Your data stays with you.

We do not need a copy of your work on our servers, for any product. For full details on data handling, see our Privacy Policy and Terms of Use.

Overview

Chartbuddy runs in three products, and each handles data differently. The table covers authentication, storage, and what reaches our servers.

Authentication Storage What reaches our servers Google access
Chartbuddy Embed JavaScript package None In the page or artifact that holds them Nothing, if you self-host the package None
Chartbuddy Hub Desktop app for Mac and Windows Sign-in with Google, SSO or password. On your own device Sign-in, plan check, update check, crash reports Identity only. No Drive access.
Chartbuddy for Google Slides™ Chrome extension Sign-in with Google or SSO In your Google Slides file Account metadata. Chart images: a ~2 second transfer through our managed EU storage, or only through your own GCS with bring-your-own infrastructure — see Privacy Policy. Google OAuth scope drive.file (non-sensitive). Only files you open or pick.

Chartbuddy does not store your chart content, your spreadsheet data or your slide text.

SOC 2 Type II audited

Chartbuddy holds a SOC 2 Type II report. Our security controls have been independently audited and verified over time.

Enterprise customers may request our report, security overview or completed security questionnaire under NDA.

SOC 2 Type II

You control what we access

We never request broad access to your Google Drive. In Google Slides, Chartbuddy uses Google's drive.file scope, so it only sees the presentations you open or pick. Nothing else in your Drive is visible to us.

You can revoke that access at any time in your Google account settings.

GDPR Compliant

Secure by design

  • Minimal data handling - Chart configuration and spreadsheet data are processed on your own device. In Google Slides with default managed storage, rendered chart images are temporarily transferred to our EU Google Cloud Storage for approximately two seconds during insertion, then deleted. With bring-your-own infrastructure, chart images stay entirely within your Google Cloud environment.
  • Encrypted in transit - All traffic to our servers and Google is encrypted using HTTPS/TLS.
  • OAuth 2.0 authentication - We use Google's OAuth 2.0 protocol. Your Google password is never shared with or stored by Chartbuddy. The desktop app signs in through your system browser using a loopback redirect with PKCE, so no credentials pass through the app itself.
  • Token management - Refresh tokens are stored encrypted at rest. Short-lived access tokens are used for all API interactions.
OAuth 2.0

AI access

Chartbuddy is built to be driven by AI assistants. Here's how it works.

  • The MCP server runs locally - Your AI client starts the Chartbuddy desktop app as a local process and talks to it over standard input and output. There is no remote endpoint to reach and the app opens no inbound network listener.
  • We never see your prompt - Your prompt goes to whichever AI provider you already use, under your own agreement with them. It does not pass through Chartbuddy.
  • We do not train on your data - We do not use your charts, your data or your personal data to train machine learning models, and we do not permit our providers to do so.

Controls for your admins

  • Enterprise single sign-on - SAML and OIDC through your existing identity provider.
  • Organization-managed settings - House style, templates and storage configuration are set at organization level, so every chart your team ships is on-brand by default.
  • Token revocation - Every API token can be revoked, immediately ending that client's access.
  • Audit and consent records - We keep records of policy acceptance and of security-relevant events, and can share them on request.
  • Deletion on your terms - Personal data is removed from active systems within 24 hours of an account deletion request. Organization removal runs on a 30 day window so an accidental request can be reversed.

Create professional charts that stay alive across every surface.

Get started