Trust
Last updated October 1, 2026
The short version for a security review. The detail is on Security and Privacy.
Where your data lives
Accounts, rooms, messages, AI replies and uploaded files are stored in Supabase: its Postgres database, its sign-in service and its file storage. The app itself runs as one server we operate with our hosting provider. The master key that protects saved API keys is held in AWS’s hardware key-management service and never leaves it.
Who processes it
These companies process data for us, each for one job. We add no third-party analytics, ad trackers or data brokers, and we sell nothing.
Anthropic · Claude replies
The messages someone pointed at Claude, the earlier asks and replies in that chat, display names and attachments on those messages.
OpenAI · GPT replies
The messages someone pointed at GPT, the earlier asks and replies in that chat, display names and attachments on those messages.
Google · Gemini replies, and Google sign-in
For Gemini, the same as above, on paid tier access. For sign-in, the Google sign-in itself, if you choose it.
Supabase · Database, sign-in, realtime and file storage
Everything the product stores: accounts, rooms, messages, replies and files.
Stripe · Payments
Your card details, which Stripe collects directly. We never see the card number.
Resend · Email delivery
The recipient address and the email we send.
GitHub · Repository features, for rooms that connect one
What a commit needs: the proposed files, a commit message, the branch, and who asked in which room.
Expo · Push notifications for the phone app
The device push token and the notification: one line of title and a short preview, with anything that looks like a credential hidden.
Amazon Web Services · Key management (KMS)
Requests to wrap and unwrap the data keys that seal API keys. Never an API key, and never a message.
Our hosting provider · Runs the app server
Requests in transit and the server logs, which carry no message bodies or keys.
How API keys are protected
- Each saved key is encrypted with AES-256-GCM under its own data key. That data key is wrapped by a master key in AWS KMS and bound to your account, so a key copied to another row fails to decrypt.
- A copy of our database alone cannot reveal a key. Keys are decrypted in server memory for one request, never logged, and never sent to a browser.
- After saving, only the last four characters are ever shown, to anyone, including you.
- splitscreen’s own provider keys, used when you pay with credits, are sealed the same way and can never be swapped for a member’s.
No model training
splitscreen does not train AI models on your content. Under Anthropic’s, OpenAI’s and Google’s API terms, content sent through their APIs is not used to train their models by default, and splitscreen uses paid tier Gemini access, which is not used to improve Google’s products. Chat nobody pointed at an AI is never sent to a model provider by us.
Access and spending controls
- Every table is behind row-level security, and budget changes run only through database functions the browser cannot call.
- Budgets and caps are reserved in the database before any AI call starts, so a reply cannot cost more than what is left.
- Two-factor sign-in with an authenticator app, in Settings.
- Workspaces with roles (owner, admin, billing, member) and email domains proved by a DNS record.
- Single sign-on (SAML) for verified domains, set up with splitscreen support. It is included on business plans.
- Room owners see who joined, left, was removed or changed settings, for 90 days.
How long we keep things
- Messages, replies and files: until you or a room owner deletes them, or you delete your account.
- A room’s activity record (joins, removals, settings changes): 90 days.
- Product analytics events: 180 days, never with message content.
- Records of purchases: 7 years after the sale, as tax law requires, with nothing that says who you were once your account is deleted.
- Files sent to a code sandbox: uploaded to the provider with a one-hour expiry and never reused.
- Server logs: kept by size, a few files at most, with no message bodies or keys.
Deleting your account and data
You can delete your account yourself, in Settings under Account, and it is permanent. Revoking an API key takes effect immediately. If you have a subscription or unused credit to refund, email contact@splitscreen.chat from the address on the account and we cancel, refund and delete together within 30 days. The privacy page lists exactly what goes and what stays.
Report a security issue
Email contact@splitscreen.chat. We read security mail first, and will credit you if you want. The same address is in our security.txt.