Summary: Satelife is built around the principle of data minimization. We collect only what is strictly necessary to deliver your report and process payment — nothing more. We do not sell your personal data, we do not store payment card numbers ourselves, and you can request full deletion of your data at any time by contacting loading.... This policy covers both satelife.ai and the Satelife mobile app for iOS and Android — see Sections 3a to 3e.
1. Who We Are
Satelife, Lda. ("Satelife," "we," "our," or "us") operates the website satelife.ai, the Satelife mobile app for iOS and Android, and provides AI-powered wildfire risk assessment reports for properties. This policy applies to all three. Our contact email is loading....
2. Data Minimization Principle
We deliberately design our service to collect as little personal information as possible. Specifically, we do not:
- Build user profiles for advertising or resale.
- Store your payment card number, CVC, or expiry date — these are handled exclusively by our PCI-compliant payment processor (see Section 4).
- Request government identifiers (SSN, driver's license, etc.).
- Track you across third-party websites.
If a piece of information is not strictly required to (a) generate the report you requested, (b) charge you for it, or (c) meet a specific legal obligation, we do not ask for it.
3. Information We Collect
When you request a report, we collect only:
- Email address — used to deliver your report and respond to questions about it.
- Property address — used to generate the risk assessment for that specific location.
- Role (homeowner, insurer, real estate agent) — used to tailor the report format.
We also collect, on a minimized basis, when you visit our website:
- Aggregated usage data — pages visited, clicks, and scroll behavior, via Google Analytics 4 with IP anonymization enabled.
- Basic device information — browser type and operating system, used for compatibility and security.
- Security cookies — Cloudflare Turnstile cookies to protect our forms from automated abuse.
3a. The Mobile App — What It Collects
The Satelife mobile app exists so a property can be assessed on foot, where there is often no signal. That shapes what it collects:
- Account email address — you sign in with an email and password, or with a Google account. If you use Google, we receive your email address and name from Google; we never receive your Google password.
- Property address — the property you are assessing.
- Photographs you take — of the property, as evidence for a readiness requirement or an imagery request.
- Location of each photograph — precise coordinates, an accuracy figure, and a compass bearing, captured at the moment you press the shutter. This records that the assessment was carried out on site and which wall or slope a photo faces.
- Your answers to the readiness questionnaire.
The app contains no advertising SDK, no analytics SDK, and no third-party tracker. It does not read your photo library except for a file you explicitly attach, does not read your contacts or calendar, and does not track you across other apps or websites.
3b. Location and Camera Permissions
The app asks for two permissions, and only uses them for the purposes stated in the request:
- Camera — to photograph the property. Used only while a capture screen is open.
- Precise location, while the app is in use — to stamp each photograph with where it was taken. The app does not request background location and cannot track your movements when it is closed.
Both permissions can be refused or revoked in your device settings. Refusing the camera means you cannot photograph a requirement; refusing location means photographs are recorded without coordinates, and the report will not be able to show that the assessment was performed on site.
Coordinates are taken from the device's location service at capture time rather than from photo EXIF metadata. That is deliberate: EXIF carries no accuracy figure, and on iOS the geotag is stripped when camera access is granted but location is not — which would silently produce photographs that appear to have no location at all.
3c. What the App Stores On Your Device
- Your sign-in session — held in the operating system's secure storage (iOS Keychain, Android Keystore), not in ordinary app files.
- Your draft assessment — answers and photographs, in a local database, so the walk-around works with no connectivity. Drafts stay on the device until they are delivered.
- A copy of your organisation's report list — addresses and statuses, so the list still renders offline. This local database is not encrypted. It is deleted when you sign out and whenever the account changes organisation.
Uninstalling the app removes all of it. That does not delete reports already delivered to our servers — for those, see Section 10.
3d. What the App Sends, and When
Nothing is uploaded while you are offline. When the device regains a connection, the app uploads the photographs and submits your answers against the assessment they belong to, then stops. There is no background beaconing and no periodic phone-home.
Photographs and answers are stored on Satelife infrastructure and used only to produce the report you requested, exactly as described in Sections 5 and 7.
3e. Notifications
If you allow notifications, the app can tell you that a questionnaire is ready to answer. These are local notifications, scheduled on the device by the app itself. Satelife does not operate a push service for the app and does not hold a push token for your device. Notifications can be turned off in your device settings without affecting anything else.
4. Payment Information
Paid reports are processed by Stripe, our third-party payment processor. When you pay:
- Your card number, CVC, and expiry are sent directly from your browser to Stripe — they never touch Satelife servers and we never store them.
- We receive only a transaction reference, the amount charged, and a billing email (for invoice/receipt purposes).
- Stripe's handling of your payment data is governed by its own privacy policy at stripe.com/privacy.
We retain transaction records (not card data) only for the period required by applicable tax and accounting law.
5. How We Use Your Information
We use the information we collect only to:
- Generate and deliver your personalized wildfire risk report.
- Process the payment for that report (via Stripe).
- Respond to inquiries about your report and provide customer support.
- Maintain basic site security and prevent abuse.
- Comply with applicable legal, tax, and accounting obligations.
We do not use your data for advertising, profiling, scoring, or automated decision-making that produces legal effects on you. We do not send marketing email unless you have explicitly opted in.
6. How We Share Your Information
We do not sell, rent, or trade your personal data. We share information only with a short list of service providers strictly necessary to operate the service:
- Stripe — payment processing (card data goes directly to Stripe, not to us).
- Formspree / email delivery — to receive and route your report request.
- Google Analytics 4 — aggregated, anonymized usage analytics.
- Cloudflare — security and bot protection (Turnstile).
- Google — only if you choose "Continue with Google" to sign in, and only to verify that sign-in. Google tells us your email address and name; we tell Google nothing about your property or your report.
- Legal authorities — only when required by a valid court order or by law.
If Satelife is ever acquired or merged, we will give you advance notice before your data becomes subject to a different privacy policy.
7. Data Retention
We keep your data only as long as we genuinely need it:
- Report request data (email, address, role) — kept for up to 24 months so we can answer follow-up questions and re-issue the report on request, then deleted automatically.
- Transaction records (amount, date, invoice reference) — retained for the period required by tax and accounting law (typically 7 years).
- Analytics data — aggregated and retained for up to 14 months by Google Analytics, then auto-deleted. The mobile app has no analytics at all.
- Photographs and questionnaire answers submitted from the mobile app — kept with the report they belong to, on the same 24-month schedule as the rest of the report request data.
- Drafts on your device — held until delivered, and removed with the app if you uninstall it. We cannot delete these for you; they never left your phone.
You may request earlier deletion at any time (see Section 10). Where deletion would conflict with a legal retention obligation, we will restrict processing instead and delete the data as soon as the obligation ends.
8. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used.
- Request access to, correction of, or deletion of your personal information.
- Opt out of the "sale" or "sharing" of personal information (we do neither).
- Be free from discrimination for exercising your privacy rights.
9. Cookies
We use the following types of cookies, and nothing else:
- Essential cookies — required for the website to function.
- Analytics cookies — Google Analytics 4 with IP anonymization. You can opt out via the Google Analytics Opt-out.
- Security cookies — Cloudflare Turnstile, to protect our forms from automated abuse.
We do not set advertising, retargeting, or social-tracking cookies.
The mobile app uses no cookies and no advertising identifier. It does not read the iOS IDFA or the Android Advertising ID, and it does not participate in any cross-app measurement.
10. Your Rights & Data Deletion
At any time you may request to access, correct, export, or delete the personal data we hold about you by emailing loading.... We respond within 30 days. There is no charge and no penalty for exercising these rights.
Deleting a Satelife account. To delete your account and everything attached to it — reports, submitted photographs, questionnaire answers — email loading... from the address you signed up with, with the subject line Delete my account. We confirm within 30 days. Transaction records are retained where tax law requires it, as described in Section 7; nothing else survives. Signing out of the mobile app, or uninstalling it, removes the local copy on that device but does not by itself delete your account.
11. Data Security
All data is transmitted over HTTPS and stored with access controls. Payment data is handled exclusively by Stripe under PCI-DSS Level 1 compliance. While we apply industry-standard safeguards, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
On a mobile device, your sign-in session is held in the operating system keystore. The offline copy of your report list is an ordinary local database and is not encrypted, so on a shared or unlocked handset it is readable by anyone with the device — which is why it is deleted at sign-out. Use a device passcode.
12. Children's Privacy
Our services are not directed to individuals under 18 years of age, and we do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately and we will delete it.
12a. Data and Disclosures
Much of the data behind a Satelife score is published by government agencies. We list every source, with a link to the original, on our Data & Disclosures page. Satelife is an independent private company and does not represent any government entity.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page and, where appropriate, by emailing you.
14. Contact
Questions about this Privacy Policy or about the data we hold on you:
loading...
