Privacy

How AI Security Planner handles editable work, product-use events, optional feedback, exports, and read-only shared snapshots.

Account and organization workspace

Registration and sign-in identify the individual account. Editable programs, reporting snapshots, and route comments are stored in the signed-in account or selected organization workspace and are returned only after authorization for that scope is verified.

Browser-local data

Interface preferences and share revocation keys are stored in the current browser profile. They remain available only while that site data remains intact and do not grant access to organization programs.

Anonymous product-use events

The product records only defined route, creation-stage, completion, export, and bounded error or recovery categories. A random tab-session identifier and short-lived creation-attempt identifier are sent to the same-origin event endpoint; only their SHA-256 digests are stored. Program content, titles, saved identifiers, entered values, filenames, messages, query strings, IP addresses, and user-agent strings are excluded from the product-use event table.

  • Global Privacy Control and Do Not Track suppress passive product-use collection.
  • A five-minute cleanup cycle deletes raw event rows once they are older than 90 days; the public Usage page returns 30-day aggregates only.
  • A tab session is not a person, account, device, or unique visitor, and valid automated traffic can affect counts.

Optional first-party feedback

Cancellation and recommendation questions are optional and are sent to the same-origin feedback endpoint only after the user selects Submit. A cancellation response contains one fixed reason and can include up to 180 characters when Other is selected. A completion response contains a 0–10 recommendation score. The response also contains a fixed program-family label, a random tab-session digest, a timestamp, and the product release version. It does not contain a saved program title or identifier.

  • Raw first-party feedback rows are deleted after 90 days.
  • Cancellation details are never returned on the public Usage page.
  • Recommendation results appear only as bounded aggregates with response volume.

Optional SurveyMonkey follow-up

After a successfully submitted recommendation score of 9 or 10, AI Security Planner can offer a separate public SurveyMonkey link. The link contains no NPS score, program family, program identifier, account value, custom variable, query, fragment, or referrer from AI Security Planner. Anything a respondent enters is submitted directly to SurveyMonkey, which may process service metadata such as IP addresses under its collector settings and policies. AI Security Planner does not control SurveyMonkey retention.

  • The detailed survey remains optional and opens only after a separate user action.
  • Usage receives only owner-reviewed fixed counts and quote text for which the response granted quotation permission.
  • Approved public aggregates and quotes are versioned with the product until a later reviewed release removes them.

Share snapshots

Share sends a sanitized, immutable program snapshot to bounded server storage. Route comments and reporting history are removed. The snapshot expires after 30 days and can be revoked with a separate key stored only in the creating browser profile.

Import and export

Imported JSON files are validated and processed in the browser. Downloaded JSON, CSV, Markdown, PNG, and PowerPoint files leave browser storage only through an explicit action. After export, handling is controlled by the selected device location or application.

Removing data

Browser site-data controls can remove interface preferences and local share-revocation keys, but not organization programs. Program, organization, and account deletion use their explicit authorized product actions and confirmation boundaries.