Security

The security measures UITruth has in place today, stated plainly and factually.

Where your data is stored

Account details, the data you enter and your measurement results are stored in Supabase's Japan (Tokyo) region. Application processing (our server functions) runs in Vercel's US region, so data is stored in Japan but processed outside it. The privacy policy describes this cross-border transfer in full.

Encryption in transit

Traffic to the service is encrypted with TLS. HTTPS is enforced with HSTS (max-age of two years, includeSubDomains, preload) emitted by the application itself on every response, and the domain is on the browser HSTS preload list.

Payment data

Credit card numbers and other payment details are collected and held only by our payment processor, Stripe. We never hold card numbers ourselves.

Security headers

Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy are set on every page, and CSP violations are reported back to us so we notice when something breaks the policy.

How measurement inputs are treated

We never use the questions or brand names you enter for measurement to train our own AI.

Processors we disclose

The service relies on DataForSEO for measurement, Stripe for payments, Supabase for database and authentication, Vercel for hosting, Resend for email, Google and GitHub for optional sign-in, Inngest for queueing measurement jobs, and Plausible (Plausible Insights OÜ, Estonia) for analytics. Details of each processor's handling are in our privacy policy.

Sign-in protection

Passwords must be at least 12 characters and mix upper case, lower case and digits, and known-breached passwords are rejected. Two-factor authentication (TOTP) can be turned on from settings; once on, a 6-digit code is required at every sign-in.

Exporting and deleting your data

You can download everything we store for your organization as JSON from settings, and you can delete your account there too. Deleting removes all of your organization's data, and any active subscription is cancelled first. No email request, no waiting.

Operational data retention

Product analytics events are kept 400 days, rate-limit records 7 days, free-audit usage records 90 days, processed payment events 90 days, and shared-connection free-audit grace records 180 days. A weekly job deletes anything older. The retention periods live in one place in the code, and the job reads the same values shown here.

Failure detection

Public pages and key APIs are monitored from outside, and server-side errors (HTTP 5xx) notify the operator automatically. Stripe subscriptions are reconciled against account plans weekly, and any mismatch raises an alert.

Reporting a vulnerability

We publish /.well-known/security.txt (RFC 9116). Write to security@uitruth.app or use the contact page. You'll get a first response within five business days. As a one-person business we do not offer 24/7 staffed response.

How long we keep the answers we collect

The raw data of each answer we collect (the original JSON returned by the API) is deleted 90 days after it was collected. For registered accounts, the measured results and the answer text are kept without a time limit for as long as the account exists, and all of it is deleted when the account is deleted. Results of checks run without an account are deleted after 12 months. Your history and trends stay intact.

Measurement processors

What leaves our systems for a measurement is the question text and the brand name you entered. Answers are fetched through our measurement providers (DataForSEO / Bright Data) and results are stored in Supabase (Tokyo region). Raw answer data (JSON) is deleted after 90 days (the answer text and aggregated data remain). The full list of subprocessors and the legal terms are in our privacy policy.

Read the privacy policy

Reporting a vulnerability

If you discover a vulnerability in the service, please let us know via the contact page. We review every report and respond in turn.

Go to the contact page

Security — UITruth