Early access open — 10 free slots for 3 months.

    Privacy Policy

    Last updated: April 2026

    1. Information We Collect

    We collect the following data when you use the ThermalReports platform:


  1. Registration data: full name, email address, company name and role.
  2. Thermal inspection data: thermal photographs (FLIR, HIKMICRO and other cameras), generated PDF reports, inspected equipment locations, recorded temperatures and anomaly classifications.
  3. Usage data: IP address, browser type, pages visited and access times.
  4. 2. Legal Basis for Processing

    We process your personal data based on:


  5. Consent: when you create an account and accept this policy.
  6. Contract performance: to provide the services contracted on the platform.
  7. Legitimate interest: to improve security and service quality.
  8. 3. Data Storage

  9. Files (thermal photos, PDF reports): stored on Backblaze B2 in the United States, with encryption at rest.
  10. Structured data (registrations, inspections, anomalies): stored in a PostgreSQL database via Supabase (self-hosted), on our own infrastructure.
  11. Backups: performed daily with 30-day retention.
  12. 4. Cookies and Local Storage

    We use cookies and local storage for:


  13. Authentication session (app): token in localStorage to keep your session active.
  14. Language preference: stored in localStorage.
  15. Cookie consent (marketing site): stored to honor your banner choice.

  16. On the public website (thermalreports.com), if you accept measurement cookies, we use:


  17. Google Analytics 4 (GA4): aggregated visit statistics (first-party via Google).
  18. Mautic (self-hosted): marketing automation and page tracking as configured on our instance.

  19. If you choose essential cookies only, we do not load GA4 or Mautic in your browser. See the Cookie Policy for purposes and retention.

    5. Data Sharing

    We do not sell, rent or share your personal data with third parties for commercial purposes. We share data only with essential services for platform operation:


  20. Cloudflare: CDN and DDoS protection.
  21. Backblaze B2: file storage.
  22. Sentry: error monitoring (anonymized data).

  23. All providers are subject to confidentiality and data processing agreements.

    6. Data Retention

  24. Your data is retained as long as your account is active.
  25. Upon deletion request, your data is removed within 30 days.
  26. Access log data is retained for 6 months for security purposes.
  27. 7. Your Rights

    Under LGPD (Brazil), GDPR (Europe) and CCPA (California), you have the right to:


  28. Access: request a copy of all data we hold about you.
  29. Rectification: request correction of inaccurate or outdated data.
  30. Erasure: request deletion of your personal data.
  31. Portability: receive your data in a structured, machine-readable format.
  32. Withdraw consent: withdraw your consent at any time.

  33. To exercise any of these rights, contact us at privacy@thermalreports.com.

    8. Security

    We employ technical and organizational measures to protect your data, including:


  34. Encryption in transit (TLS/HTTPS) and at rest.
  35. Role-based access control (RBAC).
  36. Automated daily backups.
  37. Continuous security monitoring.
  38. 9. International Data Transfers

    Some data may be stored on servers in the United States (Backblaze B2). We ensure these transfers comply with LGPD and GDPR requirements, with appropriate safeguards in place.

    10. Changes to This Policy

    We may update this Privacy Policy periodically. Significant changes will be communicated by email or platform notice with 30 days advance notice.

    11. Contact — Data Protection Officer (DPO)

    For questions about privacy or data protection:


  39. Email: privacy@thermalreports.com
  40. Company: ThermalReports
  41. Website: thermalreports.com