0%
Apple Β· Android

For IT & Procurement

Security & Trust

Straight answers to the questions an IT manager or procurement reviewer actually asks - not certification badges we don't hold. If something below isn't yet a self-serve feature, we say so.

Data & infrastructure

Where your data lives and how it's protected.

Where is data stored?

On managed cloud infrastructure (Firebase / Google Cloud). We don't run our own data centers.

Is data encrypted?

Yes - encrypted in transit (TLS) between the app and our infrastructure, and at rest by default through our cloud provider.

Are backups performed?

Our cloud infrastructure includes provider-level redundancy. We don't yet publish a formal backup SLA - if that's a requirement for your deployment, tell us and we'll scope it directly.

Is dedicated infrastructure possible?

Yes. Business uses our managed shared infrastructure with organization-level controls by default; dedicated databases or private-cloud deployment are optional, individually scoped in your agreement.

What audit capabilities exist?

We don't yet offer exportable audit logs as a self-serve feature. If audit trails are a requirement, contact us to discuss what's possible for your deployment.

Access & control

Who can see organizational data, and how access is managed.

Who can access organizational data?

Access is scoped to your workspace and governed by role-aware access controls - team membership and permissions determine what a given user can see and do.

Is SSO available?

Not yet as a self-serve feature on the standard Business plan. If SSO/SAML is a requirement, contact us - it's on our roadmap for larger deployments.

Can data be deleted or exported?

You can request deletion of your account and workspace data at any time, or delete your account from within the app. Self-serve data export isn't built yet - reach out and we'll get you what you need directly.

AI & third parties

How ClicktAI Copilots handle your content, and who else sees it.

Is organization data used to train models?

No. We select AI providers who commit contractually not to use your workspace content to train their general-purpose models - and require the same commitment from any provider we add in the future.

Which AI providers receive content?

Only the content relevant to the specific request from the module you're working in - never your whole workspace. On Free, you connect your own provider key. On Business, your admin assigns a Clickt-approved provider.

Can AI be disabled?

AI isn't active by default. On Free, nothing happens until you connect your own key. On Business, your administrator chooses which users have Clickt-provided AI enabled - it is not switched on for every seat automatically.

Is bring-your-own API key possible?

Yes, on the Free plan. You connect your own AI provider key, and your requests are then governed directly by that provider's own terms - Clickt does not store or transmit your credentials beyond what's needed to process each request.

What happens during an incident?

If a breach affecting your personal data occurs, we notify affected users - and any regulator required by law - without undue delay. Nothing changes to your workspace without you knowing about it first.

This page is a summary for quick reference. The full legal detail - data sharing, retention, international transfers, your rights, and how to reach us - lives in the Privacy Statement.

Reviewing Clickt for your organization?

Send us your security questionnaire or compliance checklist directly - we'll answer what we can and tell you plainly where we're not there yet.

Contact Us