Loading…
Loading…
The concrete measures we take to protect your account, your audience, and your data. No hand-waving — just what's actually implemented.
Database access is scoped per workspace at the database level, with least-privilege column grants. No client can read another workspace's rows.
Public API keys are stored as SHA-256 hashes and shown to you exactly once at creation. We can never display a key again — only revoke and reissue.
Every inbound webhook is verified with HMAC signatures — Meta for Instagram events, Cashfree for payment events. Invalid signatures are rejected fail-closed.
Instagram connect flows use the official Meta OAuth with a state parameter to prevent cross-site request forgery and authorization injection.
Every API endpoint is rate-limited to protect the platform and your account from abuse and runaway automations.
All credentials and tokens are stored as encrypted environment variables on Vercel — never in the codebase or the client bundle.
You can delete your account and all associated data from Settings at any time, meeting Meta's data-deletion requirements.
Admin-level database keys live exclusively on the server. The browser client never touches them — it only ever talks to row-level-secured endpoints.
Found something we should know about? Email ChirplyMint@gmail.com and we'll take it seriously.