Security and data handling
Know where your project data goes.
Addienator keeps active project state in your browser and sends selected content for AI work through the connection assigned to your plan. Standard and Pro connect directly to Google Gemini with your own key. Enterprise routes AI and file requests through an organization-controlled proxy.
Your AI connection
Two routes, with a clear boundary
The route depends on your Addienator plan. Addienator does not silently switch a direct plan to an organization proxy or an Enterprise plan to a personal key.
Standard and Pro: direct Gemini
You enter your own Google Gemini API key. AI requests and provider file operations go from your browser to the Google Gemini API. The key stays in browser session storage and is not saved in an .addie project file.
Enterprise connection through your organization’s proxy
Your browser sends AI and file requests only to the proxy origin approved for your organization. Provider credentials stay on that proxy. An incomplete or unsafe Enterprise connection blocks AI work instead of falling back to a personal key.
Model routing stays explicit
Direct work uses the model selected for the job. In Enterprise, your organization maps Addienator’s fast and quality work slots to its approved provider models. The browser cannot choose an arbitrary upstream model.
From source to saved project
What happens to your files and project state
1
Check locally
PDF type, file size, page count, readability, and source identity are checked in your browser before provider file preparation begins.
2
Send only when needed
After you finish uploading or start an AI task, the current Source Document, or an original file needed for that task, is sent through the active direct or Enterprise route. Later AI work normally reuses the accepted Source Document instead of sending every original again.
3
Work in browser storage
Active project state uses session storage. Original PDFs and prepared source artifacts use IndexedDB in your browser profile. Browser storage can be cleared or lost, so it is not a substitute for a saved project file.
4
Save deliberately
An .addie file is a portable project archive that can include project content, working state, original PDFs, and the prepared Source Document. It does not include credentials and is not encrypted. Store and share it according to the sensitivity of its contents.
Application controls
Controls that reduce accidental exposure
These controls narrow access and network destinations. They do not replace your information-handling policy or the security and retention terms of your chosen provider.
Member-only application access
The application launcher requires a signed-in account with an active Addienator membership before it serves the app. Account-specific application pages use private, no-store caching so one member’s configuration is not reused for another.
One AI destination at a time
The application launcher uses a browser Content Security Policy that permits the resolved AI destination for the current route: Google Gemini in direct mode, the approved organization proxy in Enterprise, or no AI destination when Enterprise is not configured.
Fail-closed Enterprise routing
Unsafe, incomplete, ambiguous, or stale organization routing stops before any AI or file request leaves the browser. Enterprise does not silently fall back to direct Gemini.
Enterprise control boundary
Your organization controls the AI connection
Enterprise AI traffic goes from the employee browser to the organization’s proxy and then to its configured provider. Addienator serves the launcher but is not in that AI request path.
Provider credentials stay server-side
Your organization hosts and operates the proxy. Provider credentials and the file-capability secret stay in its secret store. Employee browsers receive only the organization-issued proxy access needed for the approved connection.
Requests are authenticated and bounded
The Protocol 1.1 reference proxy requires authentication, allows only configured browser origins, limits request and response sizes, rejects unsupported capabilities before provider egress, and removes provider details from client errors.
Temporary files need a lifecycle
File-capable routes replace raw provider file identifiers with protected temporary references scoped to the organization and deployment. Provider storage still follows the chosen rail. Enterprise IT must configure and verify explicit deletion and any required lifecycle or periodic cleanup. Reference expiry alone is not proof of deletion.
Before you use sensitive material
Use Addienator only with information you are authorized to process. Confirm that the selected Google or organization provider route is permitted by your policies. Do not assume that browser storage, .addie files, downloaded Word documents, provider storage, or surrounding platform logs meet a particular compliance, certification, or data-residency requirement. Enterprise IT should validate the exact deployment, provider models, access controls, logs, retention, deletion, and incident procedures before use.
What this page covers
This page describes Addienator project content and AI routing. WordPress accounts, memberships, support forms, payments, cookies, and website analytics are separate website data flows. They belong in the Privacy and Cookies notices and must be verified against the final launch configuration.
Choose the route that fits your work
Review how Addienator turns approved source materials into a project you can inspect, revise, and save. Compare the current plans to see which product and routing path applies.