Your security is our priority.

Chartbuddy is SOC 2 Type II audited and GDPR aligned. We encrypt traffic, use OAuth 2.0, and collect only what each product needs to run. For full details, see our Privacy Policy and Terms of Use.

Overview

Each Chartbuddy product handles data differently. This table is the comparison: authentication, storage, what reaches our servers, and Google access.

Authentication Storage What reaches our servers Google access
Chartbuddy Embed JavaScript package None In the page or artifact that holds them Nothing, if you self-host the package None
Chartbuddy Hub Desktop app for Mac and Windows Sign-in with Google, SSO or password. On your own device Sign-in, plan check, update check, crash reports. Not chart content. Local AI over standard input/output. Identity only. No Drive access.
Chartbuddy for Google Slides™ Chrome extension Sign-in with Google or SSO In your Google Slides file Account metadata. Chart images: a ~2 second transfer through our managed EU storage, or only through your own GCS with bring-your-own infrastructure — see Privacy Policy. Google OAuth scope drive.file (non-sensitive). Only files you open or pick.
Chartbuddy for PowerPoint Microsoft Office add-in Sign-in with Google, SSO or password. In your PowerPoint file Account metadata. Not chart content. None
Remote MCP connector Optional hosted connector Chartbuddy OAuth or MCP key. Temporary chart configuration in Google Cloud, Netherlands Chart configuration you send through the connector, and short-lived exports. See Privacy Policy. None

SOC 2 Type II audited

Chartbuddy holds a SOC 2 Type II report. Our security controls have been independently audited and verified over time.

Enterprise customers may request our report, security overview or completed security questionnaire under NDA.

SOC 2 Type II

You control what we access

We never request broad access to your Google Drive. Only Chartbuddy for Google Slides uses Drive, and only for presentations you open or pick, through Google's drive.file scope. Nothing else in your Drive is visible to us. The other products do not use Drive scopes.

You can revoke that access at any time in your Google account settings.

GDPR Compliant

Secure by design

  • Only what we need - Each product only receives what it needs to run. What that is, for each product, is in the overview.
  • Local handoff to your deck - When Hub sends a chart to PowerPoint or Google Slides, it passes between them on your own machine, not through our servers.
  • Encrypted in transit - All traffic to our servers and Google is encrypted using HTTPS/TLS.
  • OAuth 2.0 authentication - Where you sign in with Google, we use Google's OAuth 2.0 protocol. Your Google password is never shared with or stored by Chartbuddy. The desktop app signs in through your system browser using a loopback redirect with PKCE, so no credentials pass through the app itself.
  • Token management - Refresh tokens are stored encrypted at rest. Short-lived access tokens are used for all API interactions.
OAuth 2.0

AI access

You can use AI assistants with Chartbuddy. Where chart data goes depends on the product — that is in the overview.

  • Your prompt goes to your AI provider - Chartbuddy does not receive the prompt. Where an assistant calls our hosted connector, we receive only the chart-tool arguments needed to perform the request.
  • We do not train on your data - We do not use your charts, your data or your personal data to train machine learning models, and we do not permit our providers to do so.

Controls for your admins

  • Enterprise single sign-on - SAML and OIDC through your existing identity provider.
  • Organization-managed settings - House style, templates and storage configuration are set at organization level, so every chart your team ships is on-brand by default.
  • Token revocation - Every API token can be revoked, immediately ending that client's access.
  • Remote MCP access - Organization administrators can disable the hosted connector for the organization.
  • Audit and consent records - We keep records of policy acceptance and of security-relevant events, and can share them on request.
  • Deletion on your terms - Personal data is removed from active systems within 24 hours of an account deletion request. Organization removal runs on a 30 day window so an accidental request can be reversed.

Frequently asked questions

Can't find what you're looking for? Visit our Help Center or contact us.

On Chartbuddy Hub, Google Slides, PowerPoint and Embed: no. Chart data is processed on your device or in your file. We store account information, not that chart content. The optional Remote MCP connector is different: it stores chart configuration temporarily in Google Cloud in the Netherlands. See the Privacy Policy.
Yes. Our security controls have been independently audited and verified over time.
Only the presentations you open or pick in Chartbuddy for Google Slides. Chartbuddy uses Google's drive.file OAuth scope, so nothing else in your Drive is visible to us. You can revoke access in your Google account settings. Chartbuddy Hub and the Remote MCP connector do not use Google Drive scopes.
Your prompt goes to whichever AI provider you already use, under your own agreement with them. Chartbuddy Hub does not receive it. The Remote MCP connector receives only the chart-tool arguments needed to perform the request, not your Google, Microsoft, SSO or password credential.
No. We do not use your charts, your data or your personal data to train machine learning models, and we do not permit our providers to do so.
Yes. Enterprise customers may request our report, security overview or completed security questionnaire under NDA.

Build consulting-grade charts. Free to start, no card.

Start for free