Authentication
- Passwords are salted and hashed with bcrypt before they are stored.
- Sessions use signed JSON Web Tokens that expire after 7 days.
- Google sign in tokens are verified on our server, including the intended audience and expiry, before an account is created or linked.
Data protection
- All traffic between your browser, our API, and our providers is encrypted with HTTPS in production.
- Your data is stored in a managed Postgres database hosted by Neon, which encrypts data at rest.
- Every database query that touches your content is filtered by your account ID, so one user can never read or change another user's data.
- All database queries are parameterized to prevent SQL injection.
Application safeguards
- Every API request is validated against a strict schema, with limits on input length.
- Credit deductions are atomic, which prevents race conditions from creating free usage.
- Paid plans cannot be selected through the API until they launch.
- The contact form is rate limited and protected against bots.
- AI video renders are limited per account, and failed renders are refunded automatically.
Third party providers
We rely on established providers for infrastructure and AI processing: Neon for the database, Groq for text generation, fal.ai for video generation, Google for sign in, and Vercel and Render for hosting. The privacy policy lists what each provider receives.
Reporting a vulnerability
If you believe you have found a security issue, please report it through the contact page and choose the Security report topic. Include the steps to reproduce it and the impact you expect. We will acknowledge your report, keep you updated, and credit you if you would like once it is fixed.
Please act in good faith while researching:
- Only test against your own account and data.
- Do not access, change, or delete other users' data.
- Do not run denial of service attacks, spam, or social engineering.
- Give us reasonable time to fix the issue before sharing it publicly.