Security & privacy
Your work is yours. Including the parts an AI reads.
The whole product only works if you're willing to put real client work in it. So here's exactly how your data is handled, in plain terms, including what happens the moment the AI touches it.
Encrypted in transit and at rest
TLS everywhere, and disk-level encryption on the database and file storage. No exceptions, on every plan.
Your data is never training data
Project content is sent to Anthropic or OpenAI only to answer the request you made, under agreements that forbid training on it. We use zero-retention endpoints where they're offered.
Least-privilege access
Nobody at Projects.chat can read your project content without you granting access to a specific project. Grants are logged and they expire.
Daily backups
Encrypted daily backups with thirty-day retention, and restores tested on a schedule rather than hoped for.
Export everything, any time
Full export of documents, messages, to-dos and files in open formats, on every plan including Free. Leaving should be as easy as arriving.
US and EU data regions
Choose where your account's data lives when you create it, and it stays there.
SSO / SAML and audit log
Single sign-on against your identity provider, and a full audit trail of who did what, on the Unlimited plan.
Sensible session handling
Signed, encrypted session cookies, sessions you can revoke from any device, and no third-party trackers anywhere on the product or this site.
The AI question
What happens when the AI reads your project.
It's the thing people are right to be suspicious about, so here's the whole mechanism in plain terms.
- Nothing is sent anywhere until you ask a question or run an action.
- When you do, only the relevant parts of that one project are sent to the model provider you selected — Anthropic or OpenAI.
- It's used to answer your request and nothing else. It is not used to train models, ours or theirs.
- Where providers offer zero-retention endpoints, we use them, so nothing is stored on their side.
- On the Unlimited plan you can use your own API key, so the request goes out under your own account and agreements.
- You can switch the AI off per project or account-wide, and the rest of the product works exactly the same.
Who we share data with
The short list of companies that will process data on our behalf. We'll keep this current, and we'll email account owners before adding anyone new.
- Anthropic — AI features, when you use them
- OpenAI — AI features, when you select their models
- Our hosting provider — application servers, database and file storage
- Our email provider — transactional email and notifications
- Our payment processor — billing, which never sees your project content
- Simple Analytics and Tinylytics — aggregate visitor counts on our marketing pages only. Cookie-free, no personal data, and they never run inside the product.
If your procurement team needs the named vendors and a signed DPA, ask us and we'll send them over.
Found something?
If you think you've found a vulnerability, email security@projects.chat and we'll reply within two working days. We won't take legal action against anyone doing good-faith research, and we'll credit you if you'd like us to.
Privacy questions
Where does my data live?
Who can see my projects?
Can I get my data out?
Something we haven't answered? Ask us directly — a person replies.
Sensible defaults, no surprises.
Join the waitlist — and if your security team needs to review something before you can try it, tell us and we'll get ahead of it.
Free to join. One email when your invite is ready — nothing else, ever.