Trust & Safety
How visualworks protects your work — built into the platform, not bolted on
Your content is never training data
Briefs and decks are processed transiently to generate your work. We enforce zero-data-retention routing on every AI call: model providers that retain prompts or train on them are excluded at the infrastructure level, not by policy alone.
Where your data lives
Your account, decks and files are stored in the United States (Ohio) with seven days of point-in-time backups. The app itself runs on a global edge network, so it answers from a location near you while the data stays put. Files you attach are removed 30 days after upload; the decks you built from them keep working.
Your files are physically isolated
Customer documents, decks and exports live in a private storage bucket with no public domain attached — they are reachable only through your authenticated session. The public CDN serves catalog imagery only, from a separate bucket that never holds customer files.
AI safety screening, before you pay
Every generation request passes a two-tier safety gate — instant rule-based checks plus an AI content-safety review —
before any credits are reserved. A refused request never costs you anything. The categories screened are exactly the ones published in our
acceptable-use terms.
Payments we never touch
Checkout, cards and UPI are handled end-to-end by Razorpay, a PCI-DSS-certified processor. Payment credentials never reach our servers; we hold only the transaction record your invoice needs.
Billing you can audit
Credits are governed by a server-side ledger — every grant, hold, spend and automatic refund is a recorded entry, and failed generations return their credits without you asking.
Hardened by default
Encrypted in transit everywhere, strict security headers and content security policy, sandboxed rendering of generated slides, audited admin actions, and rate limits on everything public. Security reports are welcome at
support@visualworks.ai (see
security.txt) — we respond fast and credit good-faith researchers.
Your rights, honoured
Access, export, correction and deletion of your data on request, acted on within 30 days, under GDPR and India's DPDP Act. Details in the
privacy policy.