About this page
This page is maintained by System Reset to answer common security and privacy questions about Done Money. It describes the controls we operate today. It is not an independent certification, and we make no audit or compliance-certification claims: we have not completed a SOC 2, ISO 27001 or third-party penetration test. When we do, this page will say so with a date.
Authentication
Email and password with verification, plus Google sign-in. Passwords are hashed by our authentication provider and never stored by us. Password reset is single-use and time-limited.
Per-row access rules
Every table in our database enforces row-level security tied to the signed-in user. A request that is not yours returns nothing — the isolation is enforced by the database, not by application code alone.
Credential encryption
Platform client secrets you supply for your own developer apps are encrypted with AES-256-GCM before they are written to the database. The encryption key lives only in server environment configuration and is never present in the browser bundle.
Tokens never reach the browser
OAuth access and refresh tokens are read and used exclusively in server code. Publishing, metric collection and inbox sync all run server-side. Nothing in the client bundle can read a token.
Transport and storage
All traffic is HTTPS with TLS. Media lives in a private storage bucket accessible only through short-lived signed URLs issued to the owning account. Backups are managed by our hosting provider.
Least-privilege OAuth
We request only the scopes needed to publish and read engagement on the channels you connect. Every scope we request is published per platform on the integration status page.
Disconnect and delete
Disconnecting a channel deletes the stored token immediately. Account deletion removes your content, media and credentials within 30 days.
Monitoring
Application errors and publishing failures are logged and alerted. Failed channel connections trigger an email so a silent disconnection cannot quietly break your queue.
AI handling
Your content is not used to train any AI model — not ours, and not our providers'. Prompts are sent to the AI provider only to produce the output you asked for, and are not retained by us beyond the generated result you keep in your library.
Who processes your data
- Lovable Cloud (Supabase infrastructure) — Application hosting, database, authentication and media storage.
- Stripe — Payment processing, invoicing and billing portal.
- Resend — Transactional email delivery (receipts, resets, alerts).
- Google (Gemini via the Lovable AI Gateway) — AI content generation you explicitly request.
- Social platform APIs you connect — Publishing, comment and message retrieval, engagement metrics.
Full detail, including data categories and regions, is in the privacy policy.
Shared responsibility
We secure the platform, encrypt credentials and isolate accounts. You are responsible for the strength of your password, who you invite into a workspace, the developer apps and scopes you create on each social platform, and the content and automation rules you publish. Review your automation rules before enabling them on a live audience.
Reporting a vulnerability or incident
Email support@done.money with “Security” in the subject. We acknowledge within two working days and will not pursue good-faith researchers who avoid privacy violations, data destruction and service disruption. Postal: System Reset, 2 John St., Burford, Ontario, N0E 1A0, Canada. Telephone 1-226-775-0156.