Section 1Who we are and what this covers
PiranCommand is operated by Trillix Labs, LLC ("Trillix", "we", "us"), mailing address, Rhode Island. This policy explains what we collect, why, and who can see it across two places:
- The website at pirancommand.com, including demo requests and any pages we publish about the product.
- The service: the PiranCommand web application, apparatus tablet application and iOS application, together with the dispatch workspace, station TV view and the integrations that feed them.
Our customers are fire departments, EMS agencies and the municipalities or districts that run them ("departments"). People who use the service do so under their department's account ("users"). The department decides what it puts into the service and how long it keeps it; we process that data on the department's behalf and under its instructions. If your department has its own privacy notice for personnel, that notice governs how the department itself handles your information.
Plain-language summary. We collect what is needed to run an incident, a station and a report. Your department owns its data. We do not sell it, we do not use it for advertising, and nobody outside your department sees an incident unless your department shares it for mutual aid.
Section 2Information we collect
Account and personnel data
Name, rank, department, platoon and shift, role "hats", work email, mobile number for notifications, certifications and training hours, and the audit trail of what a user does in the service (sign-ins, board entries, sign-offs).
Operational data
Records the department creates or that flow in from dispatch: incident and call records, unit status and timestamps, apparatus positions (AVL), tactical board assignments and ICS positions, personnel accountability (PAR) records, SCBA air readings and exit-time calculations, rehab vitals with sign-offs, MAYDAY and RIT records, hose-line and benchmark entries, hydrant and water-supply data, pre-incident plans, inspection findings and permits, truck and ambulance checks, inventory, and the NERIS and NFIRS submissions generated from all of the above.
Patient information
Where a department uses the service for EMS calls, records may include patient care information that is protected health information under HIPAA. See Section 6.
Data from integrations
Call data received from the department's CAD or dispatch center by webhook, email, file drop or pager text; staffing data synced from CrewSense; hydrant and mile-marker data imported from state datasets; routing requests sent to Google Maps; and delivery records for notifications sent through Twilio.
Technical data
Device type and operating system, app version, browser, IP address, approximate location derived from IP, crash and performance reports, offline sync queues and logs, and cookies or similar identifiers on the website (Section 13).
Communications
Demo requests, support conversations, feedback from pilot departments, and correspondence with us.
Section 3How we use information
- To run the service. Putting the call on the board, tracking units, running PAR timers, drawing the map, syncing the apparatus tablet, and generating the report.
- To file reports on your behalf. Submitting incident data to NERIS (and NFIRS 5.0 while your state transitions) when an authorized user files it.
- To send notifications your department configures, including SMS and email with quiet hours.
- To support you, onboard your data, and respond to requests.
- To keep the service secure: detecting abuse, investigating incidents, maintaining audit logs.
- To improve the product using aggregated or de-identified data that cannot reasonably identify a department, a user or a patient. We do not use identifiable operational data or patient information to train general-purpose AI models.
- To meet legal obligations and enforce our agreements.
We do not sell personal information and we do not use it for third-party advertising.
Section 4Who can see it
- Your department. Administrators control who in the department can see and edit what, by role and hat.
- Mutual-aid partners, only when your department shares a specific incident (Section 5).
- NERIS / FSRI and your state, when an authorized user files a report. Once filed, that submission is governed by the receiving system.
- Service providers that process data for us under contract and only for the purposes above:
| Provider | What it does | What it receives |
|---|---|---|
| Hosting provider | Application hosting and databases | All service data, encrypted at rest |
| Twilio | SMS and email delivery | Phone numbers, email addresses, message content the department sends |
| Google Maps Platform | Routing and loaded transport miles | Origin and destination coordinates for a route |
| CrewSense | Staffing sync (05:00 daily) | Roster and schedule data the department already keeps in CrewSense |
| Error and performance monitoring | Crash and performance reports | Technical data, never incident narrative or patient information |
- Legal requests. We disclose data when required by law or a valid legal process. Where the law allows, we notify the department first and direct the request to it, since the department is the records custodian.
- Business transfers. If Trillix is acquired or merges, data transfers with the business and stays subject to this policy and to the department's agreement.
Section 5Department isolation and mutual aid
Every record is scoped to a single department at the database level, not filtered in the application layer. There is no query path that returns another department's data.
Mutual-aid sharing is explicit and per incident. When a department shares an incident, the responding department's users see that incident's board in read-only form for the duration of the incident. Sharing is logged, can be withdrawn at any time, and ends automatically when the incident closes. Nothing else in either department's account is visible to the other.
Section 6Sensitive data: patient information and location
Patient information (EMS)
When a department uses PiranCommand for EMS calls and enters patient care information, Trillix acts as a business associate to that department under HIPAA. We sign a Business Associate Agreement with each such department before patient information is entered, we use patient information only to provide the service, and we apply the safeguards required by the HIPAA Security Rule. Patient information is never shown on a shared mutual-aid board unless the sharing department chooses to include it. Confirm with counsel whether every pilot department is a covered entity and whether the BAA is part of the pilot agreement.
Location
AVL positions come from apparatus, not from personal phones. The tablet and iOS applications report position only for a device a department has enrolled as an apparatus or command device, and only while that device is signed in. Personnel are not tracked individually. Location history is retained as part of the incident record so that the timeline reflects what actually happened.
Health data about personnel
Rehab vitals recorded at an incident are part of the incident record and are visible to the roles the department designates (typically the rehab officer, safety officer and command). They are not used for any other purpose.
Section 7Retention, export and deletion
Fire and EMS records are public records with retention periods set by state schedules, so the department controls how long operational data is kept. Unless the department instructs otherwise:
- Operational and personnel records are retained for the term of the agreement.
- Audit and technical logs are retained for 12 months.
- Website and demo-request data are retained for 24 months after our last contact.
At the end of an agreement the department can export its data in standard formats for 30 days. After that window we delete department data within 90 days, except for copies in encrypted backups that expire on their own schedule and anything we must keep to meet a legal obligation or hold.
Section 8Your choices and rights
- Access and correction. Users can see and update their own profile in the service. Requests about operational records go to the department, which is the custodian; we help departments respond.
- Notifications. Users can set quiet hours and channels for the notifications their department enables.
- Marketing email. Every marketing message includes an unsubscribe link. Service messages (outages, security notices) are not marketing and cannot be turned off.
- State privacy laws. Where a state privacy law gives you rights over personal information we hold as a controller (for example, website visitor data), you can exercise them by contacting us (Section 15). Most state laws exempt data that a government agency holds; for that data, contact your department.
Section 9Public records
Departments are public agencies, and records they keep in PiranCommand may be subject to state public records and freedom-of-information laws. Requests for those records should be directed to the department. We provide departments with export and search tools to respond, and we do not release a department's records to third parties on our own except as described in Section 4.
Section 10Security
- Encryption in transit (TLS) and at rest.
- Role-based access control, per-department isolation at the database level, and separate credentials for the dispatch workspace.
- Audit logging of sign-ins, board entries, sharing events and every NERIS submission and response.
- Encrypted backups and tested restores.
- Offline queues on the apparatus tablet are stored encrypted on the device and cleared once synced.
- Security incident notification to affected departments without undue delay and no later than 72 hours after we confirm a breach affecting their data.
No system is perfectly secure. Departments should enforce strong credentials, remove users promptly when they leave, and report suspected misuse to us immediately.
Section 11Children
The website and the service are for fire and EMS professionals and are not directed to children under 18. We do not knowingly collect personal information from children. Patient information about minors entered by an EMS crew is handled as patient information under Section 6.
Section 12Where data is stored
Data is stored and processed in the United States. We do not target users outside the United States.
Section 13Cookies on the website
The website uses strictly necessary cookies and privacy-respecting analytics with no cross-site tracking, or state that none is used. The service uses session cookies and local storage to keep you signed in and to queue work offline. We do not use advertising cookies.
Section 14Changes to this policy
When we change this policy we will post the new version here with a new effective date, and for material changes we will notify department administrators by email at least 30 days before they take effect.
Section 15Contact
Privacy questions, requests and complaints: hello@pirancommand.com or Trillix Labs, LLC, mailing address. We answer within 30 days.