⚠ Draft — pending legal review; not yet binding.
Security
Last updated July 2026
We take the security of your speeches and account seriously. This page summarises how we protect data and how to report an issue.
How we protect data
- In transit. All traffic is served over HTTPS/TLS.
- Authentication. Sign-in is handled by Keycloak (OpenID Connect); sessions are signed and httpOnly.
- Payments. Card data is handled entirely by Stripe — it never touches our servers.
- Access. Speeches are scoped to your account or your device; other users can’t read them.
- Abuse controls. Rate limiting and a bot challenge protect the generation endpoints.
Data storage
Data is stored in a managed PostgreSQL database on our infrastructure. Deleting your account removes your speeches and account data.
Reporting a vulnerability
If you believe you’ve found a security issue, please email [email protected] with details. We’ll acknowledge your report and work with you on a fix. Please give us reasonable time to respond before any public disclosure.
© 2026 Operated by Beardown Ltd · Company No. 16627254 · [email protected]