This policy reflects how RespondConnect handles your data today and may be updated as the service grows. Questions: privacy@respondconnect.com.
1. Information we collect
We collect what's needed for a verifying member at your department to confirm you, and for us to run the service. Identity & verification: name, rank, badge/ID number, department email, and any credential documents you or your agency provide (for a sponsored adult household member, the sponsoring member relationship). Account & profile: assignment/precinct, photo, bio, and your notification, shift, and quiet-hours preferences. Content: listings, board and community posts, direct messages, poll responses, and reactions. Usage & device: basic log and device data needed to operate and secure the service.
2. How we use information
To let a verifying member at your department confirm your eligibility, operate the portal, keep the space safe (moderation and safety tooling), provide support, and meet legal obligations. We do not sell your data, and we do not run advertising against member content.
3. Verified identity & handles
RespondConnect is a real-identity network. The one exception is the peer-support board, where you may post under a handle - that handle can be revealed only by the peer-support contacts your agency has designated for that role - one post at a time, with a written reason, and every reveal is logged. Ordinary agency admins and command staff cannot unmask it, and RespondConnect does not confirm what training a designated contact has had; that is your agency's call. Polls record aggregate totals only; individual votes are never shown. Your private wellness check-ins are visible only to you - no other member, your agency, and no operator screen surfaces them, and you can delete them yourself at any time. They are stored securely but are not end-to-end encrypted, so we could technically access the underlying records if compelled by law; no part of the product does so in ordinary use.
4. Data retention & deletion
We're built to keep little. Some of that runs today and some is designed but not switched on yet, and this says plainly which is which. Today: a post or message you delete is hidden immediately and retained only for safety and legal review, not shown back to members; your private wellness check-ins can be permanently deleted by you at any time; and credential documents are automatically deleted within 7 days of an approval or decline. Not switched on yet: scheduled automatic purging of older content. The rules are written and the mechanism is built, but it is not deleting anything today, and we won't describe it as active until it is. Our current target is about 12 months for board posts and messages. Throughout, a legal hold pauses deletion for the named accounts and content while a matter is open, and content that constitutes CSAM is preserved and reported, never purged.
5. How information is shared
Within your agency, content is tenant-isolated: your board, roster, and internal spaces are visible only to your own agency's members, never to other agencies. Some surfaces are deliberately cross-agency, and posting there shares your content beyond your department: Communities are shared cross-department networks where responders from other agencies can see and reply to what you post; mutual-aid posts are visible to agencies in a shared region; and a direct message reaches whoever you send it to, who may be at another agency. Service providers act as processors under confidentiality. Legal disclosures are handled through the Legal Process page below; where lawful, the affected agency is notified. CSAM is reported to NCMEC and law enforcement.
6. Who governs your data
RespondConnect runs a layered model, not a single owner. Your agency governs what it legitimately runs: it verifies your identity and administers its own board, roster, and moderation of content posted in its space. RespondConnect stewards the member-first, cross-agency parts of the network - the Communities you join across departments and the protected safe spaces (peer support, wellness, anonymous polls) - which run on platform policy and are not run by, or visible to, your employer. Operator (platform) access is recorded in our audit log, together with the reason it was needed.
7. Platform access to your information
Our operators can access member data only for legitimate operational reasons - providing support, resolving an account or access problem, investigating a safety report, or responding to legal process - and only on a least-privilege, need-to-know basis. There is no browse-all directory: looking up a member requires a specific reason, returns only minimal identity and membership details (name, agency, assignment, badge, tier, status), and is recorded in our audit log along with that reason. A routine lookup does not expose your protected content - your peer-support posts and any handle reveal, your wellness check-ins, individual poll votes, and the contents of your direct messages are not shown. Where broader access to content is genuinely necessary, it follows a separate, logged safety or legal process - never a routine lookup.
8. Security
We protect data with encryption in transit, access controls, least-privilege operator access, and append-only audit logging of sensitive actions.
9. Your choices & rights
You can edit your profile and preferences in-app at any time. For agency-governed data (your verification and your agency's board), requests to access, correct, or delete go through your agency's administrators. For the member-first and safe-space data the platform stewards (Communities, peer support, wellness), contact RespondConnect directly - so your request never has to pass through your employer. All requests are subject to legal holds and our retention schedule.
10. Eligibility
Membership is limited to public-safety personnel whose identity has been verified by a verifying member at their own department and sponsored adult household members. The service is not directed to children and is not intended for anyone under 18.
11. Changes & contact
We'll communicate material changes in-portal. Questions about this policy: privacy@respondconnect.com.