This page summarises how 800 protects Customer Content in production, where data is processed, and which providers help deliver the service. It describes controls we maintain; it does not claim certifications we have not earned, and it does not guarantee that incidents cannot occur. For personal-data roles and rights, see the Privacy Notice. For commercial terms, see the Terms of Service.
Product surface
Marketing and product: eight-hundred.app and app.eight-hundred.app. Uploads, runs, credits, and exports happen after sign-in with a company email (or an allowed Google Workspace account).
Data locations
| Data category | Primary storage | Processing | Notes |
|---|---|---|---|
| Customer Content | EU (Ireland) | Application runtime; AI inference via Fireworks AI | Fireworks may process extracted text for a run outside the EEA under transfer safeguards and zero data retention for this inference path |
| Account Data | EU (Ireland) | Application runtime; Google for Workspace sign-in; Resend for codes | Authentication and email providers may process outside the EEA |
| Payment information | Stripe | Stripe Checkout / Managed Payments | We store payment confirmation metadata, not full card numbers |
| Product analytics | PostHog EU Cloud | Browser SDK + PostHog EU | Account ID and email domain; no document content |
| Security logs | Application hosting | Operational logging | Retained 90 days |
| Support communications | legal@eight-hundred.app | 24 months after the thread closes |
How we protect data
Transport encryption
Production traffic to eight-hundred.app and app.eight-hundred.app uses HTTPS so browsers connect over TLS.
Password handling
Passwords are hashed with scrypt and never stored in plain text. Google sign-in never shares your Google password with 800.
Signed sessions
Sessions are issued by Auth.js. Session secrets stay server-side. Signing out ends the session for that browser. Sessions last up to 30 days unless you sign out sooner.
CSRF protection
State-changing product and auth requests are checked against the expected app origin so forged sites cannot trigger actions as you.
Fresh Google sign-in
Google OpenID Connect requires a fresh re-authentication. We verify ID tokens (including auth_time) before creating a session.
Company-email gate
Self-serve signup requires a company email. Common consumer providers are blocked.
Payment integrity
Stripe Checkout is hosted by Stripe under Managed Payments. Webhooks are signature-verified before credits are granted. We do not store full card numbers.
Abuse resistance
Rate limits apply on sign-in, document runs, and other sensitive endpoints to reduce brute-force and flood risk.
Tenant scoping
We use tenant-scoping and access controls designed to prevent one customer from accessing another customer’s projects through the product.
Server-only secrets
API keys, database credentials, Stripe secrets, and auth secrets live in the server environment. They are not shipped to the browser.
AI provider errors
Raw provider errors are not shown to end users. Runs fail with safe product messaging while details stay in server logs for operators.
Analytics hygiene
Product analytics (PostHog EU Cloud) identify signed-in users by internal account ID and email domain, not full email. Event properties are limited so document text and model output are not sent.
AI processing
Fireworks AI (Fireworks.ai, Inc.) is the inference processor: its infrastructure receives and processes extracted document text for a run. A Kimi-family open-weight model runs on that infrastructure. The model weights do not themselves have a legal location.
Our application calls Fireworks' Chat Completions API. Customer Content is stored in the EU (Ireland). For each run we send only the extracted text and instructions required for that run. Fireworks may process the request in the United States. Under Fireworks' published zero data retention policy for open-model inference, prompts and generations are not logged to persistent storage by default; limited service metadata such as token counts may be retained. Fireworks states that it does not use prompts or API inputs to train models without explicit opt-in. See Fireworks data handling and trust.fireworks.ai.
We do not use Customer Content to train shared or public models. Outputs are AI-generated and require human review before use.
What happens when you run a document
- You upload process documents that describe how work happens today.
- 800 stores that material in the project database in the EU, scoped to your account, and reserves credits based on document size.
- During the run, extracted text is sent to Fireworks to produce an overview of tasks, agents, and humans, plus briefs.
- When the run finishes, credits are charged and you can export an overview for builders, vendors, or other agents.
Only upload documents you are allowed to share with a processor.
Subprocessors
These providers process data to deliver 800. When we add or replace a subprocessor that will process Customer Content, we aim to give at least 30 days' advance notice and a reasonable opportunity to object. Email legal@eight-hundred.app.
| Provider | Purpose | Customer Content? | Location |
|---|---|---|---|
| Application host | Application hosting and runtime | In transit / connected to the database | Application runtime |
| Supabase | Database for accounts, projects, outputs, and credits | Yes | EU (Ireland) |
| Workspace sign-in (OpenID Connect) | No (Account Data / auth claims) | Google infrastructure | |
| Resend | Transactional email (verification and reset codes) | No | Resend infrastructure |
| Stripe | Checkout and Managed Payments | No (payment data on Stripe) | Stripe infrastructure |
| Fireworks AI (trust) | AI inference (open-weight models on Fireworks infrastructure) | Yes (extracted text for the run) | United States (transient inference; zero data retention by default for this path) |
| PostHog | Product analytics | No | EU Cloud |
Credits and payments
Runs cost a fixed number of credits based on uploaded document size. You see the price before you start. Top-ups go through Stripe Checkout under Managed Payments. Credits are added only after Stripe confirms payment via a verified webhook. Credits do not expire, do not earn interest, and are not a bank deposit.
Access and operations
Production access is restricted to people who need it to operate 800, subject to technical access controls. Operational access is separate from the tenant-scoped project data shown in the product.
Retention and deletion
Projects can be deleted in the product. Account deletion and export: email legal@eight-hundred.app. Verification codes expire after 10 minutes. Deleted or closed accounts are cleared from active systems within 30 days of confirmation; backups within 90 days. Security logs are retained for 90 days. See the Privacy Notice for the full schedule.
Incidents and vulnerability disclosure
If you believe you found a security issue, email legal@eight-hundred.app. Include enough detail to reproduce the issue, and do not disclose vulnerabilities publicly until we have had a reasonable chance to fix them.
If we confirm a personal-data breach affecting Customer Content or Account Data, we will notify affected customers without undue delay.
Documents on request
- Data Processing Addendum (GDPR Article 28): email legal@eight-hundred.app
- Procurement or security questionnaire: same address