Security

How we keep your work safe.

Your ideas and drafts are yours. Here is exactly how we protect them.

Last updated September 28, 2026

Report a vulnerability

Hashed passwords

Passwords are salted and hashed with bcrypt. We never store or log them in plain text.

Isolated accounts

Every read, update, and delete is scoped to your account on the server.

Keys stay server side

AI provider keys never reach the browser. All provider calls happen on our API.

Authentication

  • Passwords are salted and hashed with bcrypt before they are stored.
  • Sessions use signed JSON Web Tokens that expire after 7 days.
  • Google sign in tokens are verified on our server, including the intended audience and expiry, before an account is created or linked.

Data protection

  • All traffic between your browser, our API, and our providers is encrypted with HTTPS in production.
  • Your data is stored in a managed Postgres database hosted by Neon, which encrypts data at rest.
  • Every database query that touches your content is filtered by your account ID, so one user can never read or change another user's data.
  • All database queries are parameterized to prevent SQL injection.

Application safeguards

  • Every API request is validated against a strict schema, with limits on input length.
  • Credit deductions are atomic, which prevents race conditions from creating free usage.
  • Paid plans cannot be selected through the API until they launch.
  • The contact form is rate limited and protected against bots.
  • AI video renders are limited per account, and failed renders are refunded automatically.

Third party providers

We rely on established providers for infrastructure and AI processing: Neon for the database, Groq for text generation, fal.ai for video generation, Google for sign in, and Vercel and Render for hosting. The privacy policy lists what each provider receives.

Reporting a vulnerability

If you believe you have found a security issue, please report it through the contact page and choose the Security report topic. Include the steps to reproduce it and the impact you expect. We will acknowledge your report, keep you updated, and credit you if you would like once it is fixed.

Please act in good faith while researching:

  • Only test against your own account and data.
  • Do not access, change, or delete other users' data.
  • Do not run denial of service attacks, spam, or social engineering.
  • Give us reasonable time to fix the issue before sharing it publicly.