Security & Privacy

Designed for GDPR and CCPA compliance. Raw submitted content is deleted from Supabase after analysis. It is not sold, not used for AI training, and only processed by contracted subprocessors (Anthropic, Vercel, Supabase) under data processing agreements.

✓ GDPR & CCPA Compliant  |  ✓ Content Deleted After Analysis  |  ✓ No AI Training Use  |  ✓ Secure Payments via Lemon Squeezy

🕵️

Pseudonymized Processing

Submitted content is processed without persistent linkage to your personal identity. Raw content is deleted from the primary Supabase database upon completion of the analysis pipeline.

🗂️

Transient Content Handling

Raw submitted content is deleted from our Supabase database after analysis. It may exist transiently in Vercel serverless function memory or infrastructure logs for technically necessary durations, subject to automated expiration.

🚫

No Sale or Unauthorized Sharing

Your content is not sold to third parties. It is not shared with external parties except as necessary for processing by contracted subprocessors (Anthropic, Supabase, Vercel) under data processing agreements.

🤖

No AI Training Use

Submitted content is not used to train, fine-tune, or evaluate any AI model by us. We contractually require the same commitment from our AI processing subprocessor, Anthropic, per their API usage policy and DPA.

🔐

Encryption in Transit & at Rest

All data transmission is protected with TLS 1.3 encryption. All data stored in Supabase is encrypted at rest using AES-256. Row-Level Security (RLS) ensures users can only access their own data at the database layer.

🏗️

Privacy by Design

Data minimization, transient content handling, RLS enforcement, and access controls are built into the architecture of the Service from the ground up, in accordance with GDPR Art. 25.

Privacy Preferences

Customize how Edithority handles your data

Analytics & Performance

Allow anonymous usage analytics to improve the platform (optional, currently disabled)

Content Caching

Temporarily cache content during active analysis session

Analysis History

Store analysis results (scores only, not content) in your account

Compliance Standards

GDPR Compliant
CCPA Compliant
Data Protection by Design (GDPR Art. 25)
PCI-DSS via Lemon Squeezy

Infrastructure & Payments

Operator

Edithority by Harbinger Bros. LLC
Privacy-First Content Analysis

Hosting

Vercel (Global Edge Network)
Serverless, DDoS-protected, HTTPS enforced

Database & Auth

Supabase — EU Central (Frankfurt)
AES-256 at rest · RLS enforced

Merchant of Record

Lemon Squeezy
All payments secure — no card data stored by us

AI Processing

Anthropic (Claude API)
No training use — stateless inference only

Responsible Disclosure

If you discover a potential security vulnerability in Edithority, please report it responsibly to security@edithority.com. We will acknowledge your report within 48 hours and work with you to remediate the issue before public disclosure.

We credit researchers in our security acknowledgments if desired.