Loading...
Loading...
Last updated 2026-09-07
Coffee Table Tactics ("the Service") is operated by JAAI Co, LLC. Your fire department is the data controller for the incident content it enters into the Service — it decides what to record and who on its roster can see it. JAAI Co, LLC acts as the department's data processor and service provider: we handle that content on the department's instructions and under this policy. This policy applies to every department using the Service, on a free or paid plan.
The Service is a planning, training, and after-action review tool. It is not an emergency-response system and must not be relied upon for real-time decision-making during an active incident.
Account data: your name, email, department, and role, used to authenticate you and scope your access to your department's data.
Incident content: the maps, addresses, audio recordings, photos, transcripts, roster, and tactical timelines your department enters into the Service.
Operational data: basic usage and error information needed to keep the Service running and to fix problems. We do not sell personal data, and we do not use your department's incident content to train any third-party AI model.
We use the following subprocessors to deliver the Service. Each receives only the data needed for its function, and none of your department's incident content is used to train any third-party AI model. If we add or change a subprocessor, we will notify participating departments before the change takes effect for their data.
| Provider | What it does |
|---|---|
| Supabase | Database, authentication, file storage, and edge functions. |
| Vercel | Web hosting, plus cookieless Vercel Analytics and Speed Insights. |
| Google Maps Platform | Maps, geocoding, Street View imagery, and 3D building tiles. |
| OpenAI | Radio transcription, event detection, and AI-assisted incident report generation. OpenAI retains API inputs for up to 30 days for abuse monitoring before deleting them. |
| Google Gemini | Generates training-only photo severity ladders for drill scenarios. |
| Resend | Transactional email — account, billing, and lead notifications. |
| Stripe | Billing and payment processing. |
| OpenStreetMap Overpass | Street-name labels on the 3D aerial view. |
| US Census geocoder / Nominatim | Address-lookup fallbacks when the primary geocoder has no match. |
| GitHub | Stores in-app bug reports as issues on our repository. |
| Sentry | Active: receives Content-Security-Policy violation reports and edge-function error reports, so we can find and fix bugs. |
Fireground radio audio and the transcripts we generate from it may contain the names, voices, and addresses of civilians, as well as details about medical or emergency situations. We treat this content as sensitive.
Audio and transcripts are stored securely and scoped to the uploading department — they are not visible to other departments by default. Audio is sent to our transcription provider (see Subprocessors above) and is not used to train third-party models. Your department is responsible for ensuring it has the right to record and upload the audio it provides, consistent with its own records and privacy obligations.
Audio and transcripts are never shared outside your department without redaction or your department's written consent. An officer can mark an individual radio transmission as redacted; a redacted transmission's text and audio are withheld from every surface that leaves your department's own workspace — AI-assisted report generation, a published public report, and data exports — while your department's own copy is untouched.
A department officer can issue a secure, expiring link tied to a single incident. An outside contributor — for example a mutual-aid responder, a property owner, or a bystander who does not have an account — can use that link to submit photos, media, and written input about that incident, without signing up. A contributor must be at least 18 years old to use a contribution link, and anything submitted through it is licensed to the department for use in that incident's record.
Everything submitted through a contribution link lands in a quarantined, department-scoped holding area. It is reviewed by department officers before any of it becomes part of an incident record. It is never visible to other departments, and it does not automatically publish into an incident.
Because third-party submissions may incidentally contain the names, faces, voices, or property of civilians, we handle them under the same sensitivity rules as fireground radio audio (see above). Contribution links introduce no new subprocessor: submitted files and text are stored with our existing storage provider, and any link-delivery email uses our existing email provider — both covered by the Subprocessors section above.
A department officer can share a tactical replay or an approved incident report publicly through a link. A page opened through a shared link discloses that it was shared by the department, and — because a replay and a report describe an incident at a place — it includes the incident address and the map positions recorded during the response. A public replay link omits accountability-group rosters, personnel-note authorship, and free-text timeline notes; only the department that created the link, or an admin, can revoke it.
Incident records, audio, photos, transcripts, and any lesson narration or inserted media your department creates are kept until your department deletes them — we do not time-limit your department's own incident history. Lesson narration and inserted media are deleted with their incident. A fixed set of operational and short-lived records is deleted automatically on the schedule below:
| Record | Kept for |
|---|---|
| Page-view analytics | 13 months after the view |
| In-app notifications | 90 days |
| Bug / feedback reports | 12 months |
| Public replay share links | 30 days after revoke or expiry |
| Department invite codes | 90 days after expiry or revoke |
| Billing event ledger | 12 months |
| Contribution links and uploaded media | 30 days after the link expires |
| Rate-limit counters | 48 hours |
| Demo / sales-lead requests | 24 months after being marked Lost |
You can delete your own account at any time from the profile menu. Deleting your account removes your login and profile. Content you authored — incidents, after-action reviews, roster entries, and similar records — is not deleted: it belongs to your department, so we anonymize your authorship on it (for example, a quick note you wrote shows "Former member" instead of your name) rather than removing the record itself. A super_admin account cannot self-delete, and the last remaining admin of a department must hand off that role to another member first, so a department is never left without an administrator.
A department admin can request deletion of the department's entire account and data by contacting us at the address below.
We may send occasional product or account-related marketing email. You can opt out of non-transactional marketing email at any time from the profile menu; we still send transactional email your department relies on, such as billing receipts and account-security notices.
We use Sentry, which is active, to receive Content-Security-Policy violation reports from the browser and error reports from our edge functions, so we can find and fix bugs. Sentry is listed in the Subprocessors table above.
Your department owns the content it creates. If the Service is discontinued, or if JAAI Co, LLC ceases operating, departments are entitled to a complete export of their roster, incident, and audio data under our written data-continuity guarantee — including a defined turnaround window and a provision so the export remains available regardless of any single person's availability.
A department admin can download that export at any time from Admin → Export (structured data as JSON, with a manifest of every uploaded media file). You may request the media files themselves at any time by contacting us at the address below.
This policy is entered into with JAAI Co, LLC, and is governed by the laws of the State of New York.
Questions about this policy, a data export, or deletion? Reach out to us at hello@coffeetabletactics.com.