Security

Your data, under your control.

Security and privacy aren't a separate feature. They're the foundation Chartlo was built on. Here's how we protect your information at every step.

In-browser processing

Reading and analyzing your data happens on your device. The full content never leaves your browser.

No sensitive data sent to the AI

Columns with SSNs, tax IDs, emails, names, phone numbers and the like are removed automatically before anything is sent, and you can mark others as sensitive.

Encryption in transit

All communication with our servers and with the AI uses HTTPS/TLS.

Secure authentication

Sign in with email/password or OAuth providers, with sessions managed by dedicated authentication infrastructure.

Per-user isolation

Each account can only access its own dashboards and data, enforced by row-level security (RLS) policies in the database.

Usage limits

AI calls are rate-limited per user to protect the platform against abuse and unexpected costs.

Where your data is processed

When you upload a file, it is read and analyzed entirely in your browser. Column detection, statistics and chart building happen on your device: the full dataset is not sent to our servers.

When you save a dashboard to the cloud, only what you choose to keep is stored — privately and tied exclusively to your account.

What is sent to the AI

To generate dashboards, we send the AI the column names and types and a small number of sample rows (not the whole file). Before sending:

  • columns that look like personal data (SSN, tax ID, email, name, phone, address, password, tokens…) are removed automatically;
  • you can manually mark any column as sensitive to exclude it too;
  • cell values are never treated as instructions, only as data.

Authentication and isolation

Access is protected by authentication and by row-level security policies in the database: in practice, each user can only read and write their own records. Dashboards shared by link are served view-only, through a dedicated token, without exposing your account.

Responsible disclosure

Found a possible vulnerability? Write to seguranca@chartlo.com and give us a reasonable amount of time to investigate and fix it before any public disclosure. We appreciate the security community’s help.

Start securely.

Privacy by default, from upload to shared dashboard.

We use analytics to understand how Chartlo is used and improve the product. You can opt out at any time. Learn more.