Where your data lives, and who can reach it
Written plainly, because you are trusting us with an archive you cannot rebuild.
Where it is stored
Supabase, on PostgreSQL, encrypted at rest and in transit.
Who can see it
Every request is checked against your workspace membership before any data is returned, at a single point in the code that every data path passes through, so a missed check fails loudly rather than leaking quietly. Row level security is enabled on every table as a second layer.
Your API keys
Any key you connect, OtterlyAI or Semrush, is stored in an encrypted vault, never in a plain column. It is used server side only and is never sent to your browser. You see the last four characters and nothing else. Disconnect and it is deleted.
Sign in
Magic links only. We do not store passwords because we do not have any.
Staff access
Our staff can see workspaces to provide support. That access is an explicit, revocable record rather than a hardcoded exception.
Deleting your data
Delete a property and its data goes with it. Delete a workspace and everything in it goes. Both are irreversible and both tell you so before you confirm, including the row count, because for anything older than 16 months there is no copy anywhere in the world.
What we do not do
We do not sell your data. We do not use it to train anything. We do not aggregate it into an industry benchmark product. It is your archive.
