Security & Data Handling

What we collect, where it is stored, the providers that help run the service, and how retained image-extraction compatibility is handled if re-enabled.

Last updated: 2026-05-31Effective date: 2026-05-31

DatumPilot (operated by IngeniVue Engineering Services Inc.) is built for engineers who work with sensitive, IP-bearing designs. This page describes, in plain language, what we collect, where it is stored, the providers that help us run the service, and how retained image-extraction compatibility is handled if re-enabled. We describe what the product does today and update this page as the product evolves toward general availability. This is our current security posture, not a certification.

Our security posture, not a certification

DatumPilot does not hold any third-party security certification or attestation. Nothing on this page should be read as a compliance certification. We describe the safeguards we operate today and tighten them as we approach general availability.

What we collect and where it is stored

We collect only the information needed to operate authenticated GD&T workflows: your account identity, billing details, the GD&T content you submit, and operational metadata such as usage counts for quota enforcement.

Application data is stored in our primary infrastructure: a managed PostgreSQL database on Supabase and application hosting on Vercel. We select regions appropriate to the service and refine our regional footprint as we approach general availability.

Data is encrypted in transit using TLS, and our managed infrastructure providers encrypt stored data at rest. Card details are handled by Stripe and are not stored on DatumPilot servers.

Sub-processors

We rely on a small set of vetted providers (sub-processors) to deliver the service. Each receives only the data needed for its function:

  • Supabase — managed PostgreSQL database for application data.
  • Vercel — application hosting and content delivery.
  • Clerk — authentication and account identity.
  • Stripe — billing and payment processing. We do not store full card numbers on our servers.
  • OpenAI— AI processing for GD&T interpretation and recommendation, plus retained image-extraction compatibility if an approved future issue re-enables it.
  • Upstash — rate limiting and abuse prevention.
  • Resend — transactional email delivery.
  • PostHog — product analytics, consent-gated and not yet enabled.

A current sub-processor list — with each provider’s purpose, processing region, and data categories — is available at /legal/subprocessors.

Image extraction compatibility

DatumPilot does not currently expose image upload in the Interpret UI. If a future approved issue re-enables feature-control-frame image extraction, we send the image to our AI sub-processor (OpenAI) to extract the GD&T content. DatumPilot does not store raw uploaded image snippets after extraction, and sends OpenAI requests with store=false. OpenAI processes the image and text as a sub-processor and may retain content under its API abuse-monitoring controls for up to 30 days, subject to its policies.

OpenAI applies a separate safety exception for content that violates its child sexual abuse material (CSAM) policies, which it may retain and report as required by law. This is the only category that falls outside the abuse-monitoring window described above.

We are working to confirm a zero-data-retention arrangement at the account level with OpenAI. Until that is confirmed, we describe the posture conservatively rather than asserting that content is permanently removed everywhere.

Telemetry and analytics

We use privacy-safe product analytics (PostHog) that are gated behind your explicit consent. Analytics remain disabled until you opt in, you can change your choice at any time through the consent control, and we keep raw GD&T content and any future uploaded images out of telemetry. See our Cookie Policy for details on consent and storage technologies.

Access and authentication

Access to the product requires authentication through Clerk. Saved reports and other persisted artifacts are owned by the user who created them, and the service enforces owner-scoped access so one account cannot read another account’s data.

If there is a security incident

If a security incident affects your personal information and creates a real risk of significant harm, we will notify affected users and the appropriate authorities as required by applicable law, and take steps to contain and remediate the issue. See our Privacy Policy for how breach notification works.

Learn more and contact us

For the full picture of how we collect, use, and protect data, read our Privacy Policy. To report a security concern, contact us at support@datumpilot.com.