Brand Data Security
Your designs are your competitive advantage. Here's how we protect them.
Will my designs train your AI?
No. Our AI providers (Anthropic, Black Forest Labs, Runway) operate under enterprise API agreements with zero-retention policies. Your inputs and outputs are never used for model training.
Where is my data stored?
Your generated assets are stored on Storj, a decentralized encrypted storage network. Files are encrypted client-side, split into erasure-coded pieces, and distributed across independent nodes globally. No single operator can access your complete files.
Who can access my designs?
Only you (the account holder) can access your designs and generated content. Our team does not view customer content unless you explicitly share it with us for support purposes. All API calls use encrypted transport (TLS 1.3).
Can I delete my data?
Yes. You can delete individual assets at any time from your library. For complete account erasure (GDPR right to erasure), email privacy@smasher.studio. We process deletion requests within 30 days, permanently removing all data from our systems and storage.
How is authentication handled?
We use industry-standard JWT authentication with secure httpOnly cookies. Passwords are hashed with bcrypt. We support magic link authentication as a passwordless alternative.
What about payment security?
All payment processing is handled by Stripe, a PCI DSS Level 1 certified processor. We never store credit card numbers on our servers.