Trust & security
What ShadowAI actually does with your data — plainly, without marketing language.
Models and providers we use
ShadowsAI runs on its own engines — Core, Flux, Edge, Sharp, Max and Ultra — and we don't publish which third-party AI infrastructure sits behind them. What we will tell you is how your data moves:
- Chat, ShadowCode and presentations: processed by third-party AI infrastructure providers under contract.
- Images: third-party image-generation infrastructure.
- Voice: a third-party speech provider.
- Plugins: Google's Gmail and Workspace APIs, only for accounts that connect them.
Your prompts and any files you attach are sent to whichever provider handles that request, subject to that provider's own data-handling terms.
Data retention
Chat, image, and code conversation history lives in your browser's local storage by default, not on our servers — clearing your browser storage or using a different device/browser starts a fresh history there. Signing in additionally syncs your conversation list to our database so it's available across your own devices.
A conversation only becomes visible to anyone else if you explicitly use Share & Collaborate on it — that creates a real, server-stored record with whatever access level (view/comment/edit) you choose, until you turn sharing off or delete it.
Account records (plan, credits, connected plugins, saved personas, usage history) are stored in our database for as long as your account exists.
Encryption
All traffic to and from ShadowAI is encrypted in transit (HTTPS). Our database provider encrypts stored data at rest.
Gmail and Google Workspace OAuth tokens are additionally encrypted at the application level before being stored, using a server-side encryption key never exposed to the browser or to any API response.
Backups
Our database provider (Neon, a managed Postgres service) maintains its own automated backups and point-in-time recovery as part of its infrastructure.
Account deletion
To request account deletion, contact support (see the Support page). Deleting your account removes your stored profile, credits balance, connected plugin tokens, and server-stored conversation records; anything still only in your own browser's local storage is unaffected and can be cleared from your browser directly.
Data export
You can export a chat as Markdown or PDF directly from the chat header. Presentations already download as .pptx and PDF. ShadowCode projects can be downloaded as HTML directly from the result.
Subprocessors
Services that process data on our behalf: Vercel (hosting, file storage), Neon (database), Google (Gmail, Workspace and OAuth sign-in, for accounts that use them), Razorpay (payments), Resend (transactional email, where configured), and the third-party AI infrastructure providers described above, which we don't name individually.
If you need the full named list for a compliance or procurement review, email support and we'll share it under NDA.
Plugin permissions
Connecting Gmail or Google Workspace requests only the specific scopes each feature needs — send-only access for Gmail (we cannot read your inbox), and drive.file access for Workspace, which means we only ever see files ShadowAI itself created or that you explicitly opened with it, never your whole Drive. You can review what's connected and disconnect at any time from Plugins. Sending an email or creating/modifying a Doc, Sheet, or Slide always asks for your confirmation first.
Questions about any of this? Reach out from the Support page.