Legal
Security
Limespun is new. This page says exactly what we do to protect your studio's data today, and what's still to come. We'd rather be precise than impressive.
- In transit and at rest, with AES-256
- Encrypted
- Each studio’s data walled off from every other
- Separate
- Two-factor sign-in, available on every account
- 2FA
- To tell you about a breach we find
- 72 hours
On this page
Encryption
All traffic to Limespun is encrypted in transit (HTTPS with HSTS). The HSTS header is set for preloading, so browsers never connect to the app over plain HTTP.
Data is encrypted at rest (AES-256) by our database and storage provider. On top of that, Limespun encrypts some fields itself with AES-256-GCM, including connected-app credentials and consent forms that are still in draft.
Separation between studios
Every studio's records are separated at the database level with row-level security, scoped to the studio. One studio's account can't read another studio's clients, bookings or forms.
Sign-in
Accounts use Supabase Auth. Passwords must be at least 8 characters with upper-case, lower-case and a number.
Two-factor authentication with an authenticator app is available on every account, with recovery codes. Sessions use short-lived tokens that refresh automatically.
Export and activity log
Studio owners and admins can export the client list as CSV at any time, and every user can download a copy of their own data from settings.
Signed consent forms are stored as PDFs in private storage. They're served through links that expire after an hour, and can be downloaded whenever you need them.
Key actions in your studio are recorded in an activity log that owners can review.
Web security
The app sends a strict Content Security Policy, blocks being embedded in other sites (clickjacking protection), and limits the referrer information shared with other sites.
Hosting
Your studio's database and files are hosted by our infrastructure providers in the United States (AWS us-west-2, Oregon); the app runs on Railway.
We don't offer EU data hosting yet. If your studio needs it, tell us: it's on our list.
Sub-processors
These providers process studio data on our behalf, each for the purpose listed. The Privacy Policy covers how we use personal data.
| Provider | What it does for Limespun |
|---|---|
| Supabase | Database, file storage and sign-in |
| Railway | Application hosting |
| Upstash | Rate limiting |
| Resend | |
| Dodo Payments | Subscription billing and card payments |
| Twilio | Text messages (SMS) |
| Anthropic | AI features: suggested replies, aftercare and consult summaries, and flash image tagging |
Backups
We take regular database snapshots. Automated backups with point-in-time recovery are next on our list, and we'll update this page when they're switched on.
Breach notification
If we discover a personal data breach affecting your studio, we'll tell you within 72 hours of finding it: what happened, what it likely means for you, and what we're doing about it.
Reporting a vulnerability
Found something? Email security@boldteq.com with the details. We read every report, and we won't take action against anyone researching in good faith who reports responsibly and avoids harming studios or their clients.
Planned work
Next on our list: automated backups with point-in-time recovery, an option for EU data hosting, and an independent penetration test. We don't hold a SOC 2 report today, and we won't say we do until we have one.
Questions about your data?
Plain answers from the founding team.
Email hello@boldteq.com about anything these pages don't cover. Security reports go to security@boldteq.com.