← Back to home

Trust & Security

This page is maintained by the YaadRakhe team to answer common security and privacy questions about the app. It describes controls that are enabled today; it is not an independent certification or audit.

Access & authentication

  • Email/password sign-in with hashed credentials — we never see your password.
  • Sessions are issued as short-lived tokens and refreshed automatically.
  • Account deletion is available from /legal/delete-account; removing your account removes your data.

Data protection

  • All traffic between your device and our backend is encrypted in transit (HTTPS/TLS).
  • Every record in the database is scoped to the signed-in user via row-level access policies — one account cannot read another account's people, records, meetings, tasks or notes.
  • Server-side endpoints validate your session before reading or writing data.
  • Input is validated server-side before being persisted.

Hosting & subprocessors

YaadRakhe runs on Lovable Cloud (managed Supabase + edge runtime). Voice transcription and structured-field extraction are performed by Google Gemini and OpenAI. See the Privacy Policy for the full list and what each provider receives.

Your privacy rights

  • View and edit all your data inside the app at any time.
  • Export your data from Settings.
  • Delete your account and all associated data from the account-deletion page.

Reporting a security issue

If you believe you've found a vulnerability, please email the address listed in our Privacy Policy. We aim to acknowledge reports within a few business days.

Shared responsibility

YaadRakhe secures the application, database, and hosting platform. You're responsible for keeping your account password confidential and for the accuracy of the data you save. Compliance with local data-protection laws applicable to your business remains your responsibility.

See also: Privacy Policy · Terms