Skip to content
Legal

Privacy Policy

What we collect, why we collect it, who helps us process it, and how to reach us. We collect only what a plan and an activation need.

Effective October 6, 2026

1. Who we are and what this covers

Emergency Safety Planning is operated by MML Inc. d/b/a Memorial Media Links (“Memorial Media Links,” “we,” “us”). This policy explains how we handle personal information on emergencysafetyplanning.com, in the application, and on our phone line.

Our customers are organizations. When an organization puts information about its staff, volunteers or responders into its account, it decides what goes in and why; we process that information on the organization’s behalf and under its instructions. If you are on an organization’s roster and have a question about your information, please contact that organization first. We will help it respond.

2. Information we collect

  • Account information: name, email address, password (stored only as a hash), role, and, if you sign in with Google, the name and email Google shares.
  • Organization information: organization name and type, addresses, building and room details, floor plans, equipment locations, hazards, and the content of the emergency plan.
  • Roster information:names, job titles, phone numbers (including alternates), email addresses, notes, languages, incident-command assignments, training certifications and uploaded certificates for the people an organization lists, and each person’s call, text and email preferences.
  • Documents and uploads: existing plans, drawings and files you upload.
  • Activation and drill records: when an incident or drill was started, who started it, who was contacted, delivery status, responses, and, for voice calls, call audio, transcripts and summaries.
  • Phone line and support: if you call our number, the call audio, transcript and any message or client ID you give; and the content of support tickets.
  • Billing information: plan, subscription status, billing contact and invoice history. Payment card details are handled by Stripe.
  • Technical and usage information: IP address, browser and device type, pages visited, and actions taken, collected through server logs, cookies and Google Analytics.

3. How we use it

  • to provide the Service: build and store plans, run activations and drills, and place the calls, texts and emails an organization starts;
  • to create and secure accounts, prevent abuse, and keep audit logs;
  • to bill customers and send reminders, notices and service messages;
  • to answer support requests, including by viewing an account through a logged support session;
  • to understand how the website and product are used so we can improve them; and
  • to comply with law and enforce our Terms.

We do not use customer content to train our own AI models, and we do not use roster contact information for marketing.

4. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioral advertising. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent will not be shared with any third party.

We share information only with service providers that process it for us:

  • Stripe: subscription billing and payments. Card details go directly to Stripe; we never see or store full card numbers.
  • SendGrid (Twilio): sending account, reminder, support and activation emails.
  • Retell AI (and its voice sub-processors): placing automated activation calls, and answering our phone line, including call audio, transcripts and call summaries.
  • Twilio: sending activation and drill text messages.
  • OpenRouter (which routes requests to model providers such as OpenAI) and Anthropic: AI processing for the guided interview, plan drafting, document import, the writing assistant and the help chat.
  • Our email archive provider: storing copies of the emails the Service sends, for our records.
  • Google: optional sign-in with a Google account, address geocoding and aerial map images for your site, and website analytics (Google Analytics).
  • Our hosting provider: servers located in the United States that run the application, the database and file storage under our control.

We may also disclose information to comply with law or valid legal process, to protect anyone’s safety or our rights, or as part of a merger or sale of the business under this policy’s protections. Within a multi-site account, the name of the person in command of a building’s chart may be shown to the other sites in that account, and the people on a shared command chart are contacted during the activations of every site that runs on it.

5. Cookies and analytics

We use a sign-in cookie to keep you logged in (it expires after about 12 hours without activity) and a separate cookie while our staff are in a support session. These are strictly necessary.

We use Google Analytics to measure visits to the website and application. It sets its own cookies and sends usage information to Google. We do not use advertising cookies. You can block cookies in your browser or install Google’s Analytics opt-out add-on. Pages opened from a shared plan link are not reported to Google Analytics.

Browsers’ “Do Not Track” signals have no agreed meaning and we do not respond to them. Where state law requires it, we treat a Global Privacy Control signal as a request to opt out of sale or sharing, which we do not do in any case.

6. How long we keep it

We keep account and organization information for as long as the account is open. Outgoing emails are archived for our records, and activation, drill and call records are kept with the organization as part of its audit trail.

When an organization is deleted, it becomes inaccessible to everyone immediately. We keep it for 60 days so that it can be restored if the deletion was a mistake. After 60 days its database records and stored files are permanently destroyed. Server backup copies expire within 7 days after that. Two things are not removed automatically: individual user sign-in accounts, and copies of emails in our email archive; we delete those on request. Records we must keep for legal, tax or accounting reasons, such as invoices, are kept for as long as the law requires.

7. Security

We encrypt data in transit, scope every request to the signed-in organization, hash passwords, and log sensitive actions. No system is perfectly secure, and we cannot guarantee that information will never be accessed without authorization. If a breach affects your personal information we will notify you as the law requires. Our Security & privacy page has the details.

8. Children, students and patients

The Service is for adults acting for organizations and is not directed to children under 13. We do not knowingly collect personal information from children. Rosters are meant for the adults who respond during an emergency. Schools should not enter student education records, and clinics should not enter protected health information; the Service does not need them, and we are not a HIPAA business associate unless we sign a separate agreement. If you believe a child’s information was entered, contact us and we will delete it.

9. Your choices and rights

Calls and texts. Reply STOP to any text to stop texts. You can ask the organization that listed you to turn off calls, texts or emails to you; each channel can be switched off separately. See our Call & SMS Terms.

Access, correction and deletion. Account users can view and correct most of their information in the application. Depending on where you live, including under the New Jersey Data Privacy Act and similar state laws, you may have the right to confirm whether we process your personal information, to access, correct, delete or obtain a portable copy of it, and to opt out of sale, targeted advertising and certain profiling (which we do not do). To make a request, email support@emergencysafetyplanning.com. We will verify your request, respond within the time the law allows, and will not discriminate against you for exercising your rights. If we deny a request you may appeal by replying to our decision. Where we hold your information on an organization’s behalf, we may refer your request to that organization.

10. Where information is processed

The Service is operated from, and intended for organizations in, the United States. Information is stored and processed in the United States, and some of our service providers may process it in other countries under their own safeguards.

11. Changes and contact

We may update this policy. We will post the new version with a new effective date and, for material changes, notify account owners before they take effect.

Questions or requests: support@emergencysafetyplanning.com, or write to MML Inc. d/b/a Memorial Media Links, Attn: Privacy, 116 N. 2nd Street, Suite #208, Camden, New Jersey 08102.

MML Inc. d/b/a Memorial Media Links

116 N. 2nd Street, Suite #208

Camden, New Jersey 08102

support@emergencysafetyplanning.com

Terms of ServicePrivacy PolicyDisclaimerCall & SMS TermsAffiliate Agreement