Trust Center

Security & Privacy at Account AB

This page is maintained by Account AB to answer common security and privacy questions about the app. It describes enabled controls and current practices and is not an independent certification.

Authentication & access

Accounts use email/password and Google sign-in. Sessions are issued and refreshed by our managed backend; passwords are never stored in plaintext by Account AB.

Admin tooling is gated by a server-side role check — being a logged-in user is not enough to reach admin pages or data.

Data protection & row-level security

All user data lives in a managed Postgres database with row-level security enabled on every user-owned table. Policies restrict reads and writes to the owning user, circle members, or admins — enforced at the database, not just the UI.

Private Accountability Circles, private circle media, whiteboards, and direct messages are visible only to participants.

Premium & payments

Premium entitlement is checked server-side before any paid feature (AI Perspective Report, Reality Check, Accountability Insights, Private Accountability Circles) is delivered. Client-side flags are treated as UX hints only.

Email & communications

Transactional and authentication emails are queued and sent through our managed email infrastructure. Recipient lists, unsubscribe tokens, and bounce/complaint records are protected and accessible only to admins or trusted server processes.

You can unsubscribe from any non-essential email using the link in the message.

Shared responsibility

Account AB is built on Lovable Cloud's managed platform, which provides infrastructure, encryption in transit, managed authentication, and operational controls. Account AB is responsible for app-level access policies, content moderation, and feature configuration described above.

You are responsible for keeping your account credentials safe and for the content you choose to share publicly.

Reporting a security concern

If you believe you've found a security issue, please reach out through our support page with a clear description. We review every report and respond as quickly as we can.

Last updated August 2026. This page describes app-owned practices and may evolve as the product changes.