Security
Effective June 11, 2026 · Last updated June 11, 2026
What this means
We protect accounts with strong password hashing and optional two-factor authentication, and the platform with strict transport security. We tell you plainly what we do and do not have.
Our approach
This page lists the security measures that actually exist in the platform today — nothing aspirational, nothing borrowed from a template. We would rather tell you plainly what we have and what we do not.
Protecting your account
- Passwords are stored using strong one-way hashing — we never store or see your password in plain text.
- Optional two-factor authentication (authenticator-app codes) with backup codes. We recommend turning it on in your profile settings.
- Sign-in sessions use short-lived tokens: access tokens expire after 1 hour and refresh tokens after 7 days, and refresh tokens rotate on every use.
- API keys are shown once and stored only as secure hashes, so a database leak would not reveal them. You can revoke a key at any time.
Your part: use a strong, unique password, turn on two-factor authentication, and keep API keys out of shared or public places.
Protecting the platform
- All traffic is encrypted in transit. We enforce HTTPS with strict transport security (HSTS) for one year, including subdomains, with preload.
- Browsers are told never to show the app inside other sites (clickjacking protection) and cookies are marked secure.
- Rate limits on every part of the API contain abuse and keep the service stable for everyone.
Payments
Payments are handled by Stripe, a PCI-DSS-certified payment processor. Your card number goes directly to Stripe and never touches our servers — we only see the result of the payment and limited details like the card's country and last four digits.
Audit logging
Compliance-relevant actions — like handling a data subject request or changing a suppression entry — are written to an append-only audit log that cannot be edited after the fact.
Suppression enforcement
When someone opts out or asks for deletion, their identifiers go on a suppression list that is checked on every export. Suppressed emails, domains, phones, names, and profile URLs cannot be exported by any customer, on any plan, through the app or the API.
Reporting a vulnerability
If you find a security problem, please tell us through the support page with enough detail to reproduce it. Please do not access other people's data, disrupt the service, or test our systems without written permission — see the Acceptable Use Policy.
We do not currently run a paid bug-bounty program, but we take reports seriously, act on them, and will credit you for a valid find if you want.
What we don't claim
We do not currently hold SOC 2, ISO 27001, or similar third-party certifications, and we will not pretend otherwise with badges or vague wording. If we earn a certification later, we will say so here. If a security incident affects your data, we will tell you what happened and what we are doing about it as quickly as we reasonably can.
Related policies
Questions or requests
If anything on this page is unclear, or you want to act on your rights, you can reach us through the support page. To ask about data we hold on you or your business, use the data request portal — no account is needed.
Data protection contact
For data-protection matters — access, correction, deletion, objection, portability, or “do not sell” requests under GDPR/CCPA — the fastest route is the data request portal, which is logged and tracked to completion. Identity is verified before any personal data is disclosed.