Security & Privacy by Design
Botock is engineered with a strict privacy-first foundation. Discover how we protect your media files, customer data, and generative assets with client-side isolation and automated purging.
In-Browser Client Isolation
Standard PDF, image, and video utilities process locally using WebAssembly and HTML5 Canvas. Your source documents are never uploaded to any remote server.
24h Automated Purging
When you generate AI videos or images, media is retained for strictly 24 hours to give you time to download or bridge into the Video Studio. After 24h, it is irreversibly wiped.
AES-256 & TLS 1.3
All communications between client and server are encrypted using modern TLS 1.3 with Perfect Forward Secrecy. Database records are secured with AES-256 encryption.
Supabase JWT & RLS
Supabase Row-Level Security (RLS) policies enforce cryptographic isolation between user accounts. Even internal backend queries cannot read another user's generation tokens.
Zero-Training Guarantee
Botock has a strict binding policy: We never use your uploaded documents, photos, or prompts to train public AI models. Your creative prompts and proprietary documents remain exclusively your intellectual property.
- No training on confidential user PDFs, spreadsheets, or images.
- Ephemeral API sessions isolated per user request.
- Immediate unlinking upon manual deletion from "My Library".
Responsible Vulnerability Disclosure
We welcome reports from independent cybersecurity researchers. If you discover a potential security flaw or vulnerability in any of our web services, please notify our security team directly: