Trust & Security

    This page is maintained by OS Tools to answer common security and privacy questions. It describes controls we have in place today and is not an independent certification.

    See also: System status, Privacy policy, DPA, GDPR.

    Platform & hosting

    OS Tools runs on managed Postgres, edge functions, and object storage provided by Lovable Cloud (built on Supabase).

    All traffic is served over HTTPS with TLS 1.2+. Data is encrypted at rest using AES-256 on the underlying storage layer.

    Automated backups run daily with point-in-time recovery available.

    Access control & authentication

    Users sign in with Google OAuth or email + password. Passwords are hashed by the auth provider; we never see plaintext.

    Leaked-password checking is enabled — passwords are compared against Have I Been Pwned during signup and password change.

    Every application table is protected by row-level security. Users can only read and write rows scoped to their own account.

    Administrative access is gated by a separate roles table with server-side validation.

    Data handling & retention

    What we store: your email, uploaded CSV inputs while a job runs, job results (until you download or 30 days), credit ledger, purchase records.

    Retention: completed and failed job data is purged automatically after 30 days. Ad-attribution and consent audit logs are purged after 180 days.

    Deletion on request: you can delete your account from Account → Privacy. This cascades to credits, transactions, jobs, and preferences.

    Data export: a one-click JSON export is available in the same tab.

    Operational safety

    Every long-running job has a stale-detection watchdog. If a job stalls, credits for unprocessed rows are refunded automatically.

    Health checks run on a schedule and record uptime snapshots visible on the status page.

    Failed background jobs trigger internal alerts so we can respond quickly.

    Subprocessors

    We use the following third parties to deliver the service. Each processes only the data required for its purpose.

    ProviderPurposeRegion
    Lovable Cloud (Supabase)Database, auth, edge functions, file storageEU / US
    WhopPayment processing & receiptsUS
    ResendTransactional email deliveryUS / EU
    Google (OAuth)Sign-in with GoogleGlobal
    EmailListVerifyEmail deliverability checks (Email Verifier)EU
    ZeroBounceEnhanced email verification (Verify Plus)US
    Jina AIWebsite content extraction (Website Analyzer)Global
    Google GeminiAI reasoning on scraped contentUS
    Meta (Pixel + CAPI)Ad measurement — only when consentedUS
    TelegramInternal ops alerts (no customer data)Global

    Cookies & tracking

    Only strictly necessary cookies (session, security) are set by default. Analytics and advertising cookies are opt-in per vendor.

    You can review and change your choices any time via .

    Full detail: Cookie policy.

    Compliance posture

    OS Tools is designed to align with GDPR requirements: lawful basis, granular consent, data subject rights, and a signed Data Processing Addendum available on request.

    We do not currently hold SOC 2 or ISO 27001 certification. Enterprise customers evaluating us should request our security questionnaire response via the contact below.

    Governing law: Hong Kong SAR.

    Report a vulnerability

    Found a security issue? Please email us and we will acknowledge within one business day.

    security@os-tools.com

    Please do not publicly disclose the issue until we have had a chance to remediate it.

    Shared responsibility

    OS Tools secures the platform. You are responsible for keeping your account credentials safe, using unique passwords, and reviewing which data you upload.

    Support

    We typically reply in a few hours

    Hi! 👋 How can we help you today?

    Enter your email so we can reply to you: