Legal
Security
DearlyBook uses access controls, encrypted transport, and least-privilege admin practices to protect customer data.
Effective date: 17 July 2026
Access control
- User accounts are protected by authentication providers.
- Book and story access is enforced with database row-level security.
- Admin tools are limited to an allowlisted owner email and server-side checks.
- Service-role credentials are used only on trusted server routes.
Data protection
Traffic is served over HTTPS. Sensitive operations such as account deletion and vault unlock require authenticated requests. Analytics event storage is private to service-role access and is not exposed to anonymous clients.
Subprocessors
- Supabase: Authentication, database, and file storage
- Lovable / Cloudflare hosting: Application hosting and delivery
- Google Fonts: Font delivery for site typography
Incident response
If we become aware of a personal-data incident that requires notification, we investigate, contain the issue, assess impact, and contact affected users and regulators when required. Report suspected security issues to contact@dearlybook.com.
Admin and audit practices
- Owner-only admin analytics and book administration.
- Least-privilege principle for production credentials.
- Periodic review of admin access and subprocessors.
- Documented retention and deletion rules in our Data Retention policy.
Risk and continuity
We maintain a lightweight risk register covering authentication, data access, media storage, and analytics. Hosting backups support recovery from infrastructure failures. This page describes current operating practice and is not a formal ISO certification claim.
