Home / Security
How we look after your data
Written plainly, and kept current. If something here is out of date, tell us at [email protected].
In transit
Everything travels over TLS 1.2 or better. The site is served over HTTPS only, with HSTS enabled, and plain HTTP requests are redirected.
At rest
Databases and file storage are encrypted at rest by our hosting provider using AES-256. Backups are encrypted with the same standard.
Where data lives
Application data is stored in the Asia Pacific (Mumbai) region. Chart generation calls a model provider whose processing may take place outside India; see the privacy policy for details of that transfer.
Model providers
We use OpenAI's API for the language step. Under our agreement, data sent through the API is not used to train their models. We send only what is needed to build your chart.
Retention
Charts are not retained at all. Your prompt and data are held in memory long enough to build the chart, returned to your browser, and not written to our database — so there is no chart history to expose, on any plan. Deleting your account removes your personal data within 30 days, apart from records we must keep for tax and accounting.
Access control
Production access is limited to the people who need it, protected by two-factor authentication, and logged. There are no stored charts for anyone to read — the only personal data in the database is what an account needs.
Payments
Card details are handled by our payment provider and never touch our servers. We store no card data at all — not the number, not the expiry, not the last four digits. Which card is on file is shown to you by the provider, not from anything we hold.
Dependencies
Application dependencies are monitored for known vulnerabilities and patched on a regular cycle, with critical fixes applied out of band.
Certifications
We do not hold SOC 2 or ISO 27001 today. We would rather say so than imply otherwise. If your procurement process requires a security questionnaire, write to [email protected] and we will complete it.
Reporting a vulnerability
We will not take legal action against good-faith research.
Email [email protected] with enough detail to reproduce the issue. You will get an acknowledgement within two working days and an assessment within five.
Please give us a reasonable window to fix the problem before disclosing it publicly. Do not access, modify or delete data belonging to anyone else while testing, and do not run tests that could degrade the service for other people.
We do not run a paid bounty programme yet. We do credit researchers who want to be credited.