1.Encryption
All traffic runs over TLS 1.2 or higher. Data is encrypted at rest by our cloud provider using AES-256.
2.Data Isolation
Every table carries row level security, so a database read is scoped to the account that owns the row. Storage buckets are private by default and images are served through short lived signed URLs rather than public addresses.
The one deliberate exception is a presentation link you create yourself, which is unlisted and readable by anyone holding the URL until you expire it.
3.Internal Access
Access to production is limited to the engineers who need it, protected by multi factor authentication, and used only to operate the service or to resolve a support request you have raised.
4.Where Data Is Stored
Application data and uploads are stored in the United States. Image generation runs on our GPU processing providers, which receive an upload only for the duration of the job and do not retain it for training under our agreements. Payments are processed by Stripe and we never see full card numbers.
5.Retention And Deletion
Free tier uploads and outputs are deleted 30 days after creation. Paid tier content is retained until you delete it or close your account, then removed within 30 days. Deletion is available from your dashboard at any time.
6.Reporting A Vulnerability
Email security@realdesigns.ai with steps to reproduce. We acknowledge within 2 business days and will keep you updated until it is resolved.
Please give us reasonable time to fix an issue before disclosing it publicly, and do not access or modify data that is not yours while testing. We do not pursue legal action against researchers acting in good faith under those conditions.