Privacy Policy

Your information, handled with care.

Survival is mandatory. Living is contextual. Thriving is personal.

Last updated: June 30, 2026

This page is maintained by FHSE to explain what information we collect when you use fhse.world and related subdomains (the "Service"), how we use it, who can see it, and the choices you have. FHSE is a community-driven survival knowledge network. This is plain-language policy text, not legal advice.

Who runs this

FHSE ("we", "us") operates this Service as a public, community-led initiative. For privacy questions, contact us through the Support page.

What we collect

  • Account information: email address, display name, and authentication details when you sign up (including via Google if you choose).
  • Profile and participation data: region, role (volunteer, facilitator, verifier, etc.), self-checks, checklist confirmations, learning requests, skill verification requests, and FHSK card data you generate.
  • Identity verification data (optional): if you choose to verify your identity, you submit a photo of a government-issued ID and a live selfie taken in-session. See "Identity verification" below for how this is handled.
  • Technical data: standard server logs (IP address, user agent, timestamps) needed to operate and secure the Service.

How we use your information

  • To create and operate your account.
  • To run FHSE features: checklists, learning support, volunteer coordination, verification workflows, and public profile cards you opt into.
  • To protect the Service against abuse, fraud, and security threats.
  • To comply with legal obligations that apply to us.

We do not sell your personal data. We do not run third-party advertising on the Service.

Identity verification

Identity verification is optional. If you submit it, you provide:

  • A photo of a government-issued ID.
  • A live selfie captured in-session for liveness checking.

After a reviewer makes a decision on your request:

  • The live selfie is deleted from our storage. It is used only to confirm liveness at the time of review.
  • The government ID image and its metadata are retained for security, anti-fraud, and audit purposes. We keep this because identity claims on FHSE can affect trust signals other people rely on, and we may need to demonstrate that a verification decision was made against a real document.

Access to retained ID images is restricted to authorised reviewers, administrators, and the account owner. You can request deletion of your retained ID document at any time via Support; we will delete it unless we are required to retain it to comply with a legal obligation or to resolve an active dispute, and we will tell you which applies.

Who can see your data

  • You can see your own account, profile, submissions, and FHSK card.
  • Authorised FHSE roles (admins, managers, verifiers, facilitators) can see the data their role requires — for example, a verifier can see verification requests routed to them. Access is enforced by row-level security in our database.
  • The public can see only the parts of your profile and FHSK card that you explicitly publish (for example, a shared card link).
  • Our infrastructure providers process data on our behalf to host the Service (database, authentication, storage, email delivery, hosting/CDN). They act as processors and are bound by their own contractual terms.

Cookies and similar technologies

We use cookies and local storage that are necessary to keep you signed in and to operate the Service. We do not use advertising or cross-site tracking cookies.

Data retention

  • Account, profile, and participation data is retained while your account is active.
  • Live selfies submitted for identity verification are deleted after the verification decision is recorded.
  • Government ID images submitted for identity verification are retained for security and audit purposes and removed on request unless we are required to keep them.
  • Server logs are kept for a limited period needed to operate and secure the Service.

Your choices and rights

Depending on where you live (for example under the EU/UK GDPR, California CCPA/CPRA, Brazil LGPD, and similar laws), you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated personal data, subject to the retention exceptions above.
  • Object to or restrict certain processing.
  • Withdraw consent for optional features like ID verification.
  • Lodge a complaint with your local data protection authority.

To exercise any of these, contact us via Support.

International transfers

FHSE is a global initiative. Your data may be processed in countries other than the one you live in, including by our infrastructure providers. We rely on their contractual safeguards for international transfers.

Under-18 learners (Competence Card witnessed track)

FHSE is open to learners of every age. Identity verification using a government ID and a live selfie is adults-only (18+); under-18 learners use a separate witnessed track to earn their FHSE Competence Card.

For under-18 accounts:

  • No government ID is collected. No selfie or other biometric image is collected from the minor at any point.
  • We collect the learner's date of birth, display name, country and region, and their self-recorded FHSK progress — the same minimal account data as for any FHSE account.
  • Verifiable parental / guardian consent is required. The account holder records the guardian's name, email, relationship and consent method; we then email the named guardian a one-time link to confirm consent before any witnessing can be queued.
  • An approved FHSE Volunteer, Facilitator, or Verifier personally witnesses the learner demonstrating their FHSK skills, in person, and records an attestation (their identity, the location, and notes about what they observed). No images of the minor are taken as part of this process.
  • Guardians can withdraw consent at any time by emailing privacy@fhse.world. On withdrawal we revoke the Competence Card attestation and delete personal data in line with the retention rules below.

Children under the UK GDPR Article 8 age threshold (13 in the UK): the account must be created and operated with explicit parental / guardian involvement. We do not process under-13 accounts on the basis of the child's own consent.

We do not direct marketing at any user. The Service is not directed to children under 13 for marketing purposes.

Transactional emails & unsubscribe

FHSE sends transactional emails — such as the guardian consent confirmation, account notices, and witness updates — from notify.fhse.world. These emails are required for the Service to operate. We do not send marketing or newsletter emails. Each transactional email includes a one-click unsubscribe link that adds your address to our suppression list.

Security

We use row-level security, role-based access controls, encrypted transport (HTTPS), and audited storage to protect your data. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected users as required by law.

Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced in-app or by email, and the "Last updated" date at the top of this page will change.