top of page

Safeguarding Your Data

Effective Date: April 22, 2025
Last Updated: August 14, 2026

 

At Narralyze LLC, we recognize that information uploaded to Narralizer AI may include confidential research materials, interviews, transcripts, recordings, participant information, unpublished research, proprietary information, and other sensitive data.

Protecting the confidentiality, integrity, and availability of this information is an important part of how we design, develop, and operate Narralizer AI.

This statement explains our approach to safeguarding Customer Content throughout its lifecycle. Additional information about how Narralyze LLC collects, uses, and processes personal information is available in our Privacy Policy.

Our Commitment

Narralyze LLC is committed to implementing appropriate technical and organizational safeguards designed to protect Customer Content against unauthorized access, disclosure, alteration, loss, or misuse.

Our approach to data protection is based on several fundamental principles:

  • Customer Content remains under the control of the customer.

  • Access to Customer Content should be limited to authorized users and services.

  • Information belonging to different customers should remain appropriately separated.

  • Customer Content should be protected during transmission and storage.

  • Original research materials should be protected against unintended modification.

  • Security controls should be tested and reviewed as the Service evolves.

  • Customer Content should not be retained longer than required for the purposes described in our applicable policies and agreements.

Your Data Remains Yours

Uploading information to Narralizer AI does not transfer ownership of your research or source materials to Narralyze LLC.

Customer Content remains associated with your account or organization and is processed to provide the functionality and analyses you request, subject to our Terms of Service, Privacy Policy, and any applicable agreement with your organization.

Users are responsible for ensuring that they have the rights, permissions, notices, consents, or other lawful authority required to upload and process information through Narralizer AI.

Data Separation and Access Control

Narralizer AI is designed as a multi-user cloud service in which each user's or organization's information is logically separated from information belonging to other customers.

Access controls are designed to prevent users from accessing Customer Content for which they have not been granted appropriate permissions.

We treat customer data isolation as a fundamental security requirement and include authorization and data-isolation controls within our security design and testing practices.

Encryption and Secure Transmission

Narralizer AI is designed to protect Customer Content while it is transmitted and while it is stored.

Data transmitted between your browser and Narralizer AI is protected using encrypted network connections. Stored Customer Content and application data are protected using encryption appropriate to the systems in which they reside.

Encryption keys, credentials, and other sensitive system secrets are managed separately from Customer Content, with access restricted to authorized systems and personnel.

Access by Narralyze LLC Personnel

Narralyze LLC personnel do not require routine access to customer research content for normal use of Narralizer AI.

Where access by authorized personnel is necessary—for example, to provide support requested by a customer, investigate a technical or security issue, maintain the Service, or comply with a legal obligation—access is restricted according to applicable permissions and operational controls.

Administrative access to production systems is restricted and, where appropriate, logged and monitored.

Artificial Intelligence and Your Data

Artificial intelligence is an important component of Narralizer AI. Accordingly, the way Customer Content interacts with AI systems is an important part of our security and privacy approach.

Narralizer AI is designed to transmit only the information reasonably necessary to perform a requested AI-assisted operation.

Where an external AI service is used, that transfer is treated as a separate data-processing relationship and is subject to applicable technical and contractual safeguards.

AI Model Training

Narralyze LLC's policy is that Customer Content submitted to Narralizer AI is not to be used to train general-purpose artificial intelligence models.

Where third-party AI providers process Customer Content on our behalf, Narralyze LLC seeks contractual terms and service configurations that prohibit Customer Content from being used to train the provider's general-purpose models.

Additional information about applicable providers and their processing of Customer Content is available through our Privacy Policy and Subprocessor List.

AI Data Isolation

AI-assisted functionality must not create a pathway around Narralizer AI's normal access controls.

Information belonging to one user or organization should not be retrieved, included in an AI context, or returned in an AI-generated response to an unauthorized user.

We treat AI data isolation as an application security requirement rather than relying solely on the behavior of an underlying AI model.

Protecting Data Integrity

Security involves more than preventing unauthorized disclosure. Research information should also remain accurate, traceable, and protected against unintended modification.

Narralizer AI is designed to distinguish original source materials from information subsequently derived from them.

Where appropriate, technical mechanisms may be used to verify that stored source information has not changed unexpectedly and to preserve relationships between original materials and subsequent transformations or analyses.

These controls are intended to support traceability and help detect accidental corruption, substitution, or unintended modification.

Uploaded File Security

Files uploaded to an internet service can themselves present security risks.

Narralizer AI therefore treats uploaded files as untrusted input and applies controls intended to prevent malicious or malformed files from compromising the Service or other customer information.

Depending on the file type and processing workflow, these controls may include:

  • File-type and file-size validation.

  • Content inspection.

  • Malware detection.

  • Safe file-processing procedures.

  • Restrictions on potentially dangerous file structures.

Customer Content is not made publicly accessible merely because it has been uploaded to Narralizer AI.

Temporary Processing Data

Analyzing research materials may require temporary processing, such as extracting text, processing documents, generating reports, indexing information, or preparing information for AI-assisted analysis.

Narralizer AI is designed to control temporary copies and processing artifacts and to retain them only for as long as required for their intended purpose or applicable operational, security, or legal requirements.

Temporary processing should not create an uncontrolled secondary repository of customer research data.

Backups and Recovery

Narralizer AI uses backup and recovery mechanisms designed to protect against accidental data loss and service failures.

Backups containing Customer Content are subject to access restrictions and appropriate security controls.

Backup procedures should be tested periodically to confirm not only that backups exist, but also that information can be restored accurately when required.

Users should nevertheless maintain independent copies of irreplaceable original research materials unless Narralyze LLC expressly agrees to provide archival storage.

Deleting Your Data

Deleting information from Narralizer AI is intended to remove that information from active use in accordance with our data-retention practices.

Because cloud systems may contain backups, caches, indexes, logs, and temporary processing copies, deletion may not result in the instantaneous physical destruction of every residual copy.

Residual information may remain for a limited period where technically necessary for backup, security, disaster recovery, audit, legal, or system-integrity purposes. Such information remains subject to applicable security controls and is removed or expires according to the applicable retention schedule.

Additional information about data retention and deletion is available in our Privacy Policy.

Security Testing and Continuous Improvement

Security is an ongoing process rather than a one-time configuration.

As Narralizer AI evolves, Narralyze LLC reviews its security controls, software dependencies, infrastructure configurations, access controls, and data-processing practices.

Our security testing practices may include:

  • Authentication and authorization testing.

  • Customer data-isolation testing.

  • Vulnerability and dependency scanning.

  • Infrastructure configuration testing.

  • Uploaded-file security testing.

  • API security testing.

  • Data-integrity verification.

  • Backup and recovery testing.

  • AI data-isolation testing.

  • Monitoring for unintended disclosure of sensitive information.

Automated testing may be supplemented by manual security review and independent security assessments where appropriate.

Testing Customer Data Isolation

Whenever practical, security testing uses artificial test accounts and synthetic information rather than actual Customer Content.

Separate test users or organizations can be assigned uniquely identifiable synthetic datasets. Automated tests can then attempt to access one test customer's information while authenticated as another test customer.

Unauthorized access must fail.

Similar techniques may be used to test application interfaces, APIs, search, exports, AI-assisted functionality, temporary processing, logging, and deletion.

This approach allows important security properties to be repeatedly verified as Narralizer AI changes.

Testing Data Integrity

Automated tests may be used to verify that information stored by Narralizer AI remains consistent with the information originally received.

Where appropriate, cryptographic integrity checks can help identify unexpected modification of source materials during storage, retrieval, backup, or restoration.

Testing may also simulate interrupted uploads, corrupted information, duplicated requests, concurrent processing, and other abnormal conditions to confirm that the system responds safely and preserves data integrity.

Testing AI Isolation

AI-assisted research introduces security considerations that conventional application testing alone may not identify.

Narralizer AI's security testing strategy therefore includes testing designed to determine whether information associated with one synthetic customer could accidentally appear in search, retrieval, AI context, or AI-generated results provided to another synthetic customer.

Unique synthetic markers can make these failures automatically detectable and help verify that AI-assisted functionality respects the same customer boundaries as the rest of the application.

Third-Party Services and Subprocessors

Like most cloud applications, Narralizer AI may rely on specialized service providers for functions such as cloud infrastructure, authentication, communications, monitoring, payment processing, data processing, and artificial intelligence.

Narralyze LLC evaluates the role these providers play in processing customer information and seeks to limit information transferred to what is reasonably necessary to provide the applicable service.

Information about material subprocessors that process Customer Content, including their purposes and, where applicable, processing locations, is provided through our Subprocessor List or related privacy documentation.

Data Location

Narralyze LLC maintains documentation identifying the cloud infrastructure and geographic regions used to store and process Narralizer AI Customer Content.

Where data-residency options are available, applicable options and limitations are communicated to customers.

Information processed by third-party services may also be subject to the processing locations identified in our Subprocessor ListData Processing Addendum, or related documentation.

Your Responsibilities

Narralizer AI provides security controls, but account and research-data security also depend on how the Service is used.

Users should:

  • Use strong, unique passwords.

  • Enable multi-factor authentication when available.

  • Protect authentication credentials and never share passwords.

  • Grant collaborators only the access they require.

  • Remove access when a collaborator no longer requires it.

  • Maintain independent copies of irreplaceable original research materials.

  • Ensure they have appropriate authority to upload and process participant or third-party information.

  • Consider de-identifying or minimizing sensitive information when appropriate for the research purpose.

  • Notify Narralyze LLC promptly if unauthorized access or another security issue is suspected.

Security and Privacy Questions

We welcome questions and feedback about how Narralizer AI safeguards Customer Content.

If you have a question about our security practices, believe you have identified a security vulnerability, or suspect unauthorized access to your account or data, please contact us.

Narralyze LLC

When reporting a potential security issue, please provide sufficient information for us to understand and investigate the issue, but do not include passwords, authentication credentials, or unnecessary sensitive Customer Content.

We will make reasonable efforts to review security and privacy reports and respond in a timely manner.

Related Documentation

Additional information about our privacy, security, and data-processing practices is available in:

  • Privacy Policy

  • Terms of Service

  • Data Processing Addendum (where applicable)

  • Subprocessor List

  • Cookie Policy

Protecting research data is not a one-time configuration. It is a continuing process of designing, testing, monitoring, and improving the systems entrusted with that information.

bottom of page