Data & privacy

Where your data goes, and what happens to it there.

We want you to understand this before a project starts. This page explains who may process your information, where it is stored, how it is protected, and what we have not completed yet.

Is our data used to train AI models?

No. We use the business versions of AI services. Their terms say customer inputs and outputs are not used to train public models. We also never use one client's information to improve another client's system.

Where is our information stored?

Most project data is stored in a managed database on Supabase, and the software runs on Google Cloud. Both are in the United States. A request may also be processed by the AI provider named for your project. The complete list is below.

Can we get all of it deleted?

Yes. We have a written process that covers every place your information may be stored. We run it when you ask and tell you what was deleted from each location.

How it works

What happens when the software handles a task

Here is the process in plain language.

  1. 01

    Every request is tied to your company

    Before the software reads or writes anything, it identifies the company making the request. Security rules in the database prevent one client from seeing another client's records, even if the application has a bug.

  2. 02

    Regular calculations use regular code

    Counting, filtering, and calculations run as tested code against your data. We use AI for work such as reading a document, drafting a summary, or suggesting a category. This keeps AI away from tasks that do not need it.

  3. 03

    The AI never sees your passwords or access keys

    Passwords and access keys never appear in an AI request, answer, or transcript. A secure server uses the key to connect to the approved system and gives the AI only the information needed for the task.

  4. 04

    A person approves anything sent outside your company

    If the software drafts an email, publishes a page, or posts to another system, the change waits for a person to approve it. Reading information and saving approved internal work may happen automatically, and those actions are recorded.

  5. 05

    Technical logs do not copy the content of your work

    The logs record what type of action happened, how long it took, and whether it succeeded. The logging system does not accept fields for the text a person wrote or the answer an AI produced. That content stays in the part of the system that owns it.

Other service providers

The companies that may process your data

The security term is sub-processor. We name each one here, and we will tell you if the list changes.

Anthropic

AI processing

Processes requests and answers for most AI work. We use its business service, not a consumer account.

Google Cloud

Runs the software and stores files and passwords

Runs the services, keeps connected-system passwords in Secret Manager, and stores generated files. Gemini may process audio or images when a project uses those features.

Supabase

Database and user sign-in

Stores project data. Database rules keep each client limited to its own information.

Each provider is covered by its own business terms. We list them so you can review those terms before deciding whether the project may use the service.

Where your information may be stored

We use this list when a client leaves or asks us to delete data. It covers more than the main database.

  • The main database, which holds your records, AI requests and answers, documents, tasks, and security history
  • A separate database for your company, when the project requires one
  • Google Secret Manager, which holds passwords and access keys for systems you connect
  • File storage for documents and reports the software creates
  • Technical logs used to find errors and keep the software running
  • The AI provider that processed the request, under the terms agreed for your project

Your own systems, such as accounting software, a CRM, or email, keep the information they already held. When you disconnect a system, we remove our access through that provider.

Retention

Routine work records are kept long enough for the agreed business use. Security, approval, and policy records may be kept longer. We will give you the exact time periods in writing before work begins.

AI requests and answers
Routine use
System activity
Routine use
Feedback on an answer
Routine use
Approval and policy decisions
Kept longer
Access and security history
Kept longer
Current limits

What we have not completed yet

These details may affect whether we are the right vendor for your company, so we want you to see them before the project begins.

Deletion is manual, not scheduled

The system does not delete old records automatically yet. We delete them when a client asks and follow a written checklist covering every storage location. We have tested that process on a test account.

Most clients share one database, with access rules between them

Most clients use one database. Security rules inside that database limit each company to its own rows. This is not the same as giving every client a physically separate database. If your company requires a separate database, tell us before the project starts so we can set it up that way.

We are not SOC 2 certified

We are a small firm and have not completed a SOC 2 audit. If your purchasing rules require a SOC 2 report, we are not the right vendor today. We will tell you that on the first call.

Next step

Send us your security questions early.

If your requirements are stricter than what is written here, tell us on the first call. We may be able to set up a separate database or stronger controls. If we cannot meet the requirement, we will tell you before you spend time on a contract.