Legal

Security

How WyreIt protects your data and how to report a security concern.

Last updated: 25 July 2026Jurisdiction: England & Wales
App-owner contentThis page is maintained by WYREIT APP LTD and describes the app's current security practices. It is not independent legal advice, and it is not a certification by Lovable or any third party.

1. Data protection

  • All data is encrypted in transit (TLS) and at rest.
  • Your connected-platform OAuth tokens are additionally encrypted at rest with AES-256-GCM and held server-side only — never exposed to your browser, never placed in a URL, and never returned to the client.
  • We never see your account passwords — authentication is handled by our identity provider — and we do not read or store the content of your private messages.

2. Authentication & access

  • Requests for your data are authenticated with a per-user identity token issued when you sign in.
  • Access to your data is enforced by database row-level security and by authorisation checks in our backend.
  • Our servers set strict HTTP security headers, including HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and related protections.

3. Hosting & compliance

  • Your data is stored in the European Union (Supabase, Frankfurt). Our sub-processors are listed in our Privacy Policy, and we never sell your personal data.
  • WYREIT APP LTD is registered with the UK Information Commissioner's Office as a data controller (ICO registration ZC195947) and operates under UK GDPR and the Data Protection Act 2018.

Your rights over your personal data, and how to exercise them, are set out in our Privacy Policy.

4. Reporting a vulnerability

If you believe you have found a security vulnerability in WyreIt, we want to hear from you. Please email [email protected] with enough detail for us to reproduce the issue.

We welcome responsible disclosure. We will not pursue legal action against researchers who report in good faith and who avoid privacy violations, data destruction, and disruption to our service.

We aim to acknowledge reports within 5 working days.