STAYCHARTED AMT / PRODUCT

Security and your data

Understand how StayCharted handles model data, workspace access, masking, assistant connections, and deletion.

YOUR DATA, THROUGH ITS LIFECYCLE

Access. Prepare. Retain. Delete.

Know who can use a model, what masking changes, and what remains after an upload is deleted.

See retention periods ↓

Control who can use your data

Workspace roles

Assign Builder, Reviewer, and Viewer roles. Keep access appropriate to the work each person does.

Integration keys

Give integrations their own API keys and revoke keys you no longer need. Protect them in your own systems.

Assistant permissions

The Owner allows assistants, each model has an access switch, and the connection acts with the connecting person’s role.

Assistant providers receive the information read through a connection under your own agreement with them. Activity records changes made through the assistant.

PREPARE BEFORE TRAINING

Mask detected values. Review what remains.

AMT checks supported patterns such as email addresses, phone numbers, payment card numbers, and some secrets. Mask detected values, exclude rows, or keep them. Models trained with masking apply it to new text.

The checks do not detect every name, address, or sensitive free-text detail. Deleting an original upload also does not remove what an existing model learned; correct the dataset and retrain, or delete the model.

How personal-information checks work →
Review supported personal-information patterns
Review supported personal-information patterns · Sample data

RETENTION AND DELETION

Know what is removed, and when.

DataLive Service retention
Original text uploads and picture ZIPs90 days after upload, unless deleted sooner. Derived data and trained models remain.
Filled files24 hours after first download, or 7 days if never downloaded.
Files uploaded to fill but never run7 days.
Try-box questions30 days, unless feedback was given.
Example rows in an older validation report14 days after a newer version replaces it. Report figures remain.
Deleted workspace contentModels, files, datasets, and API keys removed immediately. Workspace name, billing history, and the deletion Activity entry remain.

These are live-Service deletion periods. Deleted storage versions can remain for up to 30 days; protected backups follow the periods in the Privacy Policy and DPA. Deleting an upload does not delete derived datasets, resized pictures, thumbnails, representations, or trained models.

Read the full retention policy →

Hosting, protection, and processing terms

United States hosting

Customer Content is currently stored and processed in the United States. The Privacy Policy explains international transfers.

Encryption and isolation

The Privacy Policy describes TLS in transit, encryption at rest for the database and content storage, and organization and workspace isolation.

Documented obligations

The DPA sets out processing obligations, security measures, and subprocessors. The legal documents govern the details summarized here.

Explore the details

Try it on your own examples.

Start with Free for text classification. Compare plans for AI models, Vision, and API access.