Security & Data Handling
Whether our staff see your data, where it's stored, AI training and what the AI reads, visibility and admins, two-factor authentication, and when you stop.
Last updated: 2026-09-29
Here are the questions that often come up when deciding to bring in Addness, answered along the lines of Addness's screens and how the AI works. Details on infrastructure, encryption, subcontractors, and authentication are on the Security page and in the Privacy Policy. System architecture diagrams and answers to security checklists are provided under a non-disclosure agreement. Request them through the free onboarding support form.
Can Addness employees see our data?
As a rule, no. Only when it's needed for support or incident response do authorized staff access it, and those operations are logged.
Organization admins inside your own company are a different matter. What admins can see is covered in Can we separate who sees what within the company?.
Where is data stored?
Databases, files, and backups are stored in Japan (the AWS Tokyo Region). AI processing, sign-in, error monitoring, hosting, payments, and similar are handled by external services in the United States. The list of subcontractors is in section "4" of the Privacy Policy.
Data is kept separate for each company (organization), and other organizations can't see it.
Is our data used to train AI?
AI is used in two situations, and they need to be considered separately.
| Situation | Used for training? |
|---|---|
| AI features inside Addness (meeting minutes, summaries, etc.) | No. We only use AI services whose contract terms say the data sent to them isn't used for training |
| AI that runs from "Ask AI" (Claude Code, Codex) | It depends on the contract and settings you use with that AI app. For company use, check that you have a business contract with the AI provider and that it's set not to use your data for training |
How far does the AI read?
The AI can read only what the person using it can see in Addness. It can't read goals that person has no permission to view, or other companies' data. When the AI creates or edits goals, it's also limited to that person's permissions.
The AI that runs is the Claude Code or Codex you installed on your own computer. Addness never operates your computer. "Ask AI" only passes an instruction like "move this goal forward" to that AI app. What the AI app may do on your computer is set in Claude Code's or Codex's own settings.
The AI is instructed to check with you before deleting or publishing a goal. Goals deleted by mistake can be restored (→ FAQ).
Can we separate who sees what within the company?
For goals, yes. Who can see a goal depends on whether they're assigned to that goal or a goal above it. A goal someone isn't assigned to anywhere isn't visible to them, even if they're a member of the same company (→ Who can see how much). People who join as guests can only view, comment, and chat.
Outside goals, who can see something when it's created depends on the feature.
| Feature | Who can see it when created |
|---|---|
| Knowledge, Analytics | Everyone in the organization (including guests) |
| Customer lists, files placed directly in Drive | Only the person who created it |
Change the visibility of anything you don't want others to see. If you link metrics (Analytics) to a goal, anyone who can see that goal can see the values.
Organization admins can see almost everything, regardless of assignment. They can access comments and activity on goals they aren't assigned to, the list of goals each member owns, Drive, Knowledge, customer lists, metrics, and recordings, and they can export conversations they aren't part of as CSV. Make only the people who need it admins.
The AI reads whatever the person can see, but there's no system mechanism that stops it from writing what it read into another goal. People who handle confidential information should tell the AI "don't write the contents of this goal into other goals" when using it.
Sign-in and two-factor authentication
You sign in with a one-time code sent to your email, or with a Google or Apple account. Addness doesn't hold passwords.
Each person can set up two-factor authentication with an authenticator app in My Settings › Security. There's no setting yet to require two-factor authentication for everyone in the organization.
Single sign-on (SSO) with SAML, user provisioning with SCIM, and IP address restrictions aren't supported yet.
When you stop using Addness or delete data
- When you cancel: Your data isn't deleted. You can't open it while you have no contract, and if you subscribe again, you pick up where you left off (→ Plans & Billing: "How to cancel")
- When you want to take your data out: There's no button that exports everything at once. Ask your connected AI to "export this goal and everything under it, including the body and comments, to a file," and it exports what you can see. Drive files can be downloaded, and admins can export each conversation as CSV. You can't open anything once the contract ends, so export before you stop
- When you delete the organization: The organization's data is deleted on the spot and can't be restored. Backups are also deleted within 7 days (→ Deleting an organization)
Do you have third-party certifications?
We haven't obtained ISMS (ISO/IEC 27001), SOC 2, or the Japanese PrivacyMark yet. We answer security checklists individually.
This article is written based on the content as of September 29, 2026.
Articles in this section— Settings & Billing
Was this article helpful?