Trust & Data Protection

This page is maintained by the SENTracker team to answer common security and data-protection questions about the SENTracker app. It describes controls that are currently enabled and practices we follow. It is not an independent certification.

Where your data lives

  • All account data, child profiles, evidence records, documents, screenshots, voice recordings and generated reports are stored in Lovable Cloud (Supabase), hosted in the European Union — Frankfurt (eu-central-1).
  • Data at rest is encrypted by default. Data in transit is encrypted using TLS.
  • All file-storage buckets are private. Files are served through short-lived signed URLs only.

Sub-processors

  • Lovable Cloud / Supabase — application hosting, database, authentication, file storage (EU).
  • Lovable AI Gateway — routes AI requests to underlying providers. Retention up to 90 days of request/response logs where AI app context is enabled; not used for model training.
  • OpenAI — voice-note transcription (via Lovable AI Gateway). Requests are not used to train OpenAI models.
  • Google Gemini — document and evidence analysis (via Lovable AI Gateway). Requests are not used to train Google models.
  • Lovable Email — transactional and authentication email (EU).
  • Systeme.io — subscription checkout and billing webhooks (EU).

Lovable's platform-level sub-processor list, DPA and security posture are published at trust.lovable.dev.

Backups & recovery

  • Daily database backups with approximately 14 days of retention (managed by Lovable Cloud).
  • Recovery Point Objective (worst-case data loss): up to 24 hours.
  • Restore operates on the whole database; individual-user restore is not offered.
  • Users can export their own data at any time from the Export page.

Retention

  • Evidence, documents, voice notes, reports and account data are retained for as long as the account is active. SEND matters can span many years (annual reviews, tribunals, transitions) so we do not auto-delete evidence.
  • Backups roll off after ~14 days.
  • Email send logs are retained for operational deliverability monitoring.

Account deletion

  • When you request deletion from Settings, your account enters a 30-day grace period. You can cancel by signing back in during that window.
  • After 30 days, a scheduled job permanently removes: your login, profile, child records, evidence, documents, screenshots, voice recordings, generated PDFs, subscription record, and email history for your address.
  • Data may remain in daily database backups for up to 14 further days before rolling off. After that, no copy remains in SENTracker systems.

AI processing

  • AI is used for two things only: transcribing your voice notes, and summarising documents you upload.
  • Prompts and outputs may be retained in Lovable AI Gateway logs for up to 90 days for debugging.
  • Your data is not used to train AI models by SENTracker, Lovable, OpenAI or Google.

Access controls

  • Row-level security policies restrict every read and write to the account that owns the data.
  • The SENTracker service role key is used only server-side for scheduled maintenance and webhook processing.
  • Lovable / Supabase infrastructure staff may access production systems for support in line with the platform DPA.

Authentication & account security

  • Sign-in is email and password, managed by the platform authentication service. Passwords are stored only as salted bcrypt hashes and are never visible to SENTracker.
  • Sessions use short-lived access tokens with automatic refresh; email addresses must be verified before first sign-in.
  • Multi-factor authentication for end users is not currently implemented.

Data segregation

  • Every user-data table carries an owner column, and row-level security policies scope reads and writes to the signed-in account.
  • Uploaded files are namespaced per user inside private buckets, with storage policies enforcing the same ownership rule.
  • Elevated permissions are held in a dedicated roles table and checked through a hardenedhas_role() database function — never from client-side state.

Monitoring & administrator access

  • Platform-level access, authentication and request logs are maintained by the hosting provider.
  • In-app product analytics record anonymous usage events (for example, that a demo was started) against a random browser identifier. They contain no name, email or evidence content.
  • SENTracker administrators do not use the app's admin tools to browse customer evidence. Direct database access is limited to the account owner of the project and is used only for billing reconciliation, incident investigation and support requests you raise.
  • A customer-visible audit log is not currently implemented.

Certifications

SENTracker holds no independent certifications of its own (no SOC 2, ISO 27001 or equivalent). The application is designed to support UK GDPR and EU GDPR requirements — lawful basis, data minimisation, EU residency, erasure and portability — but that is a design commitment, not an audited assurance. Platform-level security posture and compliance artefacts for our infrastructure provider are published at trust.lovable.dev.

Not currently implemented

We publish this list so partners can assess us accurately:

  • Multi-factor authentication for end users
  • Point-in-time recovery and per-user (selective) restore
  • Customer-visible audit log
  • Independent penetration test report
  • Signed customer-facing Data Processing Agreement template

Your rights

UK / EEA users can exercise their GDPR rights (access, rectification, erasure, portability, restriction, objection) from Settings, or by contacting us via Help & support. See our Privacy Policy for full detail.

SENTracker.app · EU-hosted · UK GDPR-aware · Not a diagnostic, clinical or legal tool.