Security and trust center

How we protect your data

We combine technical controls, contractual safeguards and customer-controlled integrations to protect the business context and content you process through the service.

Sources last reviewed 10 August 2026

Security at a glance

Our public policies commit to TLS 1.2 or higher in transit, encryption at rest where technically appropriate, least-privilege access, role-based controls, employee MFA for production access, logging, security reviews and an incident-response process. We do not use customer data to train AI models, and personal data is primarily stored in the EU/EEA.

Policy-grounded, not a certification claim

This page summarizes our current contractual and privacy commitments. The DPA is the controlling source for processing terms where documents differ. Nothing on this page states that we hold SOC 2 or ISO 27001 certification.

Who is responsible for the data?

The role depends on the data and purpose. Our Privacy Policy and DPA distinguish between our own business data and the content you process through the service.

When we are the controller

We are the controller for information about website visitors, account holders, customer contacts and leads when we determine the purpose of processing.

When we are the processor

For your content, connected-channel data and other personal data processed on your instructions, you are the controller and we act as processor under the DPA.

Subprocessors

We use subprocessors for hosting, AI inference, publishing, analytics, support and integrations. Other providers can have a different legal role; for example, the DPA identifies Stripe as an independent controller for payment data.

Published control commitments

The table summarizes statements in our current public Privacy Policy and Terms. “Committed” means the control is written in those documents. It does not mean an external auditor has independently certified it.

Control areaPublished commitmentEvidence statusSource
Data in transitTLS 1.2 or higher for data transmitted to and from the service.Committed in policy and DPA controlsPrivacy §10; Terms §18.2
Data at restAES-256 or equivalent encryption where technically appropriate.Committed in policy and DPA controlsPrivacy §10; Terms §18.2
AccessLeast privilege, role-based access and employee MFA for access to production data.Committed in policy and DPA controlsPrivacy §10; Terms §18.1
MonitoringLogging and monitoring of access, events and security incidents.Committed in policy and DPA controlsPrivacy §10; Terms §18.3
Secure deliveryEnvironment separation, patching, vulnerability management and regular security reviews.Committed in policy and DPA controlsPrivacy §10; Terms §18.3 and §18.5
Backups and continuityDaily automated encrypted backups and documented incident and continuity procedures.Committed; DPA sets the controlling retention maximumTerms §18.4; DPA §16.10
DPA and audit supportA binding DPA in the Terms, standalone copy on request and audit information under defined conditions.Contractual commitmentTerms §16 and §16.9

How customer data is used with AI

We use AI providers to generate text and images for the service you request. The Privacy Policy states that we do not use customer data, user data or content to train or fine-tune AI models and that we hold contractual terms preventing providers from using service inputs and outputs for model training.

  • AI inference is used to provide requested product functions.
  • Customer content is not sold or supplied as a training dataset.
  • Current policy names OpenAI, Anthropic, Google and xAI as AI processors.
  • Transfers outside the EEA use an applicable mechanism such as the EU-US Data Privacy Framework or Standard Contractual Clauses.

Hosting and international transfers

Our DPA states that personal data is stored primarily in the EU/EEA, mainly in Google Cloud regions in Ireland. The subprocessor inventory also lists AWS for cloud storage and operations.

  • Primary storage is described as EU/EEA-based.
  • Some subprocessors process data in the United States or other countries.
  • We document DPF, SCCs and transfer-impact safeguards for applicable transfers.
  • Provider certifications apply to provider data centers. They are not our certifications.

Retention and deletion

The DPA says deletion normally occurs within 30 days after termination and no later than 90 days. Backups are deleted under standard routines and no later than 180 days. Legal retention duties, such as bookkeeping records, remain exceptions. Connected-service tokens are deleted after disconnection or account closure under the Privacy Policy.

Contractual source: DPA §16.10 is the controlling schedule for customer personal data where a shorter summary elsewhere differs.

Incident response and notification

Our DPA and privacy commitments describe a defined process for identifying, classifying, escalating and handling security incidents. Notification duties depend on our role and applicable law.

  • You are notified without undue delay when a personal-data breach affects customer data.
  • We document the nature, likely consequences and mitigation steps as information becomes available.
  • We keep incident records and follow up with corrective actions.
  • Regulatory and individual notification follows GDPR and other applicable legal requirements.

Controls customers should use

  • Use a unique strong password and available account security controls.
  • Limit team access to people who need it and remove access promptly.
  • Review permissions requested by connected social and integration accounts.
  • Disconnect integrations that are no longer used.
  • Contact us promptly if you suspect unauthorized account activity.

Certification status

We do not claim on this page to hold SOC 2, ISO 27001 or another independent security certification. The Terms identify infrastructure certifications held by Google Cloud, not by us. You can request current security documentation and available audit evidence from us.

Need a DPA or security review?

Request the current DPA, subprocessor information or answers to a security questionnaire. Include your organization, deadline and the areas your review needs to cover.

Request security information

Frequently asked questions

No. Our Privacy Policy states that customer data, user data and content are not used to train or fine-tune AI models and that AI providers are contractually restricted from using service inputs and outputs for training.

Our public documents state that personal data is primarily stored in the EU/EEA. Some subprocessors may process data elsewhere under an applicable transfer mechanism such as the Data Privacy Framework or Standard Contractual Clauses.

Yes. Sections 16 to 18 of the Terms form a binding DPA, and a standalone signable version is available on request.

We do not make that certification claim on this page. Cloud-provider certifications are not the same as a certification held by us.

The DPA says deletion normally occurs within 30 days and no later than 90 days, except where law requires retention. Backups are deleted under standard routines and no later than 180 days.