How we protect your launch data

You're trusting us with your launch numbers, sometimes before you've told anyone else about them. Below is exactly how we handle it.

Row-level security on every table

Every table in our database has row-level security enabled. Your projects, funnel snapshots, evidence, and checklist rows are only ever readable and writable by you — enforced by the database itself, not by application code that could have a bug.

Roles kept in a separate table

Admin and user roles live in their own table, checked through a dedicated security-definer function, instead of a role column on your profile that a compromised session could edit. You can't grant yourself admin by editing a row you own.

Secrets never touch client code

API keys, service-role database credentials, and anything else sensitive stay server-side. The browser only ever talks to our public, rate-limited API surface — never a secret key.

Rate-limited public endpoints

Endpoints that don't require login — like the contact form and public report pages — are rate-limited per IP address to stop abuse and spam without needing a CAPTCHA on every form.

Backups

Our database is backed up automatically on a rolling schedule by our infrastructure provider, so a bad deploy or a fat-fingered migration isn't a total-loss event.

Subprocessors

We use Lovable Cloud for hosting, our Postgres database, and authentication. That's the full list — we don't pipe your data through a chain of third-party analytics or marketing tools.

What Velora does not do

  • Sell or rent your data to anyone, ever.
  • Record your sessions, keystrokes, or screen while you use the app.
  • Share your project data with other Velora users, even in aggregate, without your public-report toggle being on.
  • Store payment card details on our servers — billing is handled by a PCI-compliant processor.

Found a vulnerability?

Email security@velora.app with details and reproduction steps. We aim to acknowledge reports within one business day and don't take legal action against good-faith security research.

Contact us instead