This page is maintained by OS Tools to answer common security and privacy questions. It describes controls we have in place today and is not an independent certification.
See also: System status, Privacy policy, DPA, GDPR.
OS Tools runs on managed Postgres, edge functions, and object storage provided by Lovable Cloud (built on Supabase).
All traffic is served over HTTPS with TLS 1.2+. Data is encrypted at rest using AES-256 on the underlying storage layer.
Automated backups run daily with point-in-time recovery available.
Users sign in with Google OAuth or email + password. Passwords are hashed by the auth provider; we never see plaintext.
Leaked-password checking is enabled — passwords are compared against Have I Been Pwned during signup and password change.
Every application table is protected by row-level security. Users can only read and write rows scoped to their own account.
Administrative access is gated by a separate roles table with server-side validation.
What we store: your email, uploaded CSV inputs while a job runs, job results (until you download or 30 days), credit ledger, purchase records.
Retention: completed and failed job data is purged automatically after 30 days. Ad-attribution and consent audit logs are purged after 180 days.
Deletion on request: you can delete your account from Account → Privacy. This cascades to credits, transactions, jobs, and preferences.
Data export: a one-click JSON export is available in the same tab.
Every long-running job has a stale-detection watchdog. If a job stalls, credits for unprocessed rows are refunded automatically.
Health checks run on a schedule and record uptime snapshots visible on the status page.
Failed background jobs trigger internal alerts so we can respond quickly.
We use the following third parties to deliver the service. Each processes only the data required for its purpose.
| Provider | Purpose | Region |
|---|---|---|
| Lovable Cloud (Supabase) | Database, auth, edge functions, file storage | EU / US |
| Whop | Payment processing & receipts | US |
| Resend | Transactional email delivery | US / EU |
| Google (OAuth) | Sign-in with Google | Global |
| EmailListVerify | Email deliverability checks (Email Verifier) | EU |
| ZeroBounce | Enhanced email verification (Verify Plus) | US |
| Jina AI | Website content extraction (Website Analyzer) | Global |
| Google Gemini | AI reasoning on scraped content | US |
| Meta (Pixel + CAPI) | Ad measurement — only when consented | US |
| Telegram | Internal ops alerts (no customer data) | Global |
Only strictly necessary cookies (session, security) are set by default. Analytics and advertising cookies are opt-in per vendor.
You can review and change your choices any time via .
Full detail: Cookie policy.
OS Tools is designed to align with GDPR requirements: lawful basis, granular consent, data subject rights, and a signed Data Processing Addendum available on request.
We do not currently hold SOC 2 or ISO 27001 certification. Enterprise customers evaluating us should request our security questionnaire response via the contact below.
Governing law: Hong Kong SAR.
Found a security issue? Please email us and we will acknowledge within one business day.
Please do not publicly disclose the issue until we have had a chance to remediate it.
OS Tools secures the platform. You are responsible for keeping your account credentials safe, using unique passwords, and reviewing which data you upload.
We typically reply in a few hours
Enter your email so we can reply to you: