Security
Security and data protection, in concrete terms.
This page describes where your data lives, who can see it, and what you control at any time. No marketing: only what is actually implemented.
Data location
Your data lives in the EU.
The database and photo storage run on Supabase on AWS in Stockholm (eu-north-1). Transactional email is processed by Resend in the EU (AWS Ireland, eu-west-1). The application is delivered through Vercel's global network; its server functions also run in Stockholm.
Access
Photos are not public.
All storage buckets are private and there are no public image URLs: every retrieval goes through short-lived signed links. Profiles and photos only become visible after signing in as a company and cannot be found through search engines. Every database table is protected with Row Level Security: each role sees only what belongs to it or has been shared with it.
Hardening
Encrypted, audited, hardened.
All traffic is TLS-only (HSTS enforced), and stored data is encrypted at rest (AES-256, AWS standard). The application sets strict security headers including a Content Security Policy. In July 2026 we ran an internal security audit and closed all critical and high findings.
Consent
Every consent is versioned.
You define precisely what you allow: usage types, industry exclusions, visibility. Every consent is recorded with a timestamp and the exact text version, from the 18+ self-declaration to the binding license confirmation to the showcase release of individual campaign images. Consent can be withdrawn, and your complete consent log is part of your data export.
Control
Export and deletion, any time.
You can export all of your data as a JSON file at any time and delete your account yourself: photos, appearance, identity and KYC data are removed immediately. Completed contracts are retained without personal reference due to statutory retention obligations. After a campaign ends, the system automatically asks companies to delete the dataset and documents their confirmation.
Providers
The processors we rely on.
Few, established providers. Card data never reaches our servers at any point.
Supabase
Database & photo storage
AWS EU (Stockholm)
Vercel
Hosting & delivery
Global CDN, functions EU (Stockholm)
Stripe
Payments & identity verification
PCI-DSS certified
Resend
Transactional email
AWS EU (Ireland)
Microsoft 365
Business email
Microsoft data centers
Details are governed by the privacy policy.
Reporting
Found a vulnerability?
Write to us directly. We take responsible reports seriously, respond quickly, and will not pursue legal action against good-faith security research.
hello@faceledger.ai