INOVAYT has developed a robust infrastructure to ensure the privacy of its clients.
- All client data (settings, input, and output) is stored in AWS and it is encrypted.
- All client data is insulated from other client data. It is not even stored in relational tables.
- Client identification is not embedded with any input or output data.
- Client data is never used for training in any way.
- There are no backup copies of client data (other than what AWS implements behind-the-scenes).
- Opaque (GUID-like) URLs are used for all results. All such URLs are redirected to HTTPS, if necessary.
- There are some 3rd party services used. Their privacy policies have been fully vetted and comply with the INOVAYT standards.
- Calls made to 3rd party services do not have associated client identification (they are anonymous calls in that sense).
- Sign-in is implemented via Google Firebase.
- Personal user data is not stored or processed except as is needed for transient sign-in ability, thereby minimizing GDPR applicability. Nonetheless, INOVAYT adheres to rigorous data privacy and security protocols similar to those required under GDPR, ensuring all data remains confidential and secure.