Privacy Policy
Effective 2026-09-03. Covers engine.geoliquefy.com only.
What this covers
GeoLiquefy LLC ("GeoLiquefy", "we", "us") operates the Liquefaction Hazard Engine at engine.geoliquefy.com (the Engine). This policy describes what the Engine collects when you sign in and run a screening, how it is used, and how you can see or remove it. It does not cover geoliquefy.com, the company's marketing site, which has its own privacy policy.
Your account
Sign-in is handled by our authentication provider, Clerk. We do not store your password; Clerk verifies your identity and hands the Engine a signed token. The Engine keeps a one-way hash of your account identifier, not the identifier itself, and uses that hash to scope every read, write, and delete to your own data. Your email address, read from that token, is checked against two short internal lists: complimentary access grants and operator accounts. If your email is on one of those lists, because we added it, it stays on that list as configuration until we remove it; it is not otherwise stored by the Engine.
What a screening run saves
By default, when you run a screening while signed in, the Engine saves a record of that run: the latitude and longitude if you gave a location, a hash derived from that location, an optional site label you typed, the parameters you entered, the risk label the screening produced, and hashes and version numbers that let the run be checked for tampering later. If you do not give a location, the run is still saved, but it is not grouped into a site.
Saving is on by default because it is what lets your sites build a history across repeat screenings. You can turn this off only in the sense that GeoLiquefy can disable it operationally; there is no per-run toggle today.
From the Engine, at any time, you can:
- See every site you have screened, most recent first
- Export every run record held for you, as a single file
- Delete every run record held for you, permanently
A delete is a real removal of the stored records, not a soft flag. Once you confirm it, the run records cannot be recovered.
Screening certificates are the one exception to delete
If you mint a screening certificate from a run, that certificate is kept even after you delete the run it was minted from. A certificate is meant to be handed to a third party, such as a reviewer, lender, or insurer, who needs to be able to verify it later; a certificate that could quietly stop verifying after you delete the run behind it would not be a trustworthy certificate. Certificates you have minted are listed in your data export, and the response to a delete request tells you how many were kept.
A certificate carries: content hashes of the run's inputs and output, engine and dataset version numbers, the risk label, the site label you typed, the parameters you entered, and, if you gave a location, a hash derived from it. It does not carry your raw latitude and longitude. The public page anyone can use to verify a certificate id shows even less: it confirms whether the certificate is genuine and states only that it was tied to some location, never which one, and never your site label or your parameters.
The AI memo
When you generate a memo, the parameters and case-history matches for that run are sent to Anthropic's Claude model to draft the memo text. Anthropic processes that request under its commercial API terms: it does not use API inputs or outputs to train its models, and it may retain them for a limited period for safety and abuse monitoring, after which they are deleted. GeoLiquefy sends the run's parameters and matched case-history rows, not your account identity. GeoLiquefy does not use your inputs to train any model.
What we do not collect from a screening run
We do not ask for your name, phone number, or physical address to run a screening. We do not sell, rent, or trade the data described above.
Aggregate usage counts
The Engine separately keeps day-by-day counts of a small number of account-level events (for example, how many signed-in visitors were shown the subscription wall). These counts are totals only: no account identifier, email, or per-user detail is stored alongside them.
Where data is stored
Run records and certificates are stored on Cloudflare R2, and the Engine runs on Fly.io. A run record or certificate is kept until you delete it or close your account; there is no automatic expiry today. If GeoLiquefy introduces a retention limit, this page will say what it is before it applies.
Your rights
Regardless of where you live, you can export or delete your own run records from the Engine at any time, without contacting us. For anything not covered by those two controls, including certificates, email contact@geoliquefy.com and we will respond within 30 days. If you are in the European Union, the United Kingdom, or California, you have additional statutory rights (access, correction, deletion, portability, and objection); the same address reaches us for any of them.
Changes to this policy
We may update this policy from time to time. The effective date at the top reflects the most recent update.
Contact
GeoLiquefy LLC, 30 N Gould St Ste R, Sheridan, Wyoming 82801, United States. contact@geoliquefy.com
Liquefaction screening against NGL case histories. GeoLiquefy LLC is independent and not affiliated with the NGL project. See the Terms of Use and the FAQ.