Navigation

Security & Privacy

How AI Anywhere protects your data and maintains user privacy.

3 min read

Security and privacy are fundamental to AI Anywhere. We've designed our platform with a privacy-first approach that minimizes data collection, encrypts all communications, and gives you full control over your information.

Privacy-First Design: AI Anywhere is built on the principle that your users' data should remain private. We don't store text content, and all AI processing happens in real-time without retention.

Data Handling & Storage

No Text Storage

The text your users enter is never stored on our servers. When a user clicks the Helper button, their text is:

  1. Sent securely over HTTPS to our AI processing service
  2. Processed in real-time to generate suggestions
  3. Immediately discarded after processing

We don't maintain logs, databases, or any persistent storage of user text content.

What We Store

AI Anywhere only stores configuration data necessary to provide the service:

  • Helper configurations: Your Helper Answers, keywords, and Helper settings (selector) stored securely in your account
  • Account information: Your email, account preferences, and billing information (standard account data)
  • Usage metrics: Aggregated, anonymized statistics about Helper usage (e.g., "Helper was used 50 times this month"; no text content included)

We do not store, log, or retain any user-submitted text content.

Encryption & Security

HTTPS-Only Communication

All communication between your site, users' browsers, and AI Anywhere's servers is encrypted using TLS 1.3. This ensures:

  • Data in transit cannot be intercepted or read by third parties
  • Authentication tokens are transmitted securely
  • API requests are protected from man-in-the-middle attacks

CSRF Tokens

If your application uses CSRF (Cross-Site Request Forgery) protection, AI Anywhere uses CSRF tokens that:

  • Are transmitted securely over HTTPS
  • Are validated server-side for each request
  • Help prevent unauthorized actions
  • Can be regenerated if needed

Best practice: If using CSRF tokens, ensure they're stored securely and not exposed in client-side code or public repositories.

Privacy Practices

No Tracking or Analytics on User Text

We don't track what users type, analyze content for advertising, or use text for training AI models. Each request is independent and not linked to user identities.

Minimal Cookies

AI Anywhere uses only essential cookies for functionality (such as session management). We don't use tracking cookies, advertising cookies, or cross-site tracking.

GDPR & Privacy Regulation Compliance

AI Anywhere is designed to comply with GDPR, CCPA, and other privacy regulations. Since we don't store personal text content, there's minimal personal data to protect, and what we do handle is managed according to strict privacy standards.

Security Best Practices for Users

For Site Owners:
  • Protect your auth token: Never expose it in client-side code if avoidable, use environment variables in server-side rendering
  • Use HTTPS: Always serve your site over HTTPS to ensure encrypted communication
  • Regenerate tokens: If you suspect a token is compromised, regenerate it immediately in your dashboard
  • Monitor usage: Regularly check your dashboard for unusual activity or unexpected usage patterns
  • Keep updated: Use the latest snippet version; we update our CDN with security improvements regularly

Data Processing Addendum (DPA)

For enterprise customers or organizations requiring formal data processing agreements, AI Anywhere offers a Data Processing Addendum (DPA) that:

  • Formally documents our data handling practices
  • Establishes responsibilities for both parties
  • Complies with GDPR requirements for data processors
  • Can be customized for your organization's needs

To request a DPA, contact our support team at support@ai-anywhere.ai or through your dashboard.

Incident Response

In the unlikely event of a security incident:

  1. We will notify affected users within 72 hours of discovery
  2. We will provide clear information about what happened and what data (if any) was affected
  3. We will take immediate steps to remediate any vulnerabilities
  4. We will work transparently to restore security and prevent future incidents

Questions or Concerns?

If you have questions about security or privacy practices, or need to report a security concern:

Your Privacy Matters: We're committed to maintaining the highest standards of security and privacy. If you see any way we can improve, please let us know.