RootCause Simulator
Back to home

Policy Version 1.0

Privacy Policy

Effective date: May 5, 2026. This policy describes how RootCause Simulator ("we", "our", or "the Service") collects, uses, and protects information when you use our platform.

Early Access / Beta: This platform is currently in active development and is available to early-access users. Features, data structures, and security controls are subject to change before general availability. See our Security page and Data Processing Agreement for full details on how we protect your data.

1. Who We Are

RootCause Simulator is a professional training and certification platform built around the Human Factors Analysis and Classification System (HFACS) 8.0 framework, which is published by the U.S. Department of War (formerly the Department of Defense). We are an independent training provider and are not affiliated with, endorsed by, or acting on behalf of any government agency.

We are also not affiliated with, endorsed by, or acting on behalf of HFACS, Inc. or any other private organization that provides official HFACS instructor certification, licensed workshops, or formal HFACS training programs. Completion records generated by this platform do not represent certification from HFACS, Inc. or any official HFACS training authority.

2. What We Collect

We collect only the data necessary to provide and improve the Service:

  • Account information: Email address and hashed password (handled by Supabase Auth; we never store plaintext passwords).
  • Training progress: Module completion status, quiz answers, scenario attempts, reflection responses, and earned badges. This data drives your personalized learning path and certification records.
  • Scenario narratives: Text you write in the narrative builder is stored to enable export, AI-assisted feedback, and report generation. Narratives may contain details about real-world incidents; do not include personally identifiable information about third parties.
  • Consent records: A timestamped record of your agreement to this policy at the moment of account creation.
  • Security logs: Login timestamps, failed login attempts (for account lockout protection), and, for admin users, admin action logs. IP addresses are stored in truncated form only (first three octets).
  • Settings and preferences: Industry, coaching preferences, and optional AI integration settings you configure in your account.

3. How We Use Your Data

Your data is used exclusively to operate the Service:

  • Authenticate you and keep your account secure.
  • Track your progress through the HFACS learning curriculum (Levels 1–4) and generate your certification records upon completion.
  • Provide AI-assisted feedback on scenario narratives. When this feature is enabled, your narrative text is sent to a third-party AI provider (OpenAI) via our server — it is not sent directly from your browser. OpenAI's data use policies apply to that processing; we do not authorize OpenAI to train on your content.
  • Personalize coaching suggestions and adaptive challenge difficulty.
  • Generate exportable training reports and certification PDFs for your records or your employer.
  • Protect the platform from abuse and unauthorized access.

We do not sell your data. We do not use your training data for advertising. We do not share your personal information with third parties except as described in Section 5.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with GDPR-equivalent law, our legal bases for processing are:

  • Contract performance — processing necessary to provide the training and certification service you signed up for.
  • Consent — specifically, your explicit agreement at signup to the processing of your training data for HFACS certification purposes.
  • Legitimate interests — security logging and fraud prevention, where our interests do not override your rights.

5. Third-Party Services

We use the following sub-processors:

  • Supabase — database, authentication, and file storage. Data is stored in the region selected at project creation.Supabase Privacy Policy.
  • OpenAI — AI narrative analysis, invoked only when you use the AI feedback feature. Only the text of the specific narrative section being analyzed is transmitted; no account identifiers are sent.OpenAI Privacy Policy.

6. DoD HFACS Content

This platform incorporates the HFACS 8.0 taxonomy, training materials, and framework guidance published by the U.S. Department of War (formerly the Department of Defense). That content is used for educational purposes. Your training interactions with DoD HFACS content — quiz responses, classification decisions, reflection entries — are stored solely to support your personal learning progress and certification. This data is not shared with any government agency.

7. Certification Records

Upon verified completion of the required curriculum, a certification record is generated and stored in your account. Certification issuance is tied to server-verified completion of all required modules; client-side state alone cannot trigger certification. Your certification records are retained for as long as your account is active.

If you use the PDF export feature, the resulting file is generated on your device and is not stored on our servers.

8. Data Retention

  • Account and training data: Retained while your account is active. If you delete your account, your personal data is deleted within 30 days, except where retention is required by law.
  • Consent records and security logs: Retained for 3 years for compliance and fraud-prevention purposes.
  • AI-analyzed narrative text: Not retained by us after the OpenAI API call completes. OpenAI's own retention policy governs their handling of the request.

9. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, or to withdraw consent. To exercise these rights, contact us at the address below. We will respond within 30 days.

10. Security

We apply industry-standard security measures: encryption in transit (TLS), row-level database security policies, server-side route authentication for admin functions, and append-only audit logs for sensitive operations. No system is perfectly secure; if you discover a vulnerability, please report it responsibly rather than exploiting it.

For a full description of controls currently in place, see our Security page. Enterprise customers may also review the Data Processing Agreement.

11. Changes to This Policy

If we make material changes, we will update the version number and effective date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

12. Contact

Questions about this policy or requests to exercise your data rights:
RootCauseSim@gmail.com