Security

Your data is yours.

Your trust is our priority. Here's how we protect your study data and privacy with enterprise-grade security measures and transparent practices.

What we build in

Security by default.

Six safeguards baked into every layer of the platform — not bolted on later.

Encryption in transit & at rest

Traffic is protected with TLS/SSL, and sensitive data is encrypted at rest using AES-256.

Secure authentication

Strong password requirements (bcrypt-hashed, never stored in plain text) and OAuth sign-in for account protection.

Isolated per-user data

Row-Level Security in our database keeps each account’s content separated. We access your content only to provide the service (e.g. generating your flashcards).

Reliable infrastructure

Hosted on managed cloud infrastructure (Supabase, DigitalOcean) with redundant backups and automatic security updates.

Privacy by design

We collect only the data necessary to run the service and never sell your personal information to third parties.

Access controls

A permissions system lets you control who can access the study materials you choose to share.

Compliance

Privacy commitments.

We align our data-protection practices with recognized privacy standards.

GDPR aligned

Data-handling practices aligned with EU data protection principles, including account deletion on request.

CCPA aligned

Practices aligned with California Consumer Privacy Act principles.

Built for ages 13+

GoodOff is intended for users aged 13 and older; the 18+ community section is gated separately.

How we operate

Our security practices.

We implement comprehensive security measures across all aspects of our platform, from development to deployment and ongoing maintenance.

Daily discipline

  • Regular security audits and penetration testing
  • Automated vulnerability scanning and patching
  • Employee security training and background checks
  • Incident response plan with 24/7 monitoring
  • Regular data backups with geographic redundancy
  • Secure development lifecycle (SDLC) practices
  • Third-party security assessments and code reviews
  • Network security with firewall and intrusion detection

What we build in

The core protections in place today.

  • Encryption in transit (TLS) and at rest (AES-256) for sensitive data
  • Row-Level Security isolating each account’s content
  • Bcrypt password hashing — plain-text passwords are never stored
  • Delete your account and associated data at any time
Disclosure

Responsible reporting.

Security researchers and users who discover potential vulnerabilities can report them through our responsible disclosure program.

How to report

Email [email protected] or [email protected].

  • PGP key available on request
  • Include detailed reproduction steps
  • We respond within 24 hours

Our commitment

  • No legal action for good-faith research
  • Credit given for valid reports
  • Coordinated disclosure timeline
  • Bug bounty rewards available
Still have questions?

Our security team is listening.

We're available to address any concerns or questions about how we protect your data.

Security — GoodOff