Privacy

What we collect, and what we do with it.

Cairn holds compliance records, so this policy is written to be read rather than skimmed. It describes what actually happens, not what a template says usually happens.

LAST UPDATED 8 AUGUST 2026

Status

Drafted for launch — pending review by an Australian lawyer.

Who we are

Cairn is a work health and safety documentation tool operated from Perth, Western Australia. Contact us at hello@cairnwhs.au about anything in this policy, including a request to access or delete your data.

What we collect

We collect three kinds of information, and no more:

  • Account and contact information — your email address and the business name you enter at checkout. Your email is verified by Stripe at payment and again by the sign-in link, and it is how your account is identified.
  • Subscription information — your plan, subscription status, and billing period. Card details are entered directly into Stripe and are never sent to, seen by, or stored by Cairn.
  • The content you submit — the descriptions, dates, locations, hazard tags and other details you enter into the Incident Reporter and Risk Assessment Generator, together with the documents generated from them, any worker names and site names you add, and the name of the person who records a review.

What we do not collect

We do not use analytics, advertising or tracking cookies. We do not build a profile of you. The only cookie Cairn sets is the session cookie that keeps you signed in.

Voice dictation, where your browser supports it, is handled by your browser and its operating system. Cairn receives only the resulting text, in the same form as if you had typed it.

Where it is stored

Account records, subscription records and generated documents are stored in Supabase (PostgreSQL and Supabase Storage). Rendered PDFs are held in a private storage bucket that is not publicly readable; downloads are served through short-lived signed links after we check that the document belongs to your account.

The Supabase project region is set by the operator at deployment. If you need the specific region for your own compliance purposes, ask us and we will tell you.

Who else processes it

Cairn relies on three processors, each for a single purpose:

  • Anthropic — the text you submit for a document, together with our system instructions, is sent to the Claude API to produce the draft. This is the only place your submitted content leaves our infrastructure for processing, and it is sent solely to generate your document.
  • Stripe — payment processing and subscription management, including the billing portal where you change or cancel your plan.
  • Resend — transactional email only (your welcome email and payment-failure notices). We do not send marketing email.

How long we keep it

Generated documents and their inputs are kept for as long as your account exists, because they are compliance records and deleting them without being asked would defeat the purpose of the product.

Cancelling a subscription does not delete anything. Your records remain until you ask us to remove them.

Deleting your data

Email hello@cairnwhs.au and we will delete your account, your documents, their stored PDFs, and your worker and site records. We will confirm when it is done.

Note that deletion is permanent and we cannot recover the records afterwards. If they are records you may need to produce to a regulator or a principal contractor, export them first.

Security

Every table is protected by row-level security scoped to your account, and every write to a document, review record, worker or site goes through a server-side check of who you are and what you are entitled to. Stored PDFs are in a private bucket with no public read access.

No system is perfectly secure. If you believe your account has been accessed by someone else, email us and we will revoke its sessions.

Changes to this policy

If we change how your data is collected, stored or processed, we will update this page and email existing customers before the change takes effect.