Legal
Security
How we keep your files, prompts, and account safe.
Encryption in transit & at rest
All traffic is TLS 1.2+. Uploaded files and outputs are encrypted at rest by our storage provider. Session cookies are HTTP-only and signed.
Isolated sandboxed execution
Every generated command runs inside an ephemeral, network-restricted container. Your files never share a process or filesystem with another user.
Aggressive deletion
Uploaded files and AI outputs are automatically deleted 24 hours after creation. You can delete chat metadata and your account at any time.
No model training on your data
We do not use your prompts, files, or outputs to train AI models. Our model vendors operate under zero-retention or short-retention agreements.
Minimal scopes
Google sign-in requests only basic profile and email. ReFile cannot read your Drive, Gmail, or anything else.
Responsible disclosure
Found something? Email security@denoiselabs.com. We respond within 72 hours and publicly thank reporters of valid issues.
Reporting a vulnerability
Please email security@denoiselabs.com with steps to reproduce. Do not publicly disclose until we've had a reasonable window to fix the issue (typically 30 days). We do not currently run a paid bounty, but we credit reporters of valid issues.