Security & Trust

    How we protect your data and operations

    A plain-language overview of our infrastructure, data handling practices, and the commitments we make to every client before a project starts.

    GDPR-aligned · Berlin, Germany · Last reviewed May 2026

    Core commitments

    What every client can expect from us

    We never train on your data

    Your prompts, documents, and workflow data are never used to train AI models — ours or any third party's.

    We never sell your data

    Personal data and client information are never sold, rented, or shared with third parties for commercial purposes.

    Encryption in transit and at rest

    All data is encrypted over TLS in transit. Stored data uses provider-level encryption at rest across our infrastructure.

    GDPR-aligned by design

    We are based in Berlin, Germany. Our data handling follows GDPR principles including purpose limitation, data minimization, and consent management.

    Human review stays in place

    All client deployments include human-in-the-loop checkpoints for sensitive decisions. Automation does not replace oversight.

    90-day data retention

    Analytics and session data are retained for a maximum of 90 days and deleted on request. We keep only what is needed to operate.

    Hard limits

    What we will never do

    Sell, rent, or share your personal data with third parties for commercial gain

    Train AI models on your prompts, documents, or workflow data

    Store sensitive data beyond the minimum necessary for service operation

    Deploy automation into your workflows without agreed review controls and rollback procedures

    Use client project data for any purpose outside the agreed scope of work

    Infrastructure

    Where your data lives and who touches it

    Edge & hosting

    Cloudflare Workers

    All API endpoints run on Cloudflare's global edge network. No origin server exposed.

    Analytics storage

    Supabase (EU region)

    Consented analytics stored in Supabase with row-level security and access controls.

    AI processing

    OpenAI API

    Prompts are processed under OpenAI's API terms. Your data is not used for OpenAI model training.

    Email delivery

    Resend

    Transactional email for demo booking confirmations. No marketing without explicit opt-in.

    Access control

    Secret management + env vars

    API keys and secrets never exposed in client-side code. All sensitive variables are server-side only.

    Consent management

    First-party, on-site

    Consent is captured and stored first-party. Non-essential analytics are disabled until you opt in.

    Client projects

    Before any build begins

    Every client engagement includes a scoping session where we agree on data access scope, review controls, human checkpoints, and rollback procedures before a single line of automation is written.

    Minimum-access data design

    We request only the data access required to deliver the agreed workflow. No broad permissions, no access beyond scope.

    Review checkpoints in every pilot

    Automation outputs go through human review before affecting downstream systems. Control gates are agreed in advance.

    Confidentiality by default

    Client workflow data, process details, and business logic are treated as confidential and never shared outside the project team.

    Rollback and exit procedures

    Every deployment includes a defined rollback path. You can stop or revert any automation without depending on us to do it.

    Questions

    Have specific security or compliance requirements?

    We're happy to discuss data handling, access controls, or compliance alignment before you commit to a pilot. Email us directly or book a call.