Back to Home

    Security & AI Transparency

    Last Updated: March 18, 2026

    We believe in transparency about how we protect your data and how our AI systems work. This page outlines our security practices and provides clear information about our use of artificial intelligence.

    Security Practices

    Security Overview

    Protecting your data is a core priority at AI42. We implement multiple layers of security controls across our platform to safeguard your personal information, user content, and account credentials. Our security approach follows industry best practices and is continuously reviewed and updated.

    Encryption

    Data in Transit

    All data transmitted between your browser and our servers is encrypted using HTTPS with TLS 1.2 or higher. This ensures that your data cannot be intercepted or read by third parties during transmission.

    Sensitive Tokens & Credentials

    Sensitive data such as API keys, integration tokens, and encrypted credentials are protected using AES-256 encryption, one of the strongest encryption standards available. These tokens are encrypted at rest and are only decrypted when actively needed for authorized operations.

    Database Encryption

    Our database provider (Supabase) encrypts data at rest using AES-256 encryption at the storage level, providing an additional layer of protection for all stored data.

    Authentication

    Authentication is managed through Supabase Auth, which provides:

    • Secure email/password authentication with hashed password storage (bcrypt)
    • OAuth social login (Google) for convenient and secure sign-in
    • JWT-based session management with secure token rotation
    • Row Level Security (RLS) policies enforced at the database level
    • Session expiration and automatic token refresh mechanisms

    Data Isolation

    Every user's data is strictly isolated from other users through:

    • Row Level Security (RLS): Database-level policies ensure that queries can only return data belonging to the authenticated user. This is enforced at the database engine level, not just in application code.
    • Per-User Scoping: All API endpoints and data queries are scoped to the authenticated user's ID, preventing cross-account data access.
    • Isolated AI Context: AI conversations and semantic memories are scoped per user. One user's AI context is never accessible to or shared with another user.

    Infrastructure

    Our platform is built on modern, cloud-hosted infrastructure:

    • Cloud-hosted application servers with automated scaling and redundancy
    • Supabase-managed PostgreSQL database with automated backups and point-in-time recovery
    • CDN-distributed static assets for performance and DDoS mitigation
    • Separation of concerns between application logic, data storage, and AI processing
    • Regular dependency updates and vulnerability scanning

    Incident Response

    We are committed to promptly addressing any security incidents:

    • We maintain an incident response plan to quickly identify, contain, and remediate security events.
    • In the event of a data breach that affects your personal information, we will notify affected users and relevant authorities as required by applicable law, including GDPR (within 72 hours) and state breach notification laws.
    • We conduct post-incident reviews to prevent recurrence.
    • Security vulnerabilities can be reported to security@ai42tech.com. We take all reports seriously and will investigate promptly.

    AI Transparency

    AI Transparency Overview

    Important Disclosure

    The AI assistant in AI42 is an artificial intelligence system. It is not a human. While it is designed to be helpful, conversational, and knowledgeable, it is a machine learning model that generates responses based on patterns in its training data and the context you provide. It does not have consciousness, emotions, or true understanding.

    We are committed to being transparent about how AI is used in our platform. This section explains which AI systems we use, what data they process, how AI memory works, and the known limitations of AI technology.

    AI Providers

    AI42 integrates with multiple AI providers to deliver the best possible experience. The specific provider used may vary depending on the feature, task complexity, and your settings:

    OpenAI

    GPT models for conversation, analysis, and embeddings

    Anthropic

    Claude models for nuanced reasoning and conversation

    Google AI

    Gemini models for multimodal processing

    Perplexity

    AI-powered web search and real-time research

    When you send a message to the AI assistant, the relevant portions of your conversation are sent to one or more of these providers for processing. Each provider has their own data handling policies. We select providers that commit to not training on customer data where possible.

    What AI Processes

    The AI assistant may process the following types of data to provide its functionality:

    Conversations

    Your text messages to the AI assistant, along with the conversation history for context. This allows the AI to provide relevant and coherent responses throughout a conversation.

    Voice Input

    When using voice chat, your audio is transcribed to text in real time using Deepgram (speech-to-text). The raw audio is transient and is not permanently stored. The AI processes the resulting text transcription to generate a response.

    Documents & Content

    When you ask the AI to work with your tasks, notes, calendar events, or other content, the relevant data is included in the AI prompt so the assistant can provide helpful responses. Only the data relevant to your request is sent.

    Meeting Transcripts

    When using the AI note-taker for meetings, the meeting audio is transcribed and then processed by AI to generate summaries, action items, and key takeaways.

    AI Semantic Memory

    AI42 includes an AI semantic memory system that allows the assistant to remember information about you across conversations, creating a more personalized experience.

    How It Works

    During conversations, the AI may identify and extract key facts, preferences, relationships, goals, and behavioral patterns. These "memories" are stored in your account and can be used to personalize future AI interactions. For example, if you mention you prefer morning meetings, the AI may remember this and suggest morning time slots when helping you schedule.

    What Gets Stored

    AI memories are structured facts extracted from your conversations, such as preferences, habits, relationships, goals, and other contextual information you share. Raw conversation content is not duplicated into memories — only distilled facts.

    How to Opt Out

    You can disable AI memory extraction at any time through your account settings. When disabled, the AI will no longer extract or store new memories from your conversations. Existing memories will remain until you explicitly delete them.

    How to Delete AI Memories

    You can view and delete individual AI memories or bulk-delete all memories through the AI Memory section in your account settings. Deleted memories are permanently removed and cannot be recovered. You can also request complete deletion of all AI memories by contacting us at privacy@ai42tech.com.

    AI Limitations

    It is important to understand the limitations of AI technology:

    Hallucinations

    AI models can and do generate information that is factually incorrect, fabricated, or misleading. This is an inherent limitation of current AI technology known as "hallucination." Always verify important information from authoritative sources.

    Errors & Inconsistencies

    AI may produce errors in reasoning, calculations, summaries, or code generation. It may also give inconsistent answers to the same question asked in different ways. Do not rely on AI output without verification.

    Inappropriate Content

    Despite safety filters and guardrails, AI models may occasionally generate responses that are biased, inappropriate, or offensive. We actively work to minimize these occurrences through provider selection and system prompts, but they cannot be entirely eliminated.

    Not a Replacement for Professional Advice

    AI-generated content is not a substitute for professional advice from qualified experts. This includes, but is not limited to, financial advisors, attorneys, medical professionals, accountants, and therapists. Always consult appropriate professionals for important decisions.

    Knowledge Cutoff

    AI models have a training data cutoff date and may not have knowledge of recent events or developments. When current information is critical, use the AI's web search capabilities or verify independently.

    Reporting AI Issues

    If you encounter any of the following, please report it to us so we can investigate and improve the system:

    • AI producing consistently incorrect or harmful information
    • AI generating inappropriate or offensive content
    • AI memory storing incorrect or unwanted information
    • AI behaving unexpectedly or in ways that cause concern
    • Security or privacy concerns related to AI processing

    Report AI Issues

    Email: support@ai42tech.com

    Security Issues: security@ai42tech.com

    Privacy Concerns: privacy@ai42tech.com