Security & AI transparency

Your business data deserves careful handling.

Here is what HappyNoodle protects today, how its AI features work, and the limits we will never hide behind vague promises.

Data access

Private by structure, not just by promise.

Access checks live beside the data and on protected server actions, so changing what appears in a browser does not grant extra access.

One business cannot see another

Business records are separated by row-level access rules. Each signed-in request is checked against active membership and the selected business before records can be read or changed.

Permissions are checked on the server

Owners, team members, client accounts and platform staff have distinct access. Sensitive decisions are not trusted to a hidden button or a browser setting.

Clients see only shared work

Client accounts are connected to named projects. Internal project costs remain private, while proposals use short-lived access and one-time verification codes.

Public forms are constrained

Public quote forms use human-verification checks, input validation and request throttling. Public requests cannot directly browse private workspace tables.

Cryptography in use

Plain answers about protected secrets.

Encryption, hashing and signatures solve different problems. HappyNoodle uses each for a defined purpose.

Connected-service credentials
Encrypted on the server with AES-GCM before storage. The encryption key is not sent to the browser.
API keys and invitation links
Stored as one-way SHA-256 hashes, so the original value is not kept for later display.
Outgoing webhooks
Signed with HMAC-SHA256 so a receiving service can check that a message came from HappyNoodle.
Proposal access
Uses an HMAC-signed grant plus a one-time hashed code that expires after ten minutes and records attempts.
Uploaded images
Shared with the screening service through a signed link that expires after ten minutes.

How AI is used

Helpful assistance, with a human still in control.

AI requests travel through our hosting partners' AI gateway. HappyNoodle currently uses the gateway label OpenAI GPT-6 Astra for Noodle and core writing tasks, and Google Gemini 3 Flash Preview for lower-cost client update drafts and directory image screening.

Relevant workspace context

Noodle can retrieve relevant contacts, invoices, conversations, tasks, deals, quotes, appointments and proposals from the signed-in business. Existing access rules still apply.

Approval before action

Noodle can prepare an email, task, note, deal move, invoice message or proposal draft, but it creates a pending action first. Nothing changes until the owner approves it.

Injection resistance, honestly stated

Noodle is instructed to treat client messages and imported text as data, never new commands. Tool inputs are validated and business-scoped, but prompt instructions alone cannot guarantee complete protection from every manipulation attempt.

What leaves the workspace for AI processing

A prompt and the relevant workspace text—or a temporary image link for image screening—are sent through our hosting partners' AI gateway to produce the requested result. HappyNoodle's Privacy Policy contractually states that Customer Data is not used to train general-purpose models, subject to limited security, abuse-prevention and legal-compliance processing. That provider-side commitment is contractual rather than something this website's code can independently prove.

Safety around harm

Noodle is instructed to refuse illegal, abusive, fraudulent and dangerous requests and not to propose related actions. For urgent UK situations it can point people towards 999, 101, NHS 111, Samaritans on 116 123, SHOUT on 85258 and the National Domestic Abuse Helpline on 0808 2000 247.

What that does not mean

This safety response relies on the AI following its instructions; it is not an emergency service or an independent output filter. In immediate danger, contact the appropriate emergency service directly.

A check before images go public.

Directory uploaders must confirm they have the sole and exclusive right to use each image and are not using another person's likeness without rights.

New logos and gallery images are screened for nudity, sexual content, graphic violence, hate or extremist imagery, weapons or drugs promotion, harassment and other offensive content.

Recognisable public figures can also be flagged for review. If the automatic check fails, the image is marked for a manual look rather than treated as clear.

Flagged and uncertain images enter a staff-only queue where they can be approved or removed, and that decision is recorded.

Automated image screening can make mistakes. Rights confirmation and staff review remain essential.

Day-to-day controls

Designed to reduce avoidable exposure.

  • Sensitive server operations check user entries for the expected format and length before using them.
  • Repeated signed-in and public requests are throttled; public limits use a shortened hash rather than storing the raw visitor IP.
  • Email and text messages enter one controlled queue with recipient checks, sending limits, retry history and an audit trail.
  • Membership, integration, API-key, bulk-delete, export and selected staff actions leave audit records.
  • Security headers restrict framing, form destinations, embedded objects, referrer detail and browser access to camera, microphone and location.
  • Account owners can export their data, schedule closure with a typed DELETE confirmation, and reactivate before the deletion deadline.

Our honest limits

No online service can promise absolute security, uninterrupted availability or perfect detection. Security controls reduce risk; they do not remove it.

AI output may be incomplete, inaccurate, unsuitable or unoriginal. It is not legal, tax, accounting, financial, medical or other regulated professional advice. Review it before acting, publishing or sending.

Users remain responsible for strong credentials, appropriate team access, the rights to uploaded material and checking work produced with AI.

The model names above are the routing labels configured in HappyNoodle. The AI gateway may manage the underlying model infrastructure.

Run the whole business from one place.

Set up your workspace in minutes. Your pipeline, project plan and calendar come ready to use.