Descrybe published a security page stating its data handling position: customer prompts, files and conversational history are not used to train Descrybe owned models; the primary model provider is OpenAI's API, with Descrybe opted out of training and OpenAI abuse monitoring logs retained up to 30 days; uploaded files are discarded once text is extracted; research history can be deleted by the user at any time, with no zero retention mode offered; data is stored on DigitalOcean in the New York region on multi tenant infrastructure, encrypted in transit and at rest; the product runs on individual user accounts with no shared or matter based workspaces; and Descrybe holds no SOC 2 or ISO 27001 certification of its own, with SOC 2 work begun. Subprocessors are listed with links to each provider's attestation.
Buyer relevance. For a solo or small firm buyer this page answers the four questions a client's outside counsel guidelines will ask before the tool touches a matter: who processes the data, where it sits, whether it trains anything, and how it is deleted. It also says plainly what it lacks, no SOC 2 yet and no matter level walls, which is more useful than a badge, because a firm can plan around a stated limit and cannot plan around silence.