Effective and last updated: June 15, 2026

Security

Cruxl uses layered safeguards designed to protect accounts and content. No internet service can guarantee absolute security.

1. Safeguards

  • HTTPS/TLS is used to protect data in transit.
  • Supabase authentication and row-level database policies are used to control account access.
  • Uploaded files are configured for private access and short-lived signed access where needed.
  • Administrative credentials and server-side provider keys are kept out of client application code.
  • Rate limits, input validation, authorization checks, and security logging are used on sensitive server functions.
  • Payment-card information is collected and processed by Stripe rather than stored in Cruxl's database.

2. Voice and local recordings

Audio submitted for transcription is transmitted to Cruxl's infrastructure and Google Gemini for processing. Cruxl does not intentionally save that submitted audio in its server database after the request completes. Recordings you explicitly save for later may remain in browser or device storage until you delete them.

3. Your role

  • Use a unique password and protect access to your email account and devices.
  • Review collaborators and public-link settings before sharing sensitive content.
  • Do not place secrets, credentials, or information you are not authorized to disclose into prompts or uploads.
  • Sign out of shared devices and report suspicious activity promptly.

4. Vulnerability reporting

Send security reports to contact@cruxl.app. Include affected URLs, reproduction steps, impact, and relevant evidence. Do not access other users' data, disrupt the Service, use social engineering, or publicly disclose an unresolved issue. We will acknowledge and assess good-faith reports as resources permit.

5. Security incidents

If we determine that a security incident affects personal information, we will investigate, mitigate, and provide legally required notices to affected users or authorities.