How AI Wave protects your data.
Your data is yours. We protect it, we don't sell it, and we never use it to train AI models.
- Nothing publishes without your approval. Every post, email, and ad requires your explicit OK.
- Your data is never used to train AI. Your content, brand data, and business information stay in your workspace.
- We never see your passwords. Connected accounts use standard OAuth, the same secure process used by every major app.
- Export anytime. Download your content, campaigns, and analytics whenever you want.
- Delete anytime. Request full account deletion. All data is permanently removed within GDPR timeframes.
Infrastructure and security measures.
Encryption
All data is encrypted at rest and in transit. Connections use TLS 1.2+.
Hosting
AI Wave runs on Vercel (edge compute), Supabase (database), and Cloudflare (CDN and security). All providers maintain SOC 2 compliance.
Access control
Multi-tenant architecture with strict data isolation between accounts. Role-based permissions within each workspace.
Monitoring
Continuous infrastructure monitoring with real-time alerts for anomalies and security events.
Authentication
Managed by Clerk. Email/password and OAuth login with optional multi-factor authentication. AI Wave never handles or stores user passwords directly.
Human approval for every external action.
AI Wave has a hard rule: no external action happens without human approval. This applies to:
- Social media publishing: every post requires approval before going live.
- Email campaigns: every send requires approval before delivery.
- Ad campaigns: every launch and every budget change requires approval.
- External integrations: any action that writes data to your connected tools requires approval.
You see exactly what will happen, confirm it, and only then does the system execute. No exceptions. No surprises.
What we do, and don't do, with your data.
We store
Your brand profile, content, campaign configurations, analytics, and connected account credentials (secure authorization keys, never passwords).
We don't
Sell your data. Share it with third parties for advertising. Use it to train AI models. Access your accounts beyond what's needed to run your campaigns.
GDPR compliance. AI Wave is designed to comply with GDPR from the ground up. You can request data export, data portability, rectification, or deletion at any time.
Security questions or concerns?
Contact us at contact@ai-wave.co.
For responsible disclosure of security vulnerabilities, email contact@ai-wave.co with details. We take every report seriously and will respond within 48 hours.