Privacy Policy
Privacy Policy
Effective 2026-07-21
Mobilize is a fire-mobilization tool operated by StationWorks for fire-service agencies and the regional coordinating bodies they answer to. This policy explains what we collect, why, and how it's handled. Mobilize is invite-only; we don't run consumer sign-ups and we don't show ads.
What we collect
Some of this information you enter in the app. Some is linked from systems your agency already uses — its Microsoft 365 or Google directory, a certification registry, or an existing regional roster — including for personnel who have not signed in to the Service. Your agency controls those sources. Much of what we hold exists to produce the records agencies need — most of all the Mission Acceptance forms and manifests submitted to state and federal partners for resource tracking and reimbursement.
- Account & identity: name, work email, agency, role/scope, sign-in identifiers and profile photo from Microsoft or Google when used, directory details drawn from your agency's systems (such as an employee ID, department, or group membership), display-timezone preference, and your mobile phone number — entered by you during SMS setup or provided by your agency — along with your SMS opt-in consent when you give it.
- Mobilization records: apparatus, personnel records (including date of birth and personnel or certification photos where your agency records them), certifications, availability, rotation entries, page notifications and replies (including the text of replies you send back), mission acceptances, and signatures captured in the app. Records generated to support a mobilization may include the additional details the relevant forms require — for example crew contact and mailing-address information and an agency tax identifier on a Mission Acceptance form.
- Audit log: a hash-chained, append-only record of meaningful actions (sign-ins, refusals, status changes, document generation), including IP address and user agent for authentication events. Because one purpose of the log is to let agency administrators see who attempted access and was turned away, a refused sign-in records the email address that was used — including for people who are not, and may never become, users of the Service.
- Operational telemetry: error reports, request logs, and product-usage telemetry used to keep the Service running and improve it. Personally identifiable fields are tagged at the schema level and our systems are designed to redact them before they reach external error-tracking and analytics tools.
How we use it
- To run the Service: authenticate you, route pages, generate manifests and PDFs.
- To produce records the agencies need: rotation history, mobilization acceptance, after-action review, reimbursement support.
- To investigate security incidents and unauthorized-access attempts.
- To diagnose errors and improve reliability.
We do not sell personal information, and we do not use Service data to train third-party AI models.
Automated processing and AI
Two features use an AI model to cut manual work. When you upload an apparatus photo, a model reads details such as the odometer or plate to pre-fill a form. When a text-message reply to a page is ambiguous, a model proposes how to read it; a high-confidence reading may be applied automatically to set availability, and a coordinator can review and correct it. These features run on Amazon Bedrock inside our own AWS account — the content is not sent to a third-party AI service, is not used to train models, and is not shared with model providers.
Text messaging (SMS) and email
If you opt in to SMS during onboarding, we record your opt-in consent in our append-only audit log and use your mobile phone number solely to send the operational messages described in the Terms of Service — mobilization requests, Ready/Set/Go pages, availability requests, and status updates. Message frequency varies; message and data rates may apply. Reply STOP at any time to opt out (effective immediately), START to resume, or HELP for help.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent will not be shared with any third parties, excluding our SMS delivery provider (Twilio), which processes it on our behalf solely to deliver the messages you opted in to receive.
We may also deliver these same operational messages to your work email address. Email notifications carry the same mobilization, Ready/Set/Go, availability, and status content — never marketing.
Sub-processors
We use a small set of service providers to operate the Service: cloud hosting, database, document storage, email delivery, and in-account AI processing on Amazon Web Services (including Amazon Bedrock) in the United States; SMS delivery (Twilio); optional federated sign-in and directory sync (Microsoft or Google, when your agency uses them); and error-tracking and product-analytics tooling (Sentry and PostHog). DNS is provided separately. A current list of sub-processors is available on request.
Some error-tracking and analytics functions run in your browser and connect to those providers directly, so they receive standard connection information, including your IP address. Our systems are designed to redact personally identifiable fields from the telemetry payload before it is sent; the network connection itself is not something that payload redaction can remove.
We don't share Service data with third parties except as needed to operate the Service, to comply with law, or as directed by your operating agency.
Public records
Mobilize is used by public agencies. Records held in the Service on behalf of an agency may
be subject to disclosure under applicable public-records or freedom-of-information laws —
for example, Washington's Public Records Act (RCW 42.56) for agencies in Washington, with
analogous statutes in other states. Each field carries a disclosure-class tag
(public, exempt-pii, exempt-other) used when
generating disclosure bundles. The operating agency is the records custodian and makes
disclosure decisions; we provide the tooling.
Retention
Each record carries a retention class — ranging from one year to permanent — chosen to align with the retention schedule that applies to the operating agency's records, initially modeled on Washington state fire-service retention schedules and adjusted as Mobilize is used in other jurisdictions. Personnel and apparatus records are soft-deleted (deactivated) rather than removed, so prior audit entries and generated documents stay interpretable.
The audit log is append-only at the database level, and sealed portions of it are also copied to write-once storage that cannot be altered or deleted by anyone — including us — for the length of its retention period. This is deliberate: it is what lets the record be trusted for reimbursement, after-action review, and public-records purposes. One consequence is that audit-log entries cannot be edited or erased on request while that retention period runs.
Security
- Encrypted in transit; databases and document storage are encrypted at rest.
- Server-side opaque session tokens delivered as HttpOnly + Secure + SameSite cookies. We don't store passwords.
- Multi-tenant scoping enforced on every query; users can only see data for their authorized agency or region.
- Auth surface protected by layered rate limiting. Every sign-in attempt — successful, refused, or failed — is audited.
- Sensitive fields carry per-field disclosure tags that drive redaction and public-records handling.
All Service data is stored in the United States. If we become aware of unauthorized access to your data, we will notify your agency administrator promptly, consistent with applicable law.
Cookies
We use a first-party session cookie to keep you signed in, and first-party analytics identifiers (cookie and browser storage) to understand product usage and diagnose errors. We do not use advertising or cross-site tracking cookies.
Your choices
To request access to data we hold about you, to correct it, to ask that your account be deactivated, or to ask questions about how your data is used, contact your agency administrator or regional coordinator first — they own your account. For privacy questions specifically, you can also reach us at support@stationworks.io.
Because Mobilize keeps records agencies rely on for reimbursement, after-action review, and public-records obligations, deactivating an account is not the same as erasing every trace of it: personnel and apparatus records are retained in deactivated form, and audit-log entries and generated documents cannot be deleted for the length of their retention period (see Retention, above). Where records are held on behalf of a public agency, that agency and applicable records law govern what may be deleted and when.
Children
The Service is for adult fire-service personnel. It is not directed at children, and we do not knowingly collect data from anyone under 18.
Changes
We may update this policy. Material changes will be communicated through the Service or by email to your agency administrator. The "Effective" date above indicates the current version.
Contact
Privacy questions: support@stationworks.io.