Trust

Security

How System Reset protects your accounts, content and credentials.

About this page

This page is maintained by System Reset to answer common security and privacy questions about Done Money. It describes the controls we operate today. It is not an independent certification, and we make no audit or compliance-certification claims: we have not completed a SOC 2, ISO 27001 or third-party penetration test. When we do, this page will say so with a date.

Authentication

Email and password with verification, plus Google sign-in. Passwords are hashed by our authentication provider and never stored by us. Password reset is single-use and time-limited.

Per-row access rules

Every table in our database enforces row-level security tied to the signed-in user. A request that is not yours returns nothing — the isolation is enforced by the database, not by application code alone.

Credential encryption

Platform client secrets you supply for your own developer apps are encrypted with AES-256-GCM before they are written to the database. The encryption key lives only in server environment configuration and is never present in the browser bundle.

Tokens never reach the browser

OAuth access and refresh tokens are read and used exclusively in server code. Publishing, metric collection and inbox sync all run server-side. Nothing in the client bundle can read a token.

Transport and storage

All traffic is HTTPS with TLS. Media lives in a private storage bucket accessible only through short-lived signed URLs issued to the owning account. Backups are managed by our hosting provider.

Least-privilege OAuth

We request only the scopes needed to publish and read engagement on the channels you connect. Every scope we request is published per platform on the integration status page.

Disconnect and delete

Disconnecting a channel deletes the stored token immediately. Account deletion removes your content, media and credentials within 30 days.

Monitoring

Application errors and publishing failures are logged and alerted. Failed channel connections trigger an email so a silent disconnection cannot quietly break your queue.

AI handling

Your content is not used to train any AI model — not ours, and not our providers'. Prompts are sent to the AI provider only to produce the output you asked for, and are not retained by us beyond the generated result you keep in your library.

Who processes your data

  • Lovable Cloud (Supabase infrastructure)Application hosting, database, authentication and media storage.
  • StripePayment processing, invoicing and billing portal.
  • ResendTransactional email delivery (receipts, resets, alerts).
  • Google (Gemini via the Lovable AI Gateway)AI content generation you explicitly request.
  • Social platform APIs you connectPublishing, comment and message retrieval, engagement metrics.

Full detail, including data categories and regions, is in the privacy policy.

Shared responsibility

We secure the platform, encrypt credentials and isolate accounts. You are responsible for the strength of your password, who you invite into a workspace, the developer apps and scopes you create on each social platform, and the content and automation rules you publish. Review your automation rules before enabling them on a live audience.

Reporting a vulnerability or incident

Email support@done.money with “Security” in the subject. We acknowledge within two working days and will not pursue good-faith researchers who avoid privacy violations, data destruction and service disruption. Postal: System Reset, 2 John St., Burford, Ontario, N0E 1A0, Canada. Telephone 1-226-775-0156.