Security
Last updated: September 1, 2026
This page gives an honest overview of how we protect your data. It is informational and not a warranty. See the Privacy Policy for data handling and the Subprocessors page for the providers we use.
Encryption
- Data is encrypted in transit (HTTPS/TLS).
- Sensitive third-party access tokens (such as TikTok publishing tokens) are encrypted at the application level before being stored.
- Our database and storage providers encrypt data at rest at the infrastructure level.
Access and authentication
- Sign-in is delegated to Google OAuth; we do not store passwords.
- Access to production systems and secrets is limited and managed through a dedicated secrets manager.
Infrastructure
- We build on established providers (see Subprocessors) for database, storage, background jobs, analytics and monitoring.
- We use error monitoring to detect and fix problems, with measures to limit personal data in logs.
Note on public media
By design, media you upload and generate is served from public URLs (see the Terms and Privacy Policy). Treat those files as publicly accessible and avoid uploading confidential material.
Reporting a vulnerability
If you discover a security issue, please report it responsibly through . Do not access or modify other users’ data, and give us reasonable time to fix the issue before disclosing it publicly.
Breach notification
If a security breach affects your personal data, we will notify you and the competent authorities as required by applicable law.