosting provider. |
| On your device | Interface preferences (panel width, toggles) in your browser's local storage. These never leave your device. |
The Service itself sets no advertising or analytics cookies. The only cookies are the session cookie that keeps you signed in and a terms-acceptance cookie that remembers that you accepted the Terms. Please do not put confidential, privileged, health, or other people's personal information into your questions.
2. How we use it
To provide the Service (answer questions, save and show your conversations, enforce plan limits); to authenticate you and secure accounts; to process subscriptions; to send transactional email (verification, password reset, service and legal notices); to prevent abuse; to debug and improve the Service; and to comply with law and enforce our Terms. We do not sell your personal information, and we do not use your conversations for advertising. We do not use your conversations to train AI models.
3. Who processes it for us
| Provider | Purpose | What they receive |
|---|---|---|
| OpenRouter, and the AI model and embedding providers it routes to | Finding relevant paragraphs and drafting and reviewing answers | Your question, up to six earlier turns of the same conversation, and excerpts of public regulation text. Requests are sent with zero-data-retention routing and a deny-data-collection setting, so that routed providers are not permitted to retain prompts or use them for training. We do not send your email address or account identifier. We cannot independently audit third parties' compliance. |
| Lemon Squeezy (merchant of record) | Checkout, payment, tax, invoices, subscription management | Your email, an internal account number, and what you enter at checkout. Their processing is governed by their own privacy policy. |
| Optional Google Sign-In | If you choose it, Google confirms your identity to us (email and a Google account identifier). We request only the "openid" and "email" scopes. | |
| Resend | Email delivery: account messages, and the newsletter or product updates only if you opted in | Your email address and the message content (for example, a verification link). If you opted in, your address is added to the matching mailing list once it is verified; Resend records delivery, opens and link clicks for those emails. |
| Namecheap (web hosting) | Servers, database storage, backups, server logs | All data stored by the Service resides on our hosted account in the United States. |
We may also disclose information if required by law, subpoena or court order; to protect the rights, safety or property of any person; to investigate fraud or abuse; or in connection with a merger, sale or transfer of the business, in which case this notice will continue to apply to transferred data until replaced.
4. Retention
Conversations are kept until you delete them or your account is deleted. Account records are kept while your account is open. Database backups, stored in a private directory on our hosting account, are kept for about 30 days and then overwritten, so deleted data may persist in backups for up to that period. Rate-limit counters expire within a day. Billing records are retained by the merchant of record as required by tax and accounting law. We may retain records of Terms acceptance and information needed to resolve disputes or enforce our agreements for as long as reasonably necessary.
5. Your choices
See and export: Settings → Data controls → Export downloads all of your conversations. Delete conversations: delete one from the sidebar, or all of them in Settings → Data controls. Delete your account, or access or correct your data: email admin@dailysafetymoment.com from your account email and we will respond within 30 days. Email: the newsletter and product updates are opt-in. Turn either on or off in Settings → Account, or use the unsubscribe link in any such email; leaving a box unticked never changes a subscription you already have. Account messages (verification, password reset, notices about your account) are sent regardless. Subscription: manage or cancel through the link in Settings → Plans & billing. Depending on where you live, you may have additional rights under local law (such as the Texas Data Privacy and Security Act or similar state laws); we honor valid requests regardless of whether those laws technically apply to a business of our size. We will not discriminate against you for exercising any right.
6. Security
We use industry-standard measures: passwords are stored only as salted hashes; sessions use secure, HTTP-only cookies; forms are protected against cross-site request forgery; a strict content-security policy is enforced; secrets and the database are stored outside the public web directory; access to conversations is checked against the signed-in account on every request. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential.
7. Children
The Service is for adults (18+) using it for work. We do not knowingly collect personal information from children under 13 — or under 18 — and will delete such information if we learn of it.
8. Location
The Service is operated from, and data is stored in, the United States, and is intended for users in the United States. If you use it from elsewhere, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country.
9. Changes
We may update this notice. When we make a material change we will update the version date and, where the change affects how we handle your data, ask you to review it when you next use the Service.
10. Contact
RMZ Media, Texas, United States · admin@dailysafetymoment.com · Contact form