Privacy Policy

Last updated: August 17, 2026

FireBrigade.com provides tools and information that help fire departments identify the hazards their members face, select protective equipment that matches them, care for it properly, and fund it. This page explains what we collect when you use those tools, why, and how to have it deleted.

The short version

  • We collect only what the tools need in order to work, and we read it to keep them working and to catch misuse.
  • There is no third-party analytics, no advertising network, and no tracking cookie on this site.
  • We do not sell, rent, or trade anything we hold, and nothing reaches a sponsor unless you ask us to put you in touch with one.
  • You can ask us to delete anything we hold about you, and we will.

What we collect, and why

The Structural PPE Risk Assessment

When you start an assessment we store the details you enter about your department, your answers to the assessment questions, your email address, and the Word and PDF documents generated from those answers.

The department details are the ones the assessment asks for on its first screen: fire department name, assessment date, type of department, the number of personnel issued structural PPE, and the name of the person preparing it.

We keep the answers so you can stop part way through and come back to it later. We ask for an email address for two reasons: it is how you get back in if your resume code is lost, and requiring a working address is what stops the tool being filled with automated submissions. You can choose to create an account with a password so that returning does not need the code or the email, but it is optional — the emailed link and the resume code work without one.

Your resume code is stored only as a one-way hash. We cannot read it, recover it, or tell you what it is. If you lose it, ask for an emailed link instead.

If you create an account

An account stores your email address as the username, a one-way hash of your password, the date it was created, and the session records that keep you signed in. We never store the password itself and cannot see it. An account is only ever a way back into your own assessments: it carries no access to anything else on this site.

The contact form

The contact form stores your name, email address, department, subject and message, together with the IP address and browser user-agent string the message was sent from. Those last two are kept only to tell genuine messages from automated ones.

Advertising slots

Where the site shows an advertiser banner, we count how often it was displayed and clicked. That count uses a short pseudonym worked out from your IP address and browser, mixed with a secret value that changes every day and then shortened. No cookie is set, your IP address is not stored, and the pseudonym cannot be connected to you or matched up across two different days.

Server logs

Like any web server, ours records requests: IP address, date and time, the page requested, and the browser user-agent. These rotate automatically and are used for security and for fixing faults.

What we do not do

  • No Google Analytics or any other third-party analytics.
  • No advertising cookies, tracking pixels, or cross-site profiling.
  • No external fonts or scripts. The site actively blocks requests to font and script hosts so that visiting a page does not tell anyone else you were here.
  • We never sell, rent, or trade your information, and we do not add you to a marketing list because you used a tool.

Cookies and browser storage

This site sets no cookies for ordinary visitors. WordPress sets cookies only for staff who log in to administer the site.

The risk assessment does keep your resume code in your browser local storage, so that returning to the page on the same computer offers to carry on where you left off. That is held in your browser, not on our server, and clearing your browsing data for this site removes it.

Email

Mail from this site is sent through Titan, our email provider, from an address at firebrigade.com. Messages about a risk assessment contain a one-time link that stops working after it is used or after 24 hours, whichever comes first.

How we use what you submit

Beyond running the assessment itself, we read what is submitted for three reasons, and it is fair that you know all three.

  • To run the tool. Your answers are stored so that you can stop and come back to them, and they are merged into the Word and PDF documents the assessment produces.
  • Internal processing and functionality review. We look at real assessments to check that the decision trees behave sensibly, that questions are being read the way they were meant, and to diagnose faults. When a change to the assessment would affect a report somebody has already generated, looking at the stored answers is how we find out.
  • Reviewing for abuse. We check submissions for automated or bad-faith use. That is the same reason a working email address is required before an assessment can begin.

This review is done on the actual details you entered, not on an anonymized copy, and it is done by the people named in the next section and nobody else. We would rather say that plainly than imply the data is only ever read by a machine.

Who can see what you submit

Completed and in-progress assessments, and contact form messages, are visible only to site administrators and to staff holding the RiskAdmin role. Nobody else has access, and assessments are not shared with equipment manufacturers, suppliers, or any other third party. There is one exception, and it is entirely in your hands.

The site runs on servers we control. It is reached through Cloudflare, which passes traffic through to us.

If you ask a sponsor for information

Some pages on this site carry sponsor banners. If you ask us to put you in touch with a sponsor, or request more information from one, we pass on what that company needs in order to reply to you: your name, your department, your email address, your message, and, if you reached that page from a question in the risk assessment, the wording of that question, so the sponsor knows what you were reading about. This is the only circumstance in which anything you give us reaches a company outside FireBrigade.com, and it happens only because you asked for it.

Your answers are not included, and neither is the assessment itself. The sponsor may be told which question you were reading about, but never how you answered it, nor anything else you have entered. A completed assessment sets out where a department’s protective equipment falls short, and that is not something we hand to a company that sells protective equipment. If you want a sponsor to see your assessment, the documents are yours to send.

Clicking a sponsor banner never sends anything by itself. It only opens a form, which tells you who will receive it before you fill it in.

Sponsors are told how often their banner was shown and clicked. Those are counts, and they identify nobody.

How long we keep it

  • Risk assessments while they are in progress, and for 24 months after the last time one was worked on.
  • Contact form messages for 24 months.
  • Advertising counts for 13 months, after which only the daily totals remain and those identify nobody.
  • One-time email links for 24 hours, and the spent records are cleared within a week.
  • Server logs for as long as the normal rotation keeps them, which is a matter of days.

Deleting what we hold

You can have anything we hold about you deleted. You do not have to give a reason, and it costs nothing.

Ask us by email

Write to info@firebrigade.com and say what you want removed. For a risk assessment, tell us the fire department name and the email address it was started with, so we can find the right one. For a contact form message, the address you wrote from is enough.

When we delete a risk assessment we remove the stored record and every answer in it, the Word and PDF documents generated from it, the email address held against it, and any unused email links still outstanding. Nothing is kept back in an archive.

We will act on a request within 30 days, and normally within a few working days. We will write back to confirm when it is done.

Deleting an account

Ask us and we will delete the account itself along with anything you want removed. Deleting an account does not automatically delete the assessments made with it, and deleting an assessment does not close the account, so tell us which you want. If you want everything gone, say so and we will remove both.

Use the contact form

The contact form reaches the same place if you would rather not send an email directly.

Clear it from your own browser

Clearing your browsing data for this site removes the resume code held in your browser. That stops this computer from offering to resume, but it does not delete the assessment from our server: use one of the routes above for that.

Deleting a risk assessment cannot be undone. The generated Word and PDF documents go with it, so download anything you want to keep before asking us to remove it.

What we cannot remove

Email we have already sent you is in your mailbox and is yours to delete. Server logs age out on their own rotation and are not edited by hand. Where we are required to keep something to comply with the law, we will say so and explain why.

Your choices

You can use most of this site without giving us anything at all: reading any page, including all of the standards and grant funding material, involves no form and no account. An email address is needed only to start a risk assessment, and only so that you can get back into it.

Children

This site is intended for fire service personnel and is not directed at children. We do not knowingly collect information from anyone under 13.

Changes to this policy

If this policy changes, the date at the top of the page changes with it. Where a change materially affects information already collected, we will say what changed rather than quietly replacing the text.

Contact

Questions about this policy, about what we hold, or about having it removed: info@firebrigade.com.