Security

How we protect your data

Ask Safely encrypts your conversations, deletes them on a timer you control, and never uses them to train AI models.

This page covers the specifics: encryption, deletion, access control, infrastructure, third parties, and our compliance program. Built and maintained by SafeLife Inc.

The defaults

Chats delete themselves

By default, chats hard-delete 8 hours after creation. The database enforces the deletion; there is no archive tier or soft-delete flag. You can pick a longer window.

TTL-based hard deletion at the database level

No training on your conversations

Your conversations never train AI models. Our agreement with our model provider prohibits it, and so does our policy.

Contractual no-training commitment with the model provider

No selling, no ads

We do not sell or rent your data. We run no advertising. Subscriptions pay for the product.

Written into our privacy policy

Encryption, access, and deletion

Encryption in transit and at rest

TLS covers all traffic between your device and our servers. Stored data carries AES-256-GCM envelope encryption.

Each chat has its own encryption key. One compromised key cannot unlock other chats.

Key management

The master key never leaves FIPS-validated hardware security modules in plaintext. Least-privilege rules restrict who and what can use each key, and every cryptographic operation is logged.

Messages decrypt only while the AI processes them, then re-encrypt before storage.

Deletion

Delete any chat instantly, or let the default 8-hour timer do it. Deleting your account removes your records.

We are extending verified deletion across every downstream system as part of our SOC 2 program.

What we encrypt

Email addresses, every chat message (yours and the assistant's), one-time passcodes, authentication tokens, and memory profiles.

Passwords are one-way hashed. Nobody can recover them, including us.

Access control

  • One-time-passcode sign-up; authentication checked on every request.
  • Data is scoped to your account, and queries enforce that boundary.
  • Biometric unlock happens in your device's Secure Enclave. We never receive biometric data.
  • Internal systems follow least-privilege access.

Secure development

  • Automated, containerized builds with dependencies pinned to exact versions.
  • Requests our systems make on your behalf are validated and restricted before they run.
  • Monitoring excludes sensitive fields from logs, and we scan for leaked personal data.

Infrastructure

Ask Safely runs on AWS, which holds independent SOC, PCI DSS, and HIPAA attestations. AI responses come from Claude models through AWS Bedrock, under an agreement that bars the use of your conversations for model training.

Internal services communicate over controlled, authenticated network boundaries. We centrally log cryptographic and administrative activity, including every AI model invocation, so we can audit our own systems.

Compliance

Privacy regulations

Our data practices follow GDPR and CCPA/CPRA principles: data minimization, user control, and the right to deletion. The marketing site uses cookie-free analytics.

Vendor requirements

Every provider that touches user data holds independent security assurance (SOC 2 Type II or ISO 27001) and signs terms limiting how it may use data. We review each vendor annually.

Third parties

A small set of providers runs the service: AWS for infrastructure, Anthropic's Claude through AWS Bedrock for AI processing, Stripe for payments, and providers for email delivery and security monitoring. When you use web search, your query text goes to Brave Search; no account identifiers travel with it, and Brave is SOC 2 attested and does not profile users.

Each provider receives only what it needs. The full sub-processor list is in our privacy policy.

Report a security concern

Found a vulnerability, or have a question about our practices? Write to security@asksafely.ai. We read every report and respond quickly.

Maintained by
SafeLife Inc — Security & Compliance
Last updated
August 31, 2026