Privacy
How AI Security Planner handles editable work, product-use events, optional feedback, exports, and read-only shared snapshots.
Account and organization workspace
Registration and sign-in identify the individual account. Editable programs, reporting snapshots, and route comments are stored in the signed-in account or selected organization workspace and are returned only after authorization for that scope is verified.
Browser-local data
Interface preferences and share revocation keys are stored in the current browser profile. They remain available only while that site data remains intact and do not grant access to organization programs.
Anonymous product-use events
The product records only defined route, creation-stage, completion, export, and bounded error or recovery categories. A random tab-session identifier and short-lived creation-attempt identifier are sent to the same-origin event endpoint; only their SHA-256 digests are stored. Program content, titles, saved identifiers, entered values, filenames, messages, query strings, IP addresses, and user-agent strings are excluded from the product-use event table.
- Global Privacy Control and Do Not Track suppress passive product-use collection.
- A five-minute cleanup cycle deletes raw event rows once they are older than 90 days; the public Usage page returns 30-day aggregates only.
- A tab session is not a person, account, device, or unique visitor, and valid automated traffic can affect counts.
Optional first-party feedback
Cancellation and recommendation questions are optional and are sent to the same-origin feedback endpoint only after the user selects Submit. A cancellation response contains one fixed reason and can include up to 180 characters when Other is selected. A completion response contains a 0–10 recommendation score. The response also contains a fixed program-family label, a random tab-session digest, a timestamp, and the product release version. It does not contain a saved program title or identifier.
- Raw first-party feedback rows are deleted after 90 days.
- Cancellation details are never returned on the public Usage page.
- Recommendation results appear only as bounded aggregates with response volume.
Optional SurveyMonkey follow-up
After a successfully submitted recommendation score of 9 or 10, AI Security Planner can offer a separate public SurveyMonkey link. The link contains no NPS score, program family, program identifier, account value, custom variable, query, fragment, or referrer from AI Security Planner. Anything a respondent enters is submitted directly to SurveyMonkey, which may process service metadata such as IP addresses under its collector settings and policies. AI Security Planner does not control SurveyMonkey retention.
- The detailed survey remains optional and opens only after a separate user action.
- Usage receives only owner-reviewed fixed counts and quote text for which the response granted quotation permission.
- Approved public aggregates and quotes are versioned with the product until a later reviewed release removes them.
Import and export
Imported JSON files are validated and processed in the browser. Downloaded JSON, CSV, Markdown, PNG, and PowerPoint files leave browser storage only through an explicit action. After export, handling is controlled by the selected device location or application.
Request boundary and external links
The hosting, delivery, and security platform processes ordinary web-request metadata outside the product-use event table. Documentation, inspectors, Specs, and Design may link to public standards or references; opening one sends the usual browser request to that third-party site under its own privacy terms.
Removing data
Browser site-data controls can remove interface preferences and local share-revocation keys, but not organization programs. Program, organization, and account deletion use their explicit authorized product actions and confirmation boundaries.

