Skip to content

Security

How we protect accounts and payment access

Authentication is managed through Supabase Auth with secure session handling. We do not store plaintext passwords.

Payment processing is handled by Stripe Checkout and Stripe webhooks. Card details are processed by Stripe, not stored in this application.

Access to paid content is enforced server-side with entitlement checks. Protected content is not unlocked by UI state alone.

We monitor for checkout and entitlement integrity issues and reserve the right to suspend abusive or fraudulent account behavior.