Early accessFree during early access: draft a course from your own document in minutes.Try it now →
Trust center

Security you can verify, claims we can keep

We're an early-access product, so this page says exactly what we do today, what we don't claim, and what's planned. If you need something that isn't here, ask: hello@spiritualityhealing.net.

Files aren't kept

Your document is read to make the draft and discarded when the request finishes.

Drafts stay with you

The draft is saved only in your browser's local storage until you export or discard it.

No trackers

No cookies, analytics, ads, or third-party scripts or fonts on this site.

Data flow

  1. You upload a file or paste text in the app. It travels over HTTPS to our server.
  2. The server reads it and sends the content to Anthropic's API to plan and write the draft.
  3. The draft streams back to your browser and is saved in local storage on your device.
  4. The uploaded file is discarded when the request finishes. We don't save it.

We keep technical metadata for each drafting request (time, a salted hash of your IP address, file type and size, token counts, success) to manage costs and fix errors, never the content of your document or draft. Daily-limit counters are deleted after 30 days.

AI processing

Coursecast is built on Anthropic's Claude API. Anthropic's commercial terms don't allow API inputs or outputs to be used to train its models. Anthropic may keep API data for a limited period for safety and abuse monitoring, as described in Anthropic's privacy policy. We don't have a zero-data-retention arrangement and don't claim one.

Application security

  • HTTPS only, with HSTS.
  • A strict Content Security Policy: scripts, fonts and connections only from this site; no inline scripts.
  • No third-party scripts, fonts, analytics or advertising.
  • The drafting endpoint is protected against use from other websites and rate-limited per person per day.
  • Private configuration and data live outside the public web folder.
  • Forms use a honeypot and timing check instead of tracking-based CAPTCHAs.

What we don't claim

Plainly: Coursecast does not currently hold SOC 2, ISO 27001 or any other certification; does not offer SSO, SAML or SCIM (there are no accounts in early access); does not offer an SLA; and does not make training compliant with any regulation. AI drafts can contain mistakes and must be reviewed by people who know the material.

Planned

As accounts, saved projects and team workspaces arrive, we'll publish how that data is stored, encrypted, retained and deleted before those features launch, and update the Privacy Policy first. Enterprise controls (SSO, audit logs, data residency options) will follow customer demand and will be listed here only when they exist.

Controls we're designing in

  • Permission-aware provenance: training never reveals what a learner couldn't read in the source.
  • Classification inheritance: a course inherits the sensitivity of its most sensitive source.
  • Model registry and private eval replay: qualify a new AI model version against your own eval set before adopting it.
  • Generation provenance: which model, prompt version and sources produced each draft.
  • Human gates: nothing reaches learners without named approval.
  • Audit logs: who did what, when, for every workspace.

These are design commitments for features that don't exist yet, listed so you can hold us to them.

Report a security issue

Email hello@spiritualityhealing.net with "Security" in the subject. Please give us a reasonable chance to fix an issue before disclosing it. We don't run a paid bounty program.

Questions from your security team?

We'll answer them straight, including "not yet".