Your data is yours. Here is exactly how we protect it.
Privacy ControlsEncrypted TransportDeletion ControlsNo Password StoragePasswordless Auth
Infrastructure
- Application hosting on Vercel and managed PostgreSQL/authentication on Supabase
- Encrypted transport for browser, API, database, payment, and model-provider connections
- Row-level database policies and service-role separation on protected data paths
- Hosting and processing locations can vary by deployment and subprocessor; current details are provided during diligence
- Passwordless authentication via one-time codes (OTP) and magic links
- No passwords stored — no password to leak
- Google OAuth as alternative sign-in method
- Session tokens with automatic rotation
- Authenticated conversation history is stored so you can reopen it, subject to plan retention and deletion controls
- Guest telemetry is content-free; authenticated operational analytics stores limited or anonymized content as described in the Privacy Policy
- Queries needed for inference are sent to the selected AI providers after applicable Privacy Shield processing
- Account deletion and history deletion are available; legal or billing records may follow separate required retention periods
- API keys are SHA-256 hashed before storage — we cannot see your key
- Rate limiting on all endpoints (per-IP and per-key)
- Content Security Policy (CSP), HSTS, X-Frame-Options, XSS protection headers
- Stripe webhooks verified via cryptographic signatures
- Anthropic, OpenAI, Google, Mistral, Perplexity, and xAI can process prompts when their models are selected
- A fallback can execute on a different provider; Satcove records requested and executed identities in consensus metadata
- Provider terms, retention options, certifications, and processing locations are provider-specific and can change
- Current subprocessor and transfer information is supplied during customer diligence rather than implied by a logo
- Privacy controls are designed to support access, correction, deletion, restriction, and objection requests where applicable
- Account deletion covers account-linked product data; legally required transaction records may be retained separately
- A DPA and current subprocessor details can be reviewed during a business pilot
- No certification or regulatory status is claimed without the corresponding current evidence
Found a security issue?
Report it hereSatcove — A product by Abyssal Group