Security
Last updated September 16, 2026
This page describes what actually protects your data, in terms specific enough that you could check them. It deliberately does not claim a certification we do not hold or a control we have not built — where something is not yet switched on, it says so.
Your files
A signed link is the only way to read a file, and it lasts 5 minutes
Files are never public. Reading one requires a link signed for that exact object, and the signature expires 300 seconds after it is issued. The signing service takes an identifier, not a path, so a caller cannot ask for a file by guessing where it lives.
No signed link is ever written to a log
A signed link is a temporary key. Our logs record a correlation identifier and an error code; no log statement anywhere in the system emits a signed URL, so one cannot leak into a log that outlives it.
An upload can only be written where a reservation already says it may go
Before your device may write a single byte, the server reserves a specific location for a specific file belonging to your account. The storage rule checks that reservation on every write, so an upload cannot be redirected to another path or another account’s space.
Nothing that runs your video can delete anything
The workers that read your spreadsheet, write the script, synthesize the narration and render the video hold no delete permission at all. Exactly two components can delete a stored object: the retention sweep and the account-deletion executor. Each has its own identity, scoped to the decision it serves.
Your account and its removal
The app cannot delete your data, and neither can we by accident
The database grants your signed-in session no delete permission on your own records. Deletion happens only through a server-side path that records what it did. This is why “delete my account” is a request with a lifecycle rather than a button that empties a table.
Deletion completes within 30 days, and the executor that does it is switched on
Asking to delete your account immediately stops new projects, uploads and video generation. You have 72 hours to cancel and keep the account. After that the executor removes your uploads and derived data, the rendered artifacts, the delivery copies, and the identifying fields on your account, and it completes within 30 days.
A deliberately narrow, de-identified spine survives: financial and reconciliation records, security records, and the deletion audit trail itself. Our Privacy Policy describes exactly what that is.
What reaches the AI model
The model gets a bounded projection, not your file
For a spreadsheet, we do not send the file. We send a derived projection — column labels, statistics, and a limited sample of values — and values from columns detected as personal or sensitive are withheld from that sample. An uploaded image of a table is the exception: the whole image is sent, because reading it is the task.
Your description of the data is treated as data, never as an instruction
You can write a short note telling the model what your numbers are. It is capped at 500 characters, and it is discarded entirely before the model sees it if it contains something that looks like personal information. What survives enters as untrusted material: it can suggest framing, but it cannot issue instructions, cannot override a figure read from your data, and cannot cause a claim to be treated as sourced.
We do not train on your data
We train no model of our own on your files, generated content, or videos. The providers who process a request are bound by their own terms; the subprocessor page names every one of them and says what reaches it.
Retention
These are the schedules the system is built around.
- Source uploads: 30 days in our primary storage, and 90 days for the working copy used to make your video. Thirty days is the earliest a file is removed rather than a guaranteed maximum — a file still referenced by an unfinished job is skipped and removed on a later sweep.
- Finished videos: by plan — 7 days on Free, 30 on Starter, 90 on Pro, and a year on Premium.
- Financial, reconciliation, security and deletion-audit records: kept as long as the law and our accounting obligations require, de-identified.
🖐 Automatic deletion at the finished-video deadlines is not yet switched on. These are the periods the product is designed around and what we will delete to, not a claim that a sweep is running today. Account deletion on request is running, and is the 30-day commitment above. When the retention sweep is armed, this paragraph comes out.
What we do not claim
We hold no SOC 2, ISO 27001, or equivalent certification. Chartapir is a small company before its public launch, and an audit of that kind is 6 to 12 months of work we have not done. We would rather publish the specific controls above, which you can ask us to demonstrate, than a badge that says less.
We also do not claim that a provider’s own retention is zero unless that provider says so in terms we have read. Where we have not verified something, the Privacy Policy says we have not.
Reporting a vulnerability
Email [email protected] with enough detail to reproduce the issue. We will acknowledge within 5 business days. We will not pursue legal action against good-faith research that avoids privacy violations, service degradation, and access to data that is not your own.
TechnicolorLife LLC
30 N Gould St, Ste N
Sheridan, WY 82801
United States