Privacy

Last updated: 2026-05-12

What we collect

How we use it

What we don't do

Retention & deletion

Payment data

Billing is processed by Stripe. We never see or store card numbers, expiry dates, or CVCs. Stripe stores them; we store only a Stripe customer ID and subscription ID so we can show you billing status and let you manage your subscription. Stripe's privacy policy: stripe.com/privacy.

Security

Sessions are server-side and never exposed in URLs. Cookies are HttpOnly + Secure + SameSite=Lax. All endpoints are HTTPS-only with HSTS. Mutating endpoints require same-origin requests. Rate limits protect signup, sign-in emails, and inbound SMS. The SMS webhook is authenticated with a shared secret.