Trust & Privacy

This page is maintained by UnlockYourPurpose Academy to answer common security and privacy questions about our platform. It describes app-owned practices and Lovable platform capabilities we have enabled. It is editable project content and is not an independent certification or third-party audit.

Security is a shared responsibility: Lovable provides the hosting platform and primitives, UnlockYourPurpose Academy operates the application and configures its access controls, and customers are responsible for protecting their own credentials and content.

Access & authentication

  • Email/password and Google sign-in are supported.
  • Passwords are stored and verified by our managed auth provider; we never see plaintext passwords.
  • Sessions use short-lived bearer tokens that refresh automatically.
  • Administrative actions are gated by role checks enforced server-side.

Data isolation & storage

  • Each organization's courses, members, enrollments, and progress are isolated via row-level security at the database layer.
  • Sensitive fields such as Stripe billing identifiers and payment links are accessible only to server-side service code, not to signed-in users via the public API.
  • Data is hosted on Supabase (managed Postgres). Connections to the platform use TLS.
  • Uploaded files (e.g. organization logos) are stored in a private bucket and served via short-lived signed URLs.

Platform & hosting

The application is built and hosted on Lovable, which provides the underlying compute, CDN, TLS termination, and managed database. Describing these capabilities is not a certification of Lovable or UnlockYourPurpose Academy.

Subprocessors & integrations

We rely on the following third-party services to operate the platform:

  • Lovable — application hosting and build.
  • Supabase — managed Postgres database, authentication, storage.
  • Stripe — payment processing for plans and course purchases. We do not store full card numbers.
  • Resend — transactional and authentication email delivery.
  • Google — optional OAuth sign-in.

Contact us if you need a current subprocessor list for a procurement review.

Cookies & analytics

We use cookies and local storage strictly required to keep you signed in and to remember interface preferences. We do not embed third-party advertising trackers in the authenticated portal.

Data retention & deletion

Course content, enrollments, and progress are retained while your organization's account is active. Account owners can request export or deletion of their organization's data by contacting us.

Vulnerability reporting

If you believe you have found a security issue, please email us with reproduction steps. Please do not publicly disclose the issue until we have had a reasonable chance to investigate and respond.

Contact

For security, privacy, data export, or compliance questions, contact the academy owner who provisioned your access, or reach our team at support@unlockyourpurpose.academy.

Compliance, certification, encryption-at-rest, and regulatory claims (GDPR, HIPAA, SOC 2, ISO, PCI, etc.) are intentionally not asserted on this page. Contact us if you need a current statement for procurement.