Security Measures
Encryption
Traffic is protected with HTTPS/TLS. Password credentials are stored as one-way hashes, and application sessions use signed tokens with HTTP-only cookies.
Database Security
Supabase PostgreSQL uses row-level security policies, scoped server credentials, and application-level authorization checks.
Authentication
Signed sessions use HTTP-only cookies. Repeated login failures are rate-limited and can trigger a temporary account lockout.
Monitoring
Application health checks and server-side error logging support incident detection and investigation.
Data Protection
What We Store
- •Account information (email, username, one-way password hash)
- •Profile content (name, bio, links, and media references)
- •Links and widgets configuration (JSON)
- •Analytics events and related metadata, retained according to plan and privacy settings
What We Don't Store
- •Credit card numbers (handled by RevenueCat Web Billing and Stripe)
- •Social media passwords (OAuth only)
- •Security questions or password-recovery answers
Privacy Rights
Access and correction
Request a copy of your personal data or ask us to correct inaccurate account information.
Deletion and portability
Delete your account or request a portable copy of eligible profile and account data.
Privacy requests
We handle applicable access, deletion, correction, portability, and opt-out requests as described in our Privacy Policy.
Report a Vulnerability
If you discover a security vulnerability, please report it responsibly:
- 1. Email: contact@wisedigitalinc.com
- 2. Include detailed description and reproduction steps
- 3. Do not publicly disclose until we've addressed it
- 4. We will acknowledge your report as soon as practical
We appreciate responsible disclosure and will credit security researchers (with permission).
User Security Best Practices
Strong Passwords
Use a long, unique password and store it in a trusted password manager. Do not reuse passwords from other services.
Regular Reviews
Review your profile and connected services regularly. Change your password promptly if you suspect unauthorized access.
Suspicious Links
Verify each external destination before publishing it. Link Lounge cannot guarantee the safety or availability of third-party sites.
Security Contact
Email security and privacy questions to contact@wisedigitalinc.com. Include enough detail for us to investigate without sending passwords, payment details, or other sensitive credentials.