Trust · vendor assessment
Security & data handling.
Everything a vendor check asks for, on a page you can forward. No form, no “contact sales for the security pack”. If your answer to a question below has to be pasted into a prequalification response, it is written so you can paste it.
Operative documents: Data Processing Agreement · Privacy & Security Statement · Terms of Service
Data handling posture
Every promise, and the mechanism behind it.
A promise you have to trust is worth less than one we could not break if we wanted to. Each of these is enforced by how the product is built, so the second column is the part that matters.
01
Nothing you write is used to train a model.
Not ours, not a provider's. That is a term in our contracts with the model providers, not a preference in our privacy policy — the commercial API terms we buy under prohibit training on submitted content.
02
The documents you upload are not kept.
A file is read once, what it teaches is written into your own profile, and the original is deleted within 24 hours. A sweep runs every hour and deletes anything a failed job left behind, so the guarantee holds on the error path too, not just the happy one.
03
Your account is sealed at the database, not in the application.
Every row carrying your content is protected by database-level row security keyed to your account. An application bug cannot serve one customer's project history to another, because the database refuses the read rather than trusting our code to filter it.
04
Leaving costs you nothing, and takes nothing from you.
Export your library in machine-readable form whenever you like, including while you are still a customer. Deleting your account removes your content immediately, and residual copies in backups are purged within 30 days.
05
You can run it entirely on your own provider account.
Supply your own model provider key and every request goes direct to that provider under your agreement with them. We store the key encrypted with AES-256-GCM, never display it again after entry, and use it only for work you start.
Operational controls
What stops it doing damage while nobody is watching.
The section above is about data we hold. This one is about a system that drafts unattended, which is the question that follows it. Same array the homepage renders, so the two cannot describe different products.
Nothing sends itself
Every outbound action — an email, a filed document, a calendar invite — waits in an approval queue. Approving is what sends it. That is the execution path, not a setting someone can leave off.
The right person signs
Drafts can route to an approver group rather than back to whoever triggered them, so a manager signs off what their team drafted.
Personal details never land
Anything arriving from a connected mailbox has personal details replaced before it is stored. A value that never enters storage cannot appear in a draft, however it is prompted.
What it read is not an instruction
Content from outside your business is fenced as data, and anything in it that tried to give instructions is surfaced to you rather than quietly obeyed.
Every document can be reconstructed
What a draft was built from — which version of your profile, which reference material, which release — is recorded and verifiable. You can prove what a document was based on.
One switch stops everything
Per-account daily caps, a rule that disables itself after repeated failure, and a kill switch. A full activity log underneath all of it.
Where the work happens
Your records stay in Australia. The drafting does not.
Your database records and your uploaded files are stored in an Australian region. That covers your rates, your project history, your documents and your account.
Drafting is a different question, and the honest answer is that it happens offshore. When a document is written, the specific content that request needs is sent to a model provider whose infrastructure is in the United States. Only what the request requires goes — not your account, not your library.
It goes under commercial terms that prohibit training on it, and it is never sold or shared for advertising or any unrelated purpose. If a head contract or an insurer requires all processing to stay onshore, say so before you upload anything regulated — there is an Australian-inference deployment, and that conversation is better had first than discovered later.
What we do not connect to
We don't touch your job system.
We don't want your data out of it, we don't replace it. We do the writing it was never built to do.
There is no integration with any of these, and that is the point rather than a roadmap item. Nothing to scope, nothing to get access to, nothing for us to hold a live copy of, and nothing that breaks when your job system updates.
The one optional connection is a read-only mailbox or file folder, switched on by you and scoped by rules you write in plain words. It can never send, change or delete anything, personal details are stripped before storage, and disconnecting removes access immediately.
Subprocessors
Everyone who touches your data.
Each one is bound by data-protection obligations no less protective than the ones we owe you, and we stay liable for them. We give notice before a new subprocessor starts processing your data, and you can object on reasonable grounds.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database and file storage | Australian region |
| Vercel | Application hosting | Global edge, AU origin |
| Anthropic | Text generation (the default) | United States |
| Stripe | Payments and subscriptions | United States |
| Resend | Transactional and inbound email | United States |
| OpenAI | Knowledge-base indexing, and generation if you select itOnly where you select those models, or for indexing unless you disable it | United States |
| Generation if you select itOnly where you select those models | United States |
Providers you connect with your own key, or your own tooling, are governed by your agreement with them rather than ours.
The questions we actually get asked
Answers you can paste into a prequalification response.
Q.01Can we get a signed Data Processing Agreement?+
Yes. The operative terms are published at /dpa and apply from the moment you use the service — nobody has to wait on a countersignature to start. Procurement teams needing an executed copy on company letterhead can request one through the support address in your account.
Q.02Does anything get sent or submitted without a person approving it?+
No, and it can't. Every document is a draft until someone approves it, including the ones written from a connected inbox. Approval is the action that sends an email or files a document, and each one is recorded against the person who made it. That is how the product is built, not a setting an administrator can leave off.
Q.03Where is our data stored?+
Your database records and files are stored in an Australian region. Generation is a separate question and is answered honestly under 'Where the work happens' above — for a standard deployment the text of a request is processed in the United States.
Q.04What happens to our data if we leave?+
You export everything in machine-readable form whenever you like, including while you are still a customer. Deleting your account removes your content immediately, and residual copies in backups are purged within 30 days.
Q.05Do you have access to our project files or job records?+
Only what you hand over. There is no integration into your job-management system, so we hold no live copy of your jobs, your schedule or your invoices. If you connect a mailbox, it is read-only, scoped to the rules you write, and personal details are stripped before anything is stored.
Q.06Who at your company can see our content?+
Production access is restricted and is used for support and incident response only. Row security means routine application traffic cannot reach across accounts at all. We notify you without undue delay if we become aware of a breach affecting your content.
Paperwork
The DPA is already live.
It is published, effective, and binding from the moment you use the service, so nobody sits waiting on a countersignature to get started. Read it in full, send the link to whoever needs it, and request an executed copy on company letterhead through the support address in your account if procurement needs one for the file.
Roles
You are the Controller of everything you upload and generate. We are your Processor, acting only on your instructions.
Assistance
We help with data-subject requests, and export and deletion are self-serve in the product rather than a support ticket.
Breach
Notice without undue delay after we become aware of a breach affecting your content.
Exit
Export everything on the way out. Deletion is immediate, with backups purged within 30 days.
Something here that won't clear your client's vendor check?
Send us the question in the form it was asked. If the honest answer is no, you will get a no — that is cheaper for both of us than finding out at contract stage.