Chats delete themselves
By default, chats hard-delete 8 hours after creation. The database enforces the deletion; there is no archive tier or soft-delete flag. You can pick a longer window.
TTL-based hard deletion at the database level
Security
Ask Safely encrypts your conversations, deletes them on a timer you control, and never uses them to train AI models.
This page covers the specifics: encryption, deletion, access control, infrastructure, third parties, and our compliance program. Built and maintained by SafeLife Inc.
By default, chats hard-delete 8 hours after creation. The database enforces the deletion; there is no archive tier or soft-delete flag. You can pick a longer window.
TTL-based hard deletion at the database level
Your conversations never train AI models. Our agreement with our model provider prohibits it, and so does our policy.
Contractual no-training commitment with the model provider
We do not sell or rent your data. We run no advertising. Subscriptions pay for the product.
Written into our privacy policy
TLS covers all traffic between your device and our servers. Stored data carries AES-256-GCM envelope encryption.
Each chat has its own encryption key. One compromised key cannot unlock other chats.
The master key never leaves FIPS-validated hardware security modules in plaintext. Least-privilege rules restrict who and what can use each key, and every cryptographic operation is logged.
Messages decrypt only while the AI processes them, then re-encrypt before storage.
Delete any chat instantly, or let the default 8-hour timer do it. Deleting your account removes your records.
We are extending verified deletion across every downstream system as part of our SOC 2 program.
Email addresses, every chat message (yours and the assistant's), one-time passcodes, authentication tokens, and memory profiles.
Passwords are one-way hashed. Nobody can recover them, including us.
Ask Safely runs on AWS, which holds independent SOC, PCI DSS, and HIPAA attestations. AI responses come from Claude models through AWS Bedrock, under an agreement that bars the use of your conversations for model training.
Internal services communicate over controlled, authenticated network boundaries. We centrally log cryptographic and administrative activity, including every AI model invocation, so we can audit our own systems.
Our data practices follow GDPR and CCPA/CPRA principles: data minimization, user control, and the right to deletion. The marketing site uses cookie-free analytics.
Every provider that touches user data holds independent security assurance (SOC 2 Type II or ISO 27001) and signs terms limiting how it may use data. We review each vendor annually.
A small set of providers runs the service: AWS for infrastructure, Anthropic's Claude through AWS Bedrock for AI processing, Stripe for payments, and providers for email delivery and security monitoring. When you use web search, your query text goes to Brave Search; no account identifiers travel with it, and Brave is SOC 2 attested and does not profile users.
Each provider receives only what it needs. The full sub-processor list is in our privacy policy.
Found a vulnerability, or have a question about our practices? Write to security@asksafely.ai. We read every report and respond quickly.