PASTOR
With every worker · Every shift · Every moment
← Back to PASTOR
Free · Anonymous · Not connected to your employer · Available 24 hours
THE SHORT VERSION — PLAIN LANGUAGE
🔒
We do not collect your name, email, phone number, or any information that identifies you.
No recopilamos tu nombre, correo, teléfono ni ninguna información que te identifique.
💬
Your conversation is processed by an AI service to write each answer. PASTOR never stores it — no copy, no archive, no backup.
Tu conversación no se guarda en nuestros servidores. Solo existe en tu dispositivo.
🚫
We never share anything with your employer, immigration authorities, law enforcement, or third parties for advertising.
Nunca compartimos nada con tu empleador, autoridades migratorias, policía ni terceros.
📊
We collect anonymous usage data — like what topics workers ask about and what language they use — to improve the platform. This data cannot be traced back to you.
Recopilamos datos anónimos de uso para mejorar la plataforma. No se pueden rastrear hasta ti.

1. Who we are

Quiénes somos

PASTOR Safety LLC is a Texas-registered limited liability company providing free anonymous worker rights guidance to construction and healthcare workers. Our platform is available at pastorsafety.com.

We are not a law firm, and PASTOR is not a substitute for the advice of an attorney. We are not affiliated with any employer, government agency, or immigration authority. We are not connected to your workplace in any way.

PASTOR Safety LLC es una empresa registrada en Texas que proporciona orientación gratuita y anónima sobre derechos laborales. No somos un bufete de abogados ni estamos afiliados a ningún empleador, agencia gubernamental ni autoridad migratoria.

2. What we do not collect

Lo que NO recopilamos

PASTOR is designed from the ground up to be anonymous. We do not collect or store:

Your name, email address, phone number, home address, Social Security number, immigration status, or any other personally identifying information. We never ask for these. We do not want them.

The content of your conversation. What you type to PASTOR is processed in real time to generate a response and is not saved to our servers in any form that can be retrieved or identified.

Your IP address in identifiable form. We use privacy-preserving analytics that anonymize IP addresses before any data is stored.

PASTOR está diseñado para ser completamente anónimo. No recopilamos tu nombre, correo, teléfono, número de Seguro Social, estatus migratorio ni ninguna información personal. El contenido de tu conversación no se guarda en nuestros servidores.

3. What we do collect

Lo que SÍ recopilamos

We collect anonymous usage data to understand how workers use PASTOR and to improve the platform. This includes:

— What industry a worker selected (construction or healthcare) — not who they are, just what category.
— What general topic category was discussed (safety, harassment, wages, etc.) — not the specific words typed.
— What language was used (English or Spanish).
— What time of day the session occurred (morning, afternoon, night) — not the exact timestamp.
— What type of device was used (mobile or desktop).
— Whether a language switch occurred during the session.
— The general area a session came from — the state, and sometimes the city.
— If you arrived through a partner organization’s link, which organization that was — not which worker.
— Whether the situation appeared urgent, and whether it involved fear, pressure from a supervisor, an injury, or possible retaliation — recorded as yes-or-no flags only, never as anything you typed.
— Whether PASTOR was able to find a rule that matched. We track our own gaps so we can fix them.
— How many messages were exchanged — a count only, never the messages themselves. It tells us whether workers are getting an answer quickly or having to dig for it.
— Which version of PASTOR answered. When we change how PASTOR responds, we need to be able to tell whether the change actually helped.

What stays on your phone, and for how long. Three things are kept in your own browser, on your own device. None of it is ever sent to us or to anyone else, and you can delete all of it at any time with the trash button in the chat.

— Your conversation, for 24 hours. So that closing the app, refreshing the page, or stepping away does not lose your place. After 24 hours it is deleted from your device automatically.
— A list of dates and topics, for 30 days. Just the date, the time, and a short label like “unpaid wages.” Never what you typed, never a name, never a workplace. This is so PASTOR can show you the order things happened in, which is often the thing you cannot remember later.
— Basic settings, for 7 days. Your language and general topic, so PASTOR does not start from zero every time.

You can copy your dates to your phone’s clipboard at any time and keep them wherever you want. We never see that copy.

Lo que se queda en tu teléfono: tu conversación por 24 horas, una lista de fechas y temas por 30 días (solo la fecha, la hora y una etiqueta corta — nunca lo que escribiste, ni nombres, ni lugares de trabajo), y tus ajustes básicos por 7 días. Nada de esto se nos envía. Puedes borrarlo todo cuando quieras con el botón de basura en el chat.

About location, plainly. Your device’s IP address is used to work out roughly what state or city a session came from, and then the IP address is discarded and never stored. We do not know your address, your street, or your worksite. We keep this because where workers are asking matters: heat questions rising across Texas in July is the kind of thing that can change a rule.

Nothing here can identify you, and none of it is connected to what you typed. Any figure we publish or share follows the ten-worker minimum in Section 7 — if fewer than ten workers are behind a number, it is not reported at all, and that applies to places as much as topics. We do not publish city, topic, and time together.

Recopilamos datos anónimos de uso: industria seleccionada, tema general, idioma, hora del día, tipo de dispositivo, y el área general de donde vino la sesión — el estado, y a veces la ciudad.

Sobre la ubicación, claramente: la dirección IP de tu dispositivo se usa para saber aproximadamente de qué estado o ciudad vino la sesión, y luego esa dirección IP se descarta y nunca se guarda. No sabemos tu domicilio, tu calle, ni tu sitio de trabajo. Guardamos esto porque importa dónde están preguntando los trabajadores. Ninguna cifra que publiquemos representa a menos de diez trabajadores.

4. Session memory

Memoria de sesión

PASTOR uses your device's local storage to remember basic session context — such as your language preference and industry — so that if you need to step away and come back, you do not have to start completely over.

This data never leaves your device. It is stored only in your browser's local storage, expires automatically after 7 days, and is deleted when you clear your browser cookies or data. PASTOR's servers never see or store this information.

You can clear this data at any time by clearing your browser's cookies and site data.

PASTOR usa el almacenamiento local de tu dispositivo para recordar tu preferencia de idioma e industria entre visitas. Esta información nunca sale de tu dispositivo, expira en 7 días, y se elimina cuando limpias las cookies de tu navegador.

5. Who we never share data with

Con quién NUNCA compartimos datos

We will never share any information — anonymous or otherwise — with:

— Your employer or any employer, HR department, or management team.
— Immigration authorities including ICE, CBP, or any other federal or state immigration agency.
— Law enforcement without a lawful court order requiring us to do so.
— Advertisers or third parties for commercial or marketing purposes.
— Any organization that could use it to identify or harm a worker.

Nunca compartiremos ninguna información con tu empleador, autoridades migratorias (ICE, CBP), fuerzas del orden sin orden judicial, anunciantes ni ninguna organización que pueda usarla para identificar o perjudicar a un trabajador.

6. Legal demands

Solicitudes legales

If PASTOR receives a subpoena, court order, or other legal demand, we will follow the law. But what we can produce is limited by what exists.

We cannot produce your conversation, because we do not keep it. It is not stored on our servers, not archived, and not backed up. There is no record to hand over — not to your employer, not to immigration authorities, not to a court. This is not a promise about our intentions. It is a fact about how PASTOR is built.

Your conversation is processed in real time by our AI provider in order to generate a response, as described in Section 10. PASTOR does not store it at any point.

If we ever receive a legal demand that would require us to change how PASTOR handles worker data, we will say so on this page rather than quietly comply.

Si PASTOR recibe una orden judicial o solicitud legal, cumpliremos con la ley. Pero no podemos entregar tu conversación porque no la guardamos. No existe en nuestros servidores. No hay nada que entregar — ni a tu empleador, ni a inmigración, ni a una corte.

7. Aggregate reporting and the minimum group rule

Reportes agregados y la regla del grupo mínimo

The anonymous usage data described in Section 3 is used to produce aggregate statistics — how many sessions occurred, which topic categories come up most often, and what share of workers use Spanish.

No number PASTOR publishes or shares will ever represent fewer than 10 workers. Small numbers identify people. If three workers at one site raise the same concern, that number can tell a supervisor which crew and possibly which person. Any group smaller than 10 is not reported at all — not rounded, not estimated, not published.

PASTOR does not collect employer names and does not build profiles of individual employers based on what workers report.

Ningún número que PASTOR publique representará jamás a menos de 10 trabajadores. Los números pequeños identifican personas. Cualquier grupo menor de 10 no se reporta — ni redondeado, ni estimado, ni publicado. PASTOR no recopila nombres de empleadores.

8. If an organization sponsors PASTOR

Si una organización patrocina PASTOR

An employer, union, or community organization may sponsor PASTOR for its workers. If that happens, these rules do not change.

What a sponsoring organization receives: aggregate counts only — session volume, topic categories, and language breakdown — subject to the same 10-worker minimum described in Section 7.

What a sponsoring organization never receives: any conversation, any part of a conversation, any individual session, any worker’s identity, or any number small enough to point at a person. There are no exceptions and no paid tier that unlocks more.

Una organización puede patrocinar PASTOR para sus trabajadores. Solo recibe conteos agregados — volumen de sesiones, categorías de temas, idioma — sujetos al mínimo de 10 trabajadores. Nunca recibe conversaciones, sesiones individuales, ni la identidad de ningún trabajador. Sin excepciones.

9. Published findings and advocacy

Hallazgos publicados y abogacía

PASTOR may eventually publish aggregate findings — for example, what topics workers in a given state are asking about, and how that changes over time. The purpose is to give advocacy organizations, researchers, and public agencies evidence about problems workers are not reporting through official channels.

If that happens, these rules apply:

— Published figures are pooled across all PASTOR users, never filtered to a single organization, employer, city, or worksite.
— The minimum in Section 7 applies to every published figure.
— No employer is ever named. No worksite is ever named. No worker is ever named.
— Every published figure will state plainly that it describes what people who used PASTOR asked about — not a survey of all workers, and not a claim about any specific workplace.

Nothing you type is ever published. Findings are counts of topic categories, not content.

PASTOR podría publicar hallazgos agregados — por ejemplo, qué temas preguntan los trabajadores en un estado. Las cifras siempre se agrupan entre todos los usuarios, nunca filtradas a una organización, empleador o sitio. Nunca se nombra a un empleador, a un lugar de trabajo, ni a un trabajador. Nada de lo que escribes se publica jamás.

10. Third party services

Servicios de terceros

PASTOR uses the following third-party services to operate:

Anthropic (Claude API) — processes your conversation in real time to generate responses. Anthropic's privacy policy governs how they handle API data. Conversations are not used to train Anthropic's models under our API agreement.

PostHog — anonymous analytics platform. Configured with person_profiles disabled, meaning no user profiles are created. Only the anonymous event data described in Section 3 is collected.

Render — hosts a small relay server that passes your message to the AI provider and returns the answer. It exists so our API key is never exposed in your browser. The relay does not write your conversation to any log or file — it forwards the request and returns the response. Its source code is public at github.com/teddy3535/claude-proxy.

One thing the relay does do, and you should know it. To stop an automated script from running up the bill and shutting PASTOR down for everyone, the relay counts how many requests come from a given connection in a ten-minute window. It does that by turning the IP address into a one-way hash — a scrambled value that cannot be turned back into an address — holding it in memory only, never writing it to disk or a log, and discarding it after ten minutes. The limit is set high on purpose, because workers on the same job site or at a community center often share one connection and none of them should be locked out.

Netlify — hosts the platform. Standard server logs may be generated as part of normal web hosting operations.

EmailJS — used only when a worker voluntarily taps the "Report a problem" button. No worker information is included in these reports — only technical metadata like device type and session context.

PASTOR utiliza Render (un servidor de relevo que pasa tu mensaje al proveedor de IA; no guarda nada en ningún registro), Anthropic (Claude API) para procesar conversaciones, PostHog para analíticas anónimas, Netlify para alojar la plataforma, y EmailJS para reportes técnicos voluntarios. Ninguno de estos servicios recibe información personal de los trabajadores.

11. Your rights

Tus derechos

Because PASTOR does not collect personally identifiable information, there is no personal data profile to access, correct, or delete. Your anonymity is built into the architecture of the platform — not just promised in a policy.

If you have questions about your data or this policy, you can contact us at the email below. We will respond within 5 business days.

Como PASTOR no recopila información personal identificable, no existe un perfil de datos que acceder, corregir o eliminar. Tu anonimato está integrado en la arquitectura de la plataforma.

12. Changes to this policy

Cambios a esta política

If we make material changes to this privacy policy we will update the effective date at the top of this page. We will not reduce your privacy protections without clear notice. Continued use of PASTOR after any changes constitutes acceptance of the updated policy.

Si realizamos cambios importantes a esta política, actualizaremos la fecha efectiva en la parte superior de esta página. No reduciremos tus protecciones de privacidad sin un aviso claro.

QUESTIONS ABOUT THIS POLICY

If you have questions about how PASTOR handles your data or this privacy policy, contact us. You do not need to provide your name.

Si tienes preguntas sobre esta política de privacidad, contáctanos. No necesitas dar tu nombre.

feedback@pastorsafety.com