Security
What exists in production today. We do not list certifications we have not earned.
Isolation
Row-level security is enabled on all customer tables. A signed-in user can read and write only their own rows. The application layer also refuses cross-account access.
Encryption
Traffic between your browser and Autonomously You is encrypted in transit (HTTPS). Databases and object storage use the encryption provided by our hosting subprocessors.
Provider keys
Model-provider credentials stay on our servers. Customers never supply OpenAI, Grok, Claude, or Gemini keys. Ask AY usage is included in the membership. We pay the providers.
What models can see
Private and never-share memories are never sent to a model. Ask AY sends only approved, shareable context. Billing events are verified on the server. Membership is never granted from the browser alone.
Export, deletion, and audit
You can export your identity, forget memories, remove sources, or delete your account. Security-relevant actions are recorded as audit events for your account.
Retention
Identity data stays while the account is open. After deletion we remove customer identity from production systems except records required for billing, security, or law.
Subprocessors
Stripe, Vercel, Supabase, and — when you use Ask AY — OpenAI, xAI, Anthropic, or Google. See the Privacy Policy.
Incident response
If we confirm a security incident that affects your account, we will investigate, contain it, and notify affected customers as required by law. Report a vulnerability to security@autonomouslyyou.com.
