Trust & security
Last reviewed:
Ascanti holds your goals, plans and notes, so it has to be safe to rely on. This page explains, in plain language, how we protect your data today. It describes only what is in place now; the one thing still to come is marked as planned.
Ascanti is in private beta and is run by a small team. For how we collect and use personal data, see our Privacy Policy.
- Your data stays yoursExport everything at any time, or delete your account. We don't sell your data or show ads.
- Strong sign-inTwo-factor, passkeys, breached-password checks and automatic sign-out of idle devices.
- Encrypted where it mattersHTTPS everywhere. Credentials, uploaded files and backups are encrypted at rest.
- Backed up continuouslyAn off-site copy about a second behind, encrypted nightly copies, and a restore test every week.
- AI that only suggestsAI can't change anything until you accept, isn't trained on your data, and can be switched off.
- Staff access is limited and loggedOur admin tools show account activity, not your content, and record every look.
1. Your data is yours
- Export at any time. Settings › Data › Export & backup downloads everything in your account as JSON, or a readable Markdown document. The export leaves out secrets such as your password, sign-in sessions and access tokens.
- Delete your account. Settings › Account › Delete account removes your account and everything linked to it from our live database straight away, in one step. In a business organization, an admin manages member accounts.
- Deleted data leaves our backups as they expire. Backups are kept on a fixed schedule (daily copies for about a month, a few weekly and monthly copies for up to a year) and then deleted automatically. We don't restore single accounts from them.
- No selling, no ads. We don't sell your personal information, share it for advertising or use advertising or tracking cookies.
- Calendars stay read-only. Calendars you connect are read, never changed, and you can disconnect them at any time.
The Privacy Policy lists what we collect, the companies that help us run Ascanti, and the few records kept after an account is deleted.
2. Account security
Passwords
- New passwords need at least 12 characters, and any password found in a known data breach is refused. The breach check sends only a short fragment of a one-way hash of the password, never the password itself.
- Passwords are stored only as a salted one-way hash.
- We email you when your password changes, and when two-factor or passkeys are added or removed.
Two-factor and passkeys
- Two-factor sign-in with a code from an authenticator app, with single-use recovery codes.
- Passkeys, so you can sign in with Face ID, Touch ID, Windows Hello or a security key.
- Two-factor is required for Ascanti staff, and for admins of business organizations after a short setup period.
Sign-in protection
- Repeated wrong passwords pause sign-in for that account for a few minutes, and sign-in attempts are rate-limited, to stop password guessing. Our team is alerted when an account is paused this way.
- A password reset link alone can't take over an account that has two-factor: the second step is still needed.
- Sign-in cookies can't be read by scripts on the page, and every request that changes data is checked against cross-site forgery.
- A strict content security policy stops the browser from running scripts that didn't come from Ascanti.
Devices and idle sign-out
- Settings › Security › Signed-in devices shows where you're signed in. Sign out one device, all others, or everywhere.
- A device is signed out after 7 days without use, and always 14 days after it signed in. Staff accounts are signed out after 12 hours without use.
- Optional extra protection after account recovery pauses your connected apps after a password or two-factor reset until you confirm it's you. A business organization's admins can require it.
3. Encryption
In transit
- Ascanti is served only over HTTPS, and browsers are told to always use HTTPS for it.
- Traffic is also encrypted between our network provider and our servers, and on our connections to calendar services and to the companies that help us run Ascanti.
At rest
- Credentials such as calendar access tokens and calendar links, two-factor secrets, webhook signing secrets and connected file-service tokens are each encrypted (AES-256-GCM) with a dedicated key, kept separate from the secrets that protect sign-in.
- Passwords, recovery codes, API keys and sign-in sessions are stored only as one-way hashes, so they can't be read back from the database.
- Files you upload are stored encrypted by our storage provider.
- Backups are encrypted (see Backups and recovery).
Your everyday content (goals, tasks, notes and plans) is kept in our database on servers only we can reach. It is protected by the access controls on this page rather than by a separate layer of encryption inside the database.
Files you upload
- Every file is checked for viruses before it can be downloaded, and nothing is let through unchecked.
- File types are checked from the file's contents, not its name. Programs, scripts and web pages are refused.
- Location and other hidden metadata are removed from common photo formats.
- Files are private to your account and download links expire after a few minutes. Files and file links are never sent to AI.
4. Infrastructure and monitoring
- Hosting: our servers and database are in a data center in the United States.
- Network protection: all web traffic passes through Cloudflare, which provides encryption, a web application firewall and bot protection. Our servers accept web traffic only from Cloudflare.
- Separation between accounts: every request is checked against the account and workspace it belongs to. An automated test calls every part of the app as a different account and fails the release if anything leaks.
- Tested releases: every update must pass the full automated test suite, including browser tests, before it ships. Updates go live without downtime: the new version starts next to the old one, is health-checked, and only then takes over, so a bad release can be rolled back quickly.
- Monitoring: server errors, failed backups and suspicious sign-in activity alert our team automatically. Error messages carry a short reference number, so support can find what went wrong without looking at your data.
- Security reviews: in October 2026 we reviewed Ascanti against the OWASP Top 10 and the OWASP Application Security Verification Standard, with a threat model and automated scanners, and we fix what we find in order of risk.
5. Backups and recovery
- Continuous off-site copy. Every change to the database is copied to separate cloud storage, away from our servers, about a second after it happens. We can restore the database to a point in time in the last 30 days.
- Encrypted nightly copies. Each night a full copy is checked and encrypted with our own key before it leaves the server, then stored off-site in storage that locks each copy for 30 days, so it can't be changed or deleted from our servers.
- A copy before every update, also encrypted, so a release can be undone.
- Tested every week. An automated job restores the latest backups each week and checks them, so we know they work rather than assume it.
- Watched around the clock. Backups are checked every few minutes, and our team is alerted if a copy falls behind or a job fails.
- Planned: an additional nightly copy on hardware we own, outside any cloud provider.
The continuous copy is encrypted at rest by the storage provider; the nightly and pre-update copies are encrypted by us before they are stored.
6. AI
Coach and the other ✦ features suggest; you decide. They run on Claude, made by Anthropic, through Anthropic's commercial API.
What AI can't do
- Change your goals, tasks or projects until you click to accept a suggestion. Most accepted changes can be undone.
- Delete anything on its own.
- Change your settings, plan, billing, password or sign-in.
- Send email or messages for you.
- See or change anyone else's account. Every accepted suggestion is checked again on our server, and must point at your own items.
- Reach your account, our database or the internet. The AI only returns text, which our app checks.
Your data and AI
- Each feature sends only what it needs, at the moment you use it. The help article "Understand privacy and AI features" lists what each one sends.
- Never sent to AI: your journal, your Daily Notes, events from calendars you connect, your files and file links, and your password and sign-in details.
- Under Anthropic's commercial terms, data sent through its API isn't used to train its models, and we don't use your data to train AI models either. Anthropic keeps it only for a limited time for safety checks, under its own policies.
- The off switch: turn off Use AI features in Settings › AI. Then nothing you type or store in Ascanti is sent to the AI service, and everything else keeps working.
AI can be wrong, so check suggestions before you accept them.
7. Staff access
- Metadata by default. Our admin tools show account details and activity, such as sign-ins, devices and how often features are used. They don't show your content.
- Content only for a reason. We look at your content only when you ask us to help, to keep the service secure and working, or when the law requires it. Support requests carry technical details, never your content; if we need to see something, we ask you to show us.
- Every look is logged. Each time staff open a person's or a workspace's data in our admin tools, it's recorded: who, when, what and why. Seeing a full IP address needs a written reason, and is logged before it's shown.
- Protected staff accounts. Staff accounts need two-factor and are signed out after 12 hours without use. Making someone staff, or removing them, needs the acting admin to confirm it's them.
- Workspace admins in a business organization can see their members' names, roles and project and task titles, and their workspace's security log, but never members' journals, notes, Pages, habits or personal goals. The Privacy Policy lists exactly what they see.
8. Report a security issue
If you think you've found a security problem in Ascanti, please email [email protected]. Our contact details are also published in our security.txt file.
- Tell us what you found and the steps to reproduce it.
- Please use only your own account or test accounts, and don't access, change or delete other people's data.
- Please give us a chance to fix the issue before you share it publicly. We'll keep you updated on what we're doing about it.
Questions about this page, or need more detail for a security review? Email [email protected]. For privacy requests, email [email protected].