Checking or saving a company report does not give permission to use its source file for our model research. Company contributions require a separate written arrangement and supporting controls.
Security measures and their status
Live
Private retention and optional research
Personal checks save reports and sources automatically. Originals remain private for 180 days, with earlier deletion by email. This does not authorise research or training. The separate research option starts unchecked and can be withdrawn in the account.
Live
Company workspace access
Company balances, reports and billing are separate from personal accounts. Owner, Admin, Analyst and Viewer permissions are checked on the server.
Live
Activity history
Case, member, invitation, report-link and export changes record who made them and when.
Live
Deletion and retries
You can delete saved reports and withdraw research files. If source-file deletion fails, it stays pending for retry; research use remains blocked.
Live
Protected API keys
API keys are randomly generated, stored as one-way hashes and shown only once with their webhook secret.
Live
Private API uploads
Source files are private while waiting or being checked. We attempt deletion after processing and retry failures.
Live
Signed webhooks
Delivered reports carry a signature and event ID. Delivery uses HTTPS, time limits and retries.
Live
Identifiable reports
Reports include an ID, creation time and format version. To request a correction, send the ID and original export rather than just a screenshot.
Live
Limited operational records
Our product and payment-funnel events are kept for 90 days; account-linked provider records for 180 days; research-file deletion is scheduled after 180 days; authentication and event-rate hashes last up to 24 hours.
Live
Optional analytics
The Google tag loads after consent. Purchase and refund events can use the pseudonymous identifier saved after that consent. Clarity is excluded from checks, results, sign-in, account and admin pages. Our own billing records are separate.
Live
OpenAI response storage disabled
Requests use store:false. Standard abuse-monitoring records may still remain; this is not a zero-retention setting.
Live
Provider arrangements
The operator confirmed current service arrangements on 7 September 2026. The provider list explains where data goes and the storage details stated for each service. This is not an independent certification.
Implemented
Company workspace deletion
The owner can close a company workspace in Account → Business agreement and data. New processing stops, keys are revoked and scheduled cleanup removes company content after running tasks finish. Failed file deletions remain pending for retry. Required billing and agreement records remain. Personal account deletion is handled separately by verified email request.
In progress
Published account settings
Some service-specific settings, including the exact Google Analytics retention choice, are not documented here. We do not assume a shorter period or a specific region.
Planned
Independent security testing
An external security review and follow-up fixes are planned. We do not currently claim SOC 2, ISO 27001 or independent security certification.