What’s true today
What happens to your work, honestly
Start with how you get in. Sign-in with Google and Microsoft is coming soon. When you use one, we never receive a password at all — there is nothing of yours for us to store badly or to lose, and your account is exactly as well defended as that Google or Microsoft account already is, including any two-factor on it and any rule your organisation tightens later.
Saved work is real and stored on our servers. When you save an analysis or a project, what gets written is the substance of it — the figures you entered, the assumptions behind them, the notes you wrote. That is the point of saving, and it would be strange to describe it as anything else. It goes into PostgreSQL, managed by Supabase — an ordinary, widely used database rather than anything we invented — encrypted in transit on the way there and encrypted at rest once it arrives.
Your data is private to you, always. Nothing you save can ever be seen by another customer. That is not a promise about how carefully we wrote the app — the database itself checks who is asking on every single request and refuses anything that is not yours, so it holds even if our own code has a bug in it, and it does not depend on anything in your browser staying secret.
As for us: access to stored customer data is restricted to the people who need it to run the service, every one of them bound by confidentiality, and only for a defined set of reasons — fixing a fault, investigating a security issue, or recovering something at your request. It is never browsed out of curiosity and never used to train anything.
And it goes to nobody else. Not sold, not shared, not handed to a partner or an advertiser, and never shown to another company in your market for any reason — being a customer or not being one makes no difference, because the answer is the same for everyone outside this company. The one exception is a legal obligation we cannot refuse — stated here rather than left out of the sentence where it matters.
When you do use the AI, it goes to Anthropic. They do not use what we send to train their models. And nothing reaches them until you have seen the itemised list of exactly what would go and pressed the button — or decided not to, copied the prompt, and run it somewhere else entirely.
Need to go deeper than this page?
If you have an internal policy to satisfy, a customer requirement to meet, or a regulator to answer to, we are happy to go through any of it in detail — including the parts that are not written down here.
Talk to us about security →Same principle as the rest of this tool: we’d rather tell you exactly how something works than let you assume it’s stronger than it is.
See it on a real decision →