Where your data goes, and what happens to it there.
We want you to understand this before a project starts. This page explains who may process your information, where it is stored, how it is protected, and what we have not completed yet.
Is our data used to train AI models?
No. We use the business versions of AI services. Their terms say customer inputs and outputs are not used to train public models. We also never use one client's information to improve another client's system.
Where is our information stored?
Most project data is stored in a managed database on Supabase, and the software runs on Google Cloud. Both are in the United States. A request may also be processed by the AI provider named for your project. The complete list is below.
Can we get all of it deleted?
Yes. We have a written process that covers every place your information may be stored. We run it when you ask and tell you what was deleted from each location.
What happens when the software handles a task
Here is the process in plain language.
- 01
Every request is tied to your company
Before the software reads or writes anything, it identifies the company making the request. Security rules in the database prevent one client from seeing another client's records, even if the application has a bug.
- 02
Regular calculations use regular code
Counting, filtering, and calculations run as tested code against your data. We use AI for work such as reading a document, drafting a summary, or suggesting a category. This keeps AI away from tasks that do not need it.
- 03
The AI never sees your passwords or access keys
Passwords and access keys never appear in an AI request, answer, or transcript. A secure server uses the key to connect to the approved system and gives the AI only the information needed for the task.
- 04
A person approves anything sent outside your company
If the software drafts an email, publishes a page, or posts to another system, the change waits for a person to approve it. Reading information and saving approved internal work may happen automatically, and those actions are recorded.
- 05
Technical logs do not copy the content of your work
The logs record what type of action happened, how long it took, and whether it succeeded. The logging system does not accept fields for the text a person wrote or the answer an AI produced. That content stays in the part of the system that owns it.
The companies that may process your data
The security term is sub-processor. We name each one here, and we will tell you if the list changes.
Anthropic
AI processing
Processes requests and answers for most AI work. We use its business service, not a consumer account.
Google Cloud
Runs the software and stores files and passwords
Runs the services, keeps connected-system passwords in Secret Manager, and stores generated files. Gemini may process audio or images when a project uses those features.
Supabase
Database and user sign-in
Stores project data. Database rules keep each client limited to its own information.
Each provider is covered by its own business terms. We list them so you can review those terms before deciding whether the project may use the service.
Where your information may be stored
We use this list when a client leaves or asks us to delete data. It covers more than the main database.
- The main database, which holds your records, AI requests and answers, documents, tasks, and security history
- A separate database for your company, when the project requires one
- Google Secret Manager, which holds passwords and access keys for systems you connect
- File storage for documents and reports the software creates
- Technical logs used to find errors and keep the software running
- The AI provider that processed the request, under the terms agreed for your project
Your own systems, such as accounting software, a CRM, or email, keep the information they already held. When you disconnect a system, we remove our access through that provider.
Retention
Routine work records are kept long enough for the agreed business use. Security, approval, and policy records may be kept longer. We will give you the exact time periods in writing before work begins.
- AI requests and answers
- Routine use
- System activity
- Routine use
- Feedback on an answer
- Routine use
- Approval and policy decisions
- Kept longer
- Access and security history
- Kept longer
What we have not completed yet
These details may affect whether we are the right vendor for your company, so we want you to see them before the project begins.
Deletion is manual, not scheduled
The system does not delete old records automatically yet. We delete them when a client asks and follow a written checklist covering every storage location. We have tested that process on a test account.
Most clients share one database, with access rules between them
Most clients use one database. Security rules inside that database limit each company to its own rows. This is not the same as giving every client a physically separate database. If your company requires a separate database, tell us before the project starts so we can set it up that way.
We are not SOC 2 certified
We are a small firm and have not completed a SOC 2 audit. If your purchasing rules require a SOC 2 report, we are not the right vendor today. We will tell you that on the first call.
Next step
Send us your security questions early.
If your requirements are stricter than what is written here, tell us on the first call. We may be able to set up a separate database or stronger controls. If we cannot meet the requirement, we will tell you before you spend time on a contract.