Security

Where your data lives.

For the director who has to ask before signing anything. Specific, including about the gaps.

If you are evaluating this for a team and need to know where your people's data would live, this page is for you. It is deliberately specific, including about what does not exist yet.

Where the data lives

Everything you create is stored in a Supabase Postgres database hosted in the United States. The app and this website are static files served by Netlify. The diagnostic engine runs on Render. The engine receives only answer ids and returns a root cause and a coaching play. It never receives or stores a person's name.

In transit and at rest

All traffic is HTTPS with certificates managed by the hosts. Supabase encrypts data at rest and takes automated backups. Passwords are hashed by Supabase's authentication service and are never visible to me or stored by the application.

Who can see what

Access is enforced in the database with row level security, not in the browser, so it cannot be bypassed by anyone reading the page source. An account only reads its own organisation's records. The usage analytics table can be written to but not read back by the application at all.

Administrative access is held by one person. There is no outsourced support desk and no third party with a login to your data.

Data minimisation, and the one thing to decide

The product asks for very little: an email address, a team name, and whatever you choose to type in the agent field. That field accepts initials or a label rather than a full name, and using initials is the single biggest thing you can do to reduce what is held about your people. The tool works exactly the same either way.

The usage analytics contain no names, no email addresses and no free text. Only answer ids and a random per visit session id.

Retention and deletion

Your records are kept until you ask for them to be removed. Email me and I will export or delete an account and everything in it. I aim to complete that within 30 days and it is usually the same week.

What does not exist yet

Being straight with you is more useful than a page of reassurance.

No SOC 2 or ISO 27001. This is a small early product and a formal audit is not proportionate yet.
No single sign on. Email and password only, for now.
No uptime guarantee. The engine runs on a free tier and can take a minute to wake.
No standing data processing agreement. If you need one before real data goes in, ask and we will put one in place. That is a conversation, not a blocker.
No penetration test report. If your process requires one, tell me and we will work out what is reasonable.

If you find a problem

Email team@ccplaycaller.com with the details. I would much rather hear it from you than not know. I will acknowledge it quickly and tell you honestly what I am doing about it.

Last updated 8 August 2026. If anything here is unclear or looks wrong, email team@ccplaycaller.com and I will fix it.