Security & Data Handling

How ChemStitch protects your research data. We believe in transparency about what we do and don’t do with your structures.

Data Flow

Your Browserdrawing & editingTLSHosting + APIproxies & storesstructuresAI requestscomputeDatabaseencrypted at restAI Servicechat context onlyRDKit & SMILES validation

All connections use TLS encryption in transit.

What We Don’t Do

  • ×We don't sell your data
  • ×We don't share your structures with anyone
  • ×We don't use your data to train AI models
  • ×We don't require you to share your AI API key

BYO API Key Architecture

Your key, your costs, your control.

  • Keys encrypted with AES-256-GCM before storage
  • Keys are only used to make AI requests on your behalf
  • You can delete your key at any time from Settings
  • Platform default key available during beta

What Data Is Sent to AI Providers

  • Structure context (SMILES representation) when you initiate a chat message
  • Only sent when you explicitly ask the AI a question
  • AI providers process the request and return results; no training on your data

Data Storage

Storage & encryption

  • Structures and documents stored in your private account in a managed PostgreSQL database
  • Encryption at rest, TLS in transit
  • No cross-user data sharing

Authentication

Access controls

  • Magic link authentication (email-based, no passwords)
  • Session tokens with automatic refresh

Ready to try ChemStitch?

Join the free beta and start drawing molecules with AI.

Join Beta