How we protect your launch data
You're trusting us with your launch numbers, sometimes before you've told anyone else about them. Below is exactly how we handle it.
Every table in our database has row-level security enabled. Your projects, funnel snapshots, evidence, and checklist rows are only ever readable and writable by you — enforced by the database itself, not by application code that could have a bug.
Admin and user roles live in their own table, checked through a dedicated security-definer function, instead of a role column on your profile that a compromised session could edit. You can't grant yourself admin by editing a row you own.
API keys, service-role database credentials, and anything else sensitive stay server-side. The browser only ever talks to our public, rate-limited API surface — never a secret key.
Endpoints that don't require login — like the contact form and public report pages — are rate-limited per IP address to stop abuse and spam without needing a CAPTCHA on every form.
Our database is backed up automatically on a rolling schedule by our infrastructure provider, so a bad deploy or a fat-fingered migration isn't a total-loss event.
We use Lovable Cloud for hosting, our Postgres database, and authentication. That's the full list — we don't pipe your data through a chain of third-party analytics or marketing tools.
What Velora does not do
- Sell or rent your data to anyone, ever.
- Record your sessions, keystrokes, or screen while you use the app.
- Share your project data with other Velora users, even in aggregate, without your public-report toggle being on.
- Store payment card details on our servers — billing is handled by a PCI-compliant processor.
Found a vulnerability?
Email security@velora.app with details and reproduction steps. We aim to acknowledge reports within one business day and don't take legal action against good-faith security research.