Security you can verify, claims we can keep
We're an early-access product, so this page says exactly what we do today, what we don't claim, and what's planned. If you need something that isn't here, ask: hello@spiritualityhealing.net.
Files aren't kept
Your document is read to make the draft and discarded when the request finishes.
Drafts stay with you
The draft is saved only in your browser's local storage until you export or discard it.
No trackers
No cookies, analytics, ads, or third-party scripts or fonts on this site.
Data flow
- You upload a file or paste text in the app. It travels over HTTPS to our server.
- The server reads it and sends the content to Anthropic's API to plan and write the draft.
- The draft streams back to your browser and is saved in local storage on your device.
- The uploaded file is discarded when the request finishes. We don't save it.
We keep technical metadata for each drafting request (time, a salted hash of your IP address, file type and size, token counts, success) to manage costs and fix errors, never the content of your document or draft. Daily-limit counters are deleted after 30 days.
AI processing
Coursecast is built on Anthropic's Claude API. Anthropic's commercial terms don't allow API inputs or outputs to be used to train its models. Anthropic may keep API data for a limited period for safety and abuse monitoring, as described in Anthropic's privacy policy. We don't have a zero-data-retention arrangement and don't claim one.
Application security
- HTTPS only, with HSTS.
- A strict Content Security Policy: scripts, fonts and connections only from this site; no inline scripts.
- No third-party scripts, fonts, analytics or advertising.
- The drafting endpoint is protected against use from other websites and rate-limited per person per day.
- Private configuration and data live outside the public web folder.
- Forms use a honeypot and timing check instead of tracking-based CAPTCHAs.
What we don't claim
Planned
As accounts, saved projects and team workspaces arrive, we'll publish how that data is stored, encrypted, retained and deleted before those features launch, and update the Privacy Policy first. Enterprise controls (SSO, audit logs, data residency options) will follow customer demand and will be listed here only when they exist.
Controls we're designing in
- Permission-aware provenance: training never reveals what a learner couldn't read in the source.
- Classification inheritance: a course inherits the sensitivity of its most sensitive source.
- Model registry and private eval replay: qualify a new AI model version against your own eval set before adopting it.
- Generation provenance: which model, prompt version and sources produced each draft.
- Human gates: nothing reaches learners without named approval.
- Audit logs: who did what, when, for every workspace.
These are design commitments for features that don't exist yet, listed so you can hold us to them.
Report a security issue
Email hello@spiritualityhealing.net with "Security" in the subject. Please give us a reasonable chance to fix an issue before disclosing it. We don't run a paid bounty program.
Questions from your security team?
We'll answer them straight, including "not yet".