Scenario One LogoScenario OneBack to Home

Privacy Policy

Last updated: July 29, 2026

1. Overview

ScenarioOne, Inc., a Delaware corporation which operates Scenario One ("Scenario One," "we," "us"), provides a software platform that helps healthcare organizations prepare for emergencies and become audit-ready. This policy explains what information we collect, how we use it, who we share it with, and the choices available to you. It applies to our public website and to the Scenario One application.

Scenario One is a business-to-business service. Most of the information in the platform is entered by the healthcare agency that subscribes (the "Agency") about its patients, staff, and operations. For that information the Agency decides what is collected and why, and we process it on the Agency's behalf and under its instructions — see Section 5.

2. Information We Collect

  • Account information: name, work email, agency name, assigned role, authentication data managed by Firebase Authentication, password-change and terms-acceptance timestamps. We do not store your password in readable form.
  • Agency and operational data: agency profile, service locations and addresses, service types, policies, emergency plans, hazard vulnerability and risk assessments, readiness and compliance records, and documents generated or uploaded in the platform.
  • Patient records entered by the Agency: patient identifiers and contact details, clinical and functional information, equipment and medication needs, evacuation and mobility considerations, emergency contacts, and addresses — as needed to produce individualized emergency plans. This may include protected health information ("PHI").
  • Staff records entered by the Agency: staff names, contact details, roles, training assignments, and training and drill results and scores.
  • Usage and technical data: log data, IP address, browser and device information, timestamps, feature usage, and error diagnostics, used to operate, secure, and improve the service.
  • Communications: demo requests, support and contact-form messages, and related correspondence.

We do not require or request payment card details in the platform, and we do not knowingly collect information from children.

3. How We Use Information

  • To provide, host, and support the platform for the Agency.
  • To generate the documents, plans, assessments, and training content the Agency requests, which involves sending the relevant content to the AI providers listed in Section 4.
  • To authenticate users, enforce roles, isolate each Agency's data, and keep records of platform activity.
  • To send transactional email such as account invitations, password-related messages, and service notices.
  • To troubleshoot, monitor performance and security, prevent abuse, and improve reliability and usability.
  • To respond to inquiries and to meet our own legal and contractual obligations.

We do not sell personal information, and we do not use Agency Data, patient information, or staff information to train our own or third parties' AI models. Any analysis we perform to improve the service uses aggregated or de-identified data that does not identify an Agency, individual, or patient.

4. Service Providers and Sub-Processors

We use the following third-party providers to operate the platform. They process information only as needed to provide their service to us:

  • Google Cloud / Firebase — authentication, database (Firestore), and file storage; hosting infrastructure.
  • Google (Gemini) and OpenAI — AI models used to draft documents, assessments, and training content, and to score responses.
  • Pinecone — vector search over reference and example documents used to improve generated output.
  • Google Maps Platform — geocoding and mapping of service addresses and locations.
  • Email delivery provider (SMTP) — sending transactional and notification email.
  • Hosting and deployment provider — running the web application and its API routes.

We may add, replace, or remove providers as the platform evolves. We may also disclose information when required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case this policy will continue to apply or you will be notified of the change.

5. Protected Health Information and Our Role

Where an Agency uses Scenario One to process PHI, the Agency is the covered entity or controller of that information and we act as its service provider, processing PHI on the Agency's behalf and under its direction. Access is restricted to that Agency's authorized users through role-based permissions and agency-based data isolation.

Where a Business Associate Agreement is required, the parties will execute one, and where an executed agreement exists it governs our use and disclosure of PHI. This page is not a Business Associate Agreement, and nothing here should be read as a claim that Scenario One holds a HIPAA certification — no such certification exists for any vendor. Agencies should confirm the agreements they need are in place before entering PHI, and should enter only the minimum necessary patient information.

Patients and staff whose information appears in the platform should direct requests about that information to the Agency that entered it; we will refer such requests to the Agency and assist it in responding.

6. Security

We maintain administrative, physical, and technical safeguards appropriate to the service, including authenticated access, role-based permissions, logical separation of each Agency's data, encryption in transit, encryption at rest as provided by our cloud infrastructure, and activity logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Agencies are responsible for the parts of security within their control, including credential hygiene, device security, and promptly removing access for departing users.

7. Data Retention

We retain information for as long as the Agency maintains an active account and as needed to provide the service, and afterwards only as required to comply with legal obligations, resolve disputes, and enforce our agreements. On termination, an Agency may request an export of its data within thirty (30) days; after that window the data is deleted in accordance with our retention practices and any executed Business Associate Agreement. Backups and logs may persist for a limited additional period before being overwritten.

8. Your Rights and Choices

Depending on your role and jurisdiction, you may have the right to request access to, correction of, deletion of, or a copy of your personal information, or to object to or restrict certain processing. Agency administrators manage user accounts, roles, and access within the platform, and can add or remove users directly. Because most information in the platform belongs to an Agency, we generally act on the Agency's instructions and will forward requests we receive to the relevant Agency. To make a request directly to us, contact team@getscenarioone.com. We do not use your information for automated decision-making that produces legal effects, and we do not send marketing email to platform users without a business relationship or their consent.

9. Cookies and Similar Technologies

We use strictly necessary cookies and similar browser storage to keep you signed in and to maintain session state. Our infrastructure and analytics providers may set their own identifiers for security and performance measurement. You can control cookies through your browser, but disabling necessary cookies will prevent you from signing in.

10. International Transfers

We and our providers operate in the United States, and information may be processed and stored there or in other countries where our providers maintain facilities. Where required, we rely on appropriate safeguards for such transfers.

11. Children's Privacy

The platform is intended for use by adult workforce members of healthcare organizations and is not directed to children. We do not knowingly collect personal information from children under 13 through our website or account signup. Note that an Agency may enter records about pediatric patients as part of its care documentation; that information is provided and controlled by the Agency in its capacity as a healthcare provider, and is handled as described in Section 5. If you believe a child has created an account with us, contact team@getscenarioone.com and we will delete it.

12. AI Processing

Generating documents, plans, assessments, and training feedback involves sending the relevant content — which may include patient information the Agency entered — to the AI providers listed in Section 4 for processing. Output is a draft and must be reviewed and approved by a qualified person at the Agency before use; it may contain errors and it does not establish compliance with any regulatory requirement. See our Terms of Service for details.

13. Changes to This Policy

We may update this policy from time to time. When we do, we will revise the "last updated" date above and, for material changes, notify Agency administrators by email or through the platform before the change takes effect where practicable. Continued use of the service after an update takes effect constitutes acceptance of the revised policy.

14. Contact

Questions about this policy or our privacy practices? Email team@getscenarioone.com, write to ScenarioOne, Inc., or reach us through our contact page.