Encrypted connections, Content Security Policy headers, rate limiting on auth endpoints and prompt-injection protection. GDPR and CCPA compliant with export, deletion and cookie controls.
Yes. Project data is tied to your account and every route verifies ownership. We never use your data to train models or share it with other users.
Securely in our database, never included in exports. Test or revoke them any time from Settings; they are only used during pipeline execution.
Project inputs go to OpenAI and/or Anthropic for agent execution only. Refer to each provider’s data usage policy for how they handle API requests.
Cookie Preferences in the footer covers Necessary, Analytics, Marketing and Functional categories, plus a CCPA Do Not Sell toggle.