Security & Privacy

This site is built with customer privacy, data protection and security as a top priority. This page explains what is in place, what you must configure, and what still needs professional review.

No website is “100% secure.” The measures below significantly reduce risk, but residual risks remain. Before accepting real customer information and payments, complete the items in “Still to configure” and the professional reviews listed below.

What we protect

We treat the following as personal data and protect it accordingly: names, email addresses, account information, purchase history, payment records, and the written content you submit. Users can never access another customer’s private information, even by changing URLs or request parameters — access is checked on the server.

Security measures implemented

  • Row-level security on every entity — users can only read and change their own private records (subscriptions, payments), enforced server-side.
  • Admin-only actions (managing books, setting page subjects, audit logs) are checked on the server, not just hidden in the UI.
  • Server-side backend functions validate every request and authenticate the user before acting.
  • An audit log records important actions (page claims, subscriptions, admin edits).
  • Payments run through Stripe Checkout — card numbers, CVV and PINs never touch our database.
  • Webhook payments are verified by Stripe signature and made idempotent (no duplicate claims).
  • Only the minimum payment data is stored: status, transaction ID, amount and currency.
  • API keys and secrets live in server-side environment variables, never in frontend code.
  • Customer-facing errors are generic and safe — no stack traces, internal IDs or other customers’ data are shown.
  • Cookie consent banner lets visitors choose essential-only or all cookies.

Payments

Card payments are processed by Stripe. We never see or store full card numbers, CVV/security codes or PINs. Only the payment status, transaction ID, amount and currency are stored. Payments are confirmed via a signed webhook from Stripe, not by trusting the browser, and duplicate webhooks are handled safely.

Database & access control

Access is enforced with row-level security on every entity. Subscriptions and payments are private to their owner and to admins. Public book content stores only a display name you choose — never your email. Admin functions verify the admin role on the server, so a normal customer cannot reach admin features by changing a URL.

Your privacy & UK GDPR rights

We collect only what the site needs: your email to create an account, a display name for credits, and your written pages. We aim to support:

  • Access — you can request a copy of your data.
  • Correction — you can ask us to fix inaccurate information.
  • Deletion — you can ask us to delete your account and data where legally applicable.
  • Retention — data is kept only as long as needed and can be removed on request.

A formal privacy policy and retention schedule should be drafted and reviewed by a qualified professional before launch.

Third-party services

Stripe

Data sent: Email address, payment amount and page reference. Card details are handled entirely by Stripe and never reach us.

Why: To process card payments and subscriptions securely.

Storage: Stripe stores the card data (PCI-DSS). We store only the payment status and transaction ID.

Base44 (hosting platform)

Data sent: Account email, name, written page content, subscription and payment records.

Why: To host the app, database and authentication.

Storage: Stored in the platform’s managed database under your account.

Still to configure or enable

  • Live Stripe keys — the app currently runs in Stripe test mode. Provide your own keys (Dashboard → Integrations) before accepting real money.
  • Email verification and password reset are handled by the platform’s auth; review the configured settings before launch.
  • Rate limiting / brute-force protection on login is a platform-level control — confirm it is enabled for your plan.
  • HTTPS and secure-cookie settings are managed by the hosting platform — verify they are active on your published domain.
  • Regular encrypted backups of customer data — confirm the backup schedule and retention with the platform.
  • Two-factor authentication for admin accounts — enable it on your admin account if the platform supports it.

Requires professional review

  • A cybersecurity professional should penetration-test the app before accepting real payments.
  • A UK solicitor or Data Protection Officer should review the privacy policy, data retention and GDPR documentation.
  • A Data Protection Impact Assessment (DPIA) is recommended given that personal data and payments are processed.

Security checklist summary

Server-side authorization (RLS) Implemented
Admin role enforced server-side Implemented
Stripe Checkout (no card storage) Implemented
Signed, idempotent payment webhook Implemented
Audit logging Implemented
Safe error messages Implemented
Cookie consent Implemented
Live Stripe keys Configure
Email verification / 2FA for admins Professional review
Rate limiting & brute-force protection Professional review
Privacy policy (legal review) Professional review
Penetration test before launch Professional review

Last updated 30/09/2026. This page is a summary of protections, not a guarantee of security.

    We use essential cookies to run the site and optional ones to understand how it's used. See our privacy policy.