Legal and trust
Security
Last updated: September 30, 2026
Encryption
Sensitive content fields use application encryption in production, and production startup requires a configured content encryption key for durable persistence.
Access control
APIs authenticate on the server and scope user-owned queries by authenticated identity. Admin access to intimate content is excluded from normal support workflows.
Auditability
Export, deletion, billing webhook, and account lifecycle actions produce redacted operational audit records without logging intimate content.