
Security and data
Where your data lives, and how it is handled.
Strategy work is confidential. Here is what happens to what you put in, said plainly and without small print: where it lives, who can see it, and what the AI is told.
Where data lives
All operations in the EU
The application runs in Frankfurt (Render) and the database lives in Ireland (Supabase). None of your data is stored outside the EU by us.
Your data is yours
Charters, strategy projects, decisions and journals are tied to your account and separated from everyone else's with row-level security in the database itself, not just in the application.
Payments with Stripe
We never see card details; they are handled by Stripe, certified for exactly that (PCI DSS). We keep only the payment reference, so your receipt can be found again.
How it is handled
Encrypted all the way
All traffic between your browser and our servers is encrypted (TLS), and the database encrypts data at rest.
Access on a need basis
Only what is needed to deliver the tool is retrieved. Nothing is sold on, and nothing is shared with third parties beyond the processors that run the platform.
Web statistics without surveillance
We use Plausible for visitor numbers: no tracking cookies, no profiles, no resale.
And what does the AI see?
The AI gets the case, not your life.
When the board works or the coach challenges, the necessary parts of your case are sent to our AI provider through one controlled channel. Concretely:
- The AI gets what you have entered in the current tool, plus the public sources you have approved: register data, annual reports and your website.
- Your data is not used to train the models. We use Anthropic as model provider via API, where customer data is not part of training.
- All model calls pass through one layer in our code. The provider can be switched with a single setting, for example to EU operation via Amazon Bedrock, without changing the products.
- The AI's answers are labelled as what they are: proposals and challenge. The decision stays with you, and it says so on every page.
You can always request access to, correction of or deletion of your data. Write to us and it happens without delay.
The details, including processors and your rights under GDPR, are in the privacy policy.
Questions about security? Write to cdla@upscalestrategy.com and a human will answer.