Security Overview
Last Updated: September 28, 2026
Effective date: September 28, 2026. Version: 1.4.
Security That Starts with an Honest Answer
We run a dedicated database for your business, and we pay for it. Your data is locked on your screen before it ever reaches that database, with a key only you hold. We store it and keep it running. We cannot read it.
What We Can and Cannot See
We can see that your account exists, when you signed in, and how much storage you use. We cannot see what you saved. Nobody can make us hand over what we cannot read. We do not sell data, share it for advertising, or train AI on it.
Leaving Is Not Losing
You can export everything in a standard format at any time and take it with you. You do not have to be leaving to do it, you do not need our permission, and you do not need us at all. The download is in your desk. Your data goes with you.
What does not go with you is the project. It is ours, it stays in our Supabase organization, and we keep paying for it. We would rather say that than imply you are taking infrastructure you never owned.
If you cancel, your project stays up and your data stays exportable for 30 days from the day you cancel, and never for less than the rest of the period you already paid for. When that window closes we keep your locked copy, free, so you can take it or come back. Only your key opens it. Ask us to delete it and we will.
Deletion is the door you can close on us. Tell us to delete your data, while you are a customer or after you leave, and we delete it within 30 days and clear backups within 90 days. That ends our access completely. The mechanics are in Section 11 of the Data Processing Addendum.
Your AI account stays yours throughout. The operator runs on Claude under your own Anthropic subscription, and your conversation history sits with Anthropic under that account, not with us.
Changes Built to Be Undone
Every change we make to your system is written to a log inside your own database, which you can read any time without asking us. Each change is reviewed before it ships and carries its undo path, so fixes are built to be undone.
Inside the Platform Layer
Row-level security is enforced on the tables we ship. Access on our side runs on named per-user accounts with least privilege and multi-factor authentication where supported, with no shared logins. Data in transit is encrypted with TLS. Your data is encrypted on your device before it leaves, and again at rest by the hosting platform.
Payments
Checkout and billing run on Stripe. Full card numbers never touch our systems; we see transaction status and limited card metadata only.
Credentials
We will never ask for your passwords, API keys, or recovery codes: not in chat, not by email. The product’s own guidance tells you the same thing: never paste credentials into any AI chat. If something claiming to be us asks for a credential, treat it as fraud and tell us.
When Something Goes Wrong
If a security incident affects personal data we hold or host, we notify affected clients without undue delay, with what we know and what we are doing about it, per our Privacy Policy and, for business customers, the defined notice window in the Data Processing Addendum. That covers the copy we keep for departed customers too, for as long as we hold it.
What We Do Not Claim
We are a young company and we will not wear badges we have not earned. We do not currently hold third-party certifications such as SOC 2 or ISO 27001. We do not run a 24/7 monitoring desk, and we will not call anything “bank-grade.” What we do claim: your data is locked with your key, and we cannot read it. When third-party attestations become real, they will be added here.
Report a Vulnerability
Good-faith security research reported responsibly is welcome: hello@firstgear.ai. We will not pursue action against good-faith research conducted in line with this page. We do not commit to a response time. Please do not access, modify, or exfiltrate any data that is not your own while testing, and give us a reasonable window to fix an issue before disclosing it.
Contact Us
Questions about security? Email hello@firstgear.ai.
First Gear AI LLC
5900 Balcones Drive STE 100
Austin, TX 78731