Effective date: August 29, 2026 · Last updated: September 5, 2026

1. Scope and who we are

ChemLevel is chemical inventory, reorder forecasting, and procurement software for water treatment, wastewater, pool and spa, and industrial facilities. This policy explains what we collect, why, who we share it with, and what you can do about it. It covers the ChemLevel marketing website at chemlevel.com, the ChemLevel web application at app.chemlevel.com (including when installed to a phone or tablet home screen), and any ChemLevel mobile application we publish.

The controller of personal information described in this policy is Henry Labs LLC, a Texas limited liability company doing business as ChemLevel, of 5900 Balcones Drive STE 100, Austin, TX 78731 (“ChemLevel,” “we,” “us”). You can reach us at info@chemlevel.com.

ChemLevel is sold to organizations, not to individuals. When your employer subscribes, that organization decides who is invited, what is recorded, and how long it stays. For operational data logged inside the product, your organization is the controller and ChemLevel acts as its processor; we are the controller for account, billing, support, and website data. Where the two roles differ, we say so below.

2. The demo, and why it collects nothing

The “Try a demo” option on app.chemlevel.com generates a fictional treatment plant entirely inside your browser. The sample sites, chemicals, readings, orders, and Safety Data Sheets are produced on your own device from code that ships with the application. None of it is transmitted to us, stored on our servers, or associated with you.

Resetting or exiting the demo clears that data from your browser. If you later create a real organization, the demo data is discarded rather than imported. The only information we receive from a demo session is the ordinary web server request data described under Technical and device data.

3. Information we collect

Account and organization data

When an organization signs up we collect the information needed to create accounts and control access: full name, work email address, organization name, site names and physical addresses, each member’s role (operator or supervisor), whether they hold account administrator access, which sites they are assigned to, and per-member permissions such as whether that person may view budget and spend figures. We also record account state — invitation status, when a member joined, and whether their access is active or revoked.

Authentication data

Passwords for cloud accounts are handled by our authentication provider and are stored as salted hashes; we never see or store your password in readable form. ChemLevel additionally supports a device-level PIN and, where your device offers it, biometric unlock. Your PIN is stored only as a hash on the device that set it and is never transmitted to us. Biometric matching happens entirely on your device through the operating system; we receive no fingerprint, face, or other biometric data at any time.

Operational data you log

This is the core of the product and it belongs to your organization: tank and cylinder rack configuration (capacity, shape, dimensions, gauge units, safety stock, supplier lead time, reorder thresholds), tank level readings, per-cylinder weigh-ins, usage logs with shift and operator attribution, order requests and their status, delivery records with quantities and costs, past delivery dates and quantities that you paste in from your own records, unit costs and cost basis, vendor names and email addresses, annual budget figures, and free-text notes your team enters. Each entry is attributed to the member who recorded it and timestamped in the site’s own time zone.

Documents you upload

If you attach a Safety Data Sheet to a chemical, we store that PDF so any member of your organization can reach it from any device. Files are held in a private storage bucket, restricted to PDF format and a 25 MB size limit, and are served only through short-lived signed links generated at the moment someone opens one — so a link cannot be reused after that person’s access is revoked. Uploading a replacement overwrites the file it supersedes; no version history is retained, because an outdated safety document is a liability rather than a record worth keeping.

Payment information

Subscriptions are billed through Stripe. Card numbers, expiry dates, and security codes are collected by Stripe directly and never reach our servers; we cannot see full card numbers. We receive and store only what we need to administer the subscription: plan and site count, subscription status, trial and renewal dates, the last four digits and card brand as Stripe reports them, and billing contact details.

Communications

If you email us, use the contact form on this website, or reply to a billing notice, we receive your name, email address, and whatever you write, and we keep it so we can respond and maintain a support history.

Technical and device data

Like any web service, our infrastructure automatically logs standard request data: IP address, browser and operating system, device type, referring page, and timestamps. We use it for security, abuse prevention, and diagnosing faults. We do not operate third-party advertising or cross-site tracking on this website or in the application.

The account creation, sign-in and password-reset screens additionally load a bot check from Cloudflare (Turnstile), which examines technical signals from your browser to tell a person from an automated script. It exists to stop scripted account creation and credential stuffing. It is not used to identify you, it does not follow you between sites, and it receives none of your plant, account or billing data.

Information stored on your device

ChemLevel is built to work offline in a plant with no signal, so a copy of your organization’s operational data, your display preferences, your forecast settings, and the roster of accounts unlocked on that device is held in the browser’s local storage or the app’s local database. Changes made offline queue on the device and sync when a connection returns. This local copy stays on your device and is cleared when you sign out of the account, exit the demo, or clear the site’s data.

What we do not collect

We do not collect precise geolocation, contacts, photos, microphone or camera input, health data, biometric identifiers, government identifiers, or advertising identifiers. We do not build advertising profiles and we do not use your operational data to train machine-learning models.

4. Where the information comes from

  • From you — what you type into the application, upload, or send us.
  • From your organization’s administrators — your name, work email, role, and permissions, when an administrator invites you.
  • From your device automatically — technical and request data.
  • From Stripe — subscription status, payment outcomes, and card metadata such as brand and last four digits.

We do not buy personal information, and we do not enrich your data from data brokers or public sources.

5. How we use information, and our legal bases

Where the EU or UK GDPR applies, the legal basis for each purpose is given in brackets.

  • Providing the service — creating accounts, authenticating, storing readings and orders, calculating forecasts, generating vendor order emails, and serving your uploaded documents. [Performance of a contract]
  • Keeping the service working — syncing devices, resolving conflicts, diagnosing faults, restoring from backups. [Legitimate interests: operating a reliable service]
  • Alerting your team — producing reorder and stale-reading notifications on your device from your own data. [Performance of a contract]
  • Billing and account administration — taking payment, sending trial-ending, payment-failure, and pending-deletion notices. [Performance of a contract; legal obligation for tax and accounting records]
  • Support — answering your questions and investigating problems you report. [Performance of a contract; legitimate interests]
  • Security and abuse prevention — detecting unauthorized access, enforcing role permissions, investigating incidents. [Legitimate interests: protecting the service and its users; legal obligation]
  • Improving the product — understanding which features are used and where people get stuck, using aggregated and internal operational information rather than by mining the contents of your readings. [Legitimate interests: improving a product our customers rely on]
  • Complying with law — responding to lawful requests and meeting record-keeping duties. [Legal obligation]

We do not use operational data for advertising, and we do not disclose one customer’s data to another customer.

6. How we share information

We do not sell personal information or operational data, and we do not share it for cross-context behavioral advertising. We disclose information only as follows.

Service providers who process data on our behalf

Each of these is bound by contract to process data only on our instructions and to protect it appropriately.

  • Supabase — database hosting, authentication, and private file storage for uploaded Safety Data Sheets.
  • Vercel — hosting and content delivery for this website and the application.
  • Stripe — subscription billing and payment processing. Stripe is an independent controller of the payment data it collects directly from you; see Stripe’s own privacy policy.
  • Resend — delivery of transactional and billing email, such as invitations and notices that a trial is ending or an account is approaching deletion.
  • Proton Mail — hosting of our own mailboxes, which therefore receives anything you send us, including replies to those notices.
  • Cloudflare — the Turnstile bot check shown when you create an account, sign in, or ask for a password reset. It receives the technical signals needed to tell a person from an automated script, and no plant, account or billing data.
  • Formspree — delivery of the contact form on this website.
  • Sentry — error and crash reporting, so we find out when something breaks for you rather than waiting for you to tell us. See Error reporting below for exactly what is sent.

Within your organization

ChemLevel is a shared workspace. Other members of your organization can see the operational data your team records, including which member logged a reading and when, according to the roles and report permissions your administrators configure. Supervisors can additionally change plant configuration and view budget and spend figures; administrators can manage members, roles and access. Where an organization runs several sites, a member may be assigned to only some of them, in which case the others are not visible to them at all.

Vendors you choose to email

When you choose to email an order, ChemLevel composes a message in your own mail client addressed to the vendor you configured. That message — which typically contains the chemical, quantity, requested delivery date, purchase order number, and delivery address and hours — is sent by you, from your own account, to a recipient you chose. We do not send it and do not receive a copy. An order you log without emailing is not shared with anyone.

Legal and corporate

  • Legal process — where required by valid legal process, or to protect the rights, safety, or property of ChemLevel, our customers, or the public. Where we are lawfully able to, we will notify the affected organization first.
  • Corporate transactions — in a merger, acquisition, financing, or sale of assets, with notice to affected customers and subject to this policy continuing to apply.

7. Cookies, local storage, and tracking

The ChemLevel application uses strictly necessary cookies and browser local storage to keep you signed in, remember your active site and display preferences, hold your offline copy of organization data, and queue changes made without a connection. These are essential; the application cannot work offline without them, and there is no way to switch them off while continuing to use the product. Clearing your browser’s site data removes them, along with any unsynced offline changes.

This marketing website does not use advertising cookies, cross-site trackers, third-party analytics pixels, session-replay tools, or social media tracking widgets. Because we do not run advertising or cross-context tracking anywhere, there is nothing here for a “Do Not Track” or Global Privacy Control signal to disable; we honor those signals by not engaging in the practices they are designed to stop.

The bot check described above runs only on the account creation, sign-in and password-reset screens, and is strictly necessary in the same sense as the cookies above: those screens are open to the internet, and without it they are open to scripts as well. It is not an analytics or advertising tool.

If we add analytics in the future, we will update this policy and, where consent is required, ask for it before setting anything non-essential.

8. Error reporting

When the application hits an unexpected error, it sends a report to Sentry so we can find and fix it. A report contains the error message and type, a stack trace, the app version and platform, the route you were on, and the identifier of your organization — a random identifier, not its name — so we can tell whether a fault affects one customer or everyone.

What a report deliberately does not contain matters more:

  • No screen recording or screenshots. Session replay is switched off, not sampled down, because the screen shows your inventory.
  • No operational data. Readings, usage, orders, deliveries, costs, vendors, and the contents of uploaded documents are never attached.
  • No request bodies or headers, which is where an access token would otherwise travel.
  • No IP-based identification, and no name or email address.
  • No query strings. Web addresses recorded alongside an error are truncated at the “?”, which removes filter values and the short-lived token in a Safety Data Sheet link while keeping enough to identify which request failed.

Error reports are processed by Sentry on our behalf under contract, retained for a limited period for diagnosis, and used for no other purpose.

9. Notifications

ChemLevel can alert you when a chemical is approaching its reorder point, when a cylinder rack is hours from a changeover, or when a chemical has not been checked recently. These alerts are generated on your own device from data already stored there — through the browser’s notification API and service worker on the web, or the operating system’s local notification scheduler in a mobile app. We do not operate a server-side push service, we do not hold push tokens, and no notification content is transmitted through us. You can turn notifications off inside ChemLevel’s settings or revoke the permission in your browser or device settings.

10. Forecasting and automated processing

ChemLevel’s forecasts are arithmetic, not artificial intelligence. The engine computes a time-weighted average of consumption between your recorded readings, projects days until empty and days until a reorder point, and derives a recommended order quantity and an order-by date. Sample Safety Data Sheets in the demo are assembled from fixed templates. Nothing about this involves machine learning, profiling of individuals, or inference about people.

These outputs are decision support for your operators. They produce no legal or similarly significant effect on any individual, and no decision about a person is made automatically. You remain responsible for chemical handling and dosing decisions; see our Terms of Service.

11. Data retention and deletion

We keep operational data for as long as your organization’s subscription is active, because historical readings are exactly what the forecasting depends on — deleting last month’s readings would degrade this month’s predictions.

If a trial expires or a subscription is canceled, the organization’s data is retained for 30 days so it can be recovered if you resubscribe, and is then deleted automatically by a scheduled process. We email the organization’s supervisors and account administrators in advance of that deadline. Deletion covers operational data and any Safety Data Sheets uploaded to the account.

Other retention periods:

  • Account records — deleted with the organization, subject to the 30-day window above. That includes the sign-in itself — name, email address and password — for anyone the deleted organization was their only one. A person who also belongs to another organization keeps their sign-in and their access to that one.
  • Billing and tax records — retained as long as applicable tax and accounting law requires, typically seven years, independently of account deletion.
  • Support correspondence — retained while it remains useful for support history, and reviewed periodically. It outlives the organization it was sent from; once that organization is deleted, what remains is the message itself, no longer linked to an account.
  • Server and security logs — retained for a short period for security and diagnostics, then rotated out.
  • Superseded Safety Data Sheets — deleted at the moment a replacement is uploaded; no prior version is kept.
  • Backups — deleted data may persist briefly in encrypted backups until those backups age out on their ordinary cycle.

Deleting your account

You can do both of these yourself, in the app, under Settings › Leaving ChemLevel:

  • Leave this organization — takes you off the roster. Your name stops appearing on the team list and you lose access to the plant’s records. The plant’s data is not affected, because it belongs to the organization rather than to you. If you are the only supervisor or the only administrator, hand that role to someone else first, or close the account instead.
  • Close this account — ends the organization. Every site, chemical, tank, reading, delivery and budget it holds is deleted 30 days later, along with the account records of everyone on it. Administrators only. If a subscription is still running, cancel it first so billing stops with the account; the app takes you to the billing portal to do that.

The 30 days are deliberate: closing an account deletes a plant’s chemical history, and it should be possible to undo that if it was a mistake. During the window the data is still there and resubscribing restores access. After it, the deletion is permanent and cannot be reversed — see what that covers above.

You can also ask us to delete an organization by contacting us instead, and we will do it for you; see Your rights.

12. Security and incident response

Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Access to customer data is enforced at the database itself through row-level security policies scoped to the organization and to the member’s role, so a request that is not entitled to a record does not receive it — the restriction does not depend on the application asking nicely. Uploaded Safety Data Sheets live in a private bucket reachable only through short-lived signed links, never a durable public URL. Administrative access by ChemLevel staff is limited to what is needed to operate and support the service.

If we become aware of a personal data breach affecting your information, we will notify the affected organization’s administrators without undue delay and, where the law requires it, notify the relevant supervisory authority — within 72 hours of becoming aware where the GDPR applies — and affected individuals where the breach is likely to present a high risk to them. Our notice will describe what happened, what data was involved, what we are doing about it, and what you can do.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password and device PIN confidential, for using a device you trust, and for telling us promptly at info@chemlevel.com if you believe an account has been compromised.

13. International transfers

ChemLevel is operated from the United States. Your organization’s data at rest — the database, authentication records, and uploaded Safety Data Sheets — is stored and processed in the United States, in our hosting provider’s US East region. Access is in any case restricted to IP addresses within the United States, for both the application and this website, so ordinary use from abroad is refused rather than transferred. Where a request does reach us from outside the country, that information is transferred to and processed in the United States, where privacy laws may differ from those in your country.

One exception is worth stating plainly: the application and this website are delivered as static files through a global content delivery network, so the request that loads a page may be served by an edge location near you rather than one in the United States, and standard request data such as your IP address may be logged there. No account data, operational data, or uploaded document is stored or processed at those edge locations.

Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) together with supplementary measures appropriate to the transfer. You can request a copy of the relevant safeguards at info@chemlevel.com. [IF OFFERING SERVICES TO EU/UK DATA SUBJECTS, INSERT ARTICLE 27 REPRESENTATIVE DETAILS HERE.]

14. Your rights (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to request access to your personal information; correction of inaccurate information; erasure; restriction of processing; portability of information you provided to us; and objection to processing carried out on the basis of legitimate interests, including at any time where the processing is for direct marketing. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

Because most operational data belongs to your organization rather than to us, requests about it are generally handled through your organization’s administrators, and we will refer you to them or assist them in responding. Requests about your account, billing, or correspondence with us can be made to us directly.

Contact info@chemlevel.com to exercise any of these rights. We will respond within one month, extendable by two further months for complex requests, and we will tell you if we need longer. We do not charge a fee unless a request is manifestly unfounded or excessive. You also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concern first.

15. Your rights (US state privacy laws)

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to know what personal information we collect and how we use and disclose it; to access a copy of it; to correct inaccuracies; to delete it; to opt out of sale, sharing for cross-context behavioral advertising, and profiling with legal or similarly significant effects; and not to be discriminated against for exercising any of these rights.

We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes that would require an opt-out under the CPRA. We do not engage in profiling that produces legal or similarly significant effects.

In the twelve months before the date of this policy, we collected the categories of information described in Information we collect — identifiers, customer records, commercial information, internet activity, and professional information — for the business purposes described in How we use information, from the sources in Where the information comes from, and disclosed them for business purposes to the service providers listed in How we share information.

To make a request, email info@chemlevel.com. We will verify your request by matching the information you provide against our records, and may ask for additional confirmation for sensitive requests. You may use an authorized agent, who must provide proof of authorization. If we decline a request you may appeal by replying to our decision; we will respond to an appeal in writing within the period your state’s law allows.

16. Children’s privacy

ChemLevel is workplace software sold to organizations and is not directed to children. The service is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact info@chemlevel.com and we will delete it.

This website and the application contain links to sites we do not control — supplier websites, regulatory resources, our payment processor’s hosted pages. When you choose to email an order, ChemLevel hands a pre-composed message to your own email client. When you open an uploaded Safety Data Sheet, your browser or device opens the file. This policy does not cover those third parties; their own privacy policies do.

18. Changes to this policy

We may update this policy as the product changes or the law does. When we do, we will revise the “Last updated” date above. If a change materially affects how we handle personal information, we will give active customers reasonable advance notice by email or through the application before it takes effect. Continuing to use ChemLevel after a change takes effect means you accept the updated policy.

19. Contact us

Questions, requests, or complaints about privacy go to info@chemlevel.com, or by post to Henry Labs LLC, 5900 Balcones Drive STE 100, Austin, TX 78731. A message reaches the people who build and operate ChemLevel, not a ticket queue.