Architecture & Protection

Security & Data Protection

Your subconscious thoughts deserve uncompromising technical defense. Learn how Subconscious Log protects your dream entries at every architectural layer.

Database Row Level Security (RLS)

We enforce multi-tenant isolation at the database engine level. Every SQL query for dreams, entities, or reflections is cryptographically bound to your authenticated Supabase user ID. Cross-account data leaks are prevented at the engine core.

Encryption in Transit & At Rest

All communications between your browser and our servers use standard HTTPS/TLS encryption. Database storage and automated backups are encrypted at rest by our managed database infrastructure (Supabase).

Isolated Payment Infrastructure

Subconscious Log never handles, touches, or stores your payment card credentials. All billing is managed through Stripe, certified under PCI-DSS Level 1 (the highest standard in payment security).

Model Training Boundaries

We do not train our own public foundation models on your journal entries or reflections. Data submitted for AI analysis is sent per-request to generate reflections according to the privacy and security terms of the Google Gemini API.

Vulnerability Reporting

Responsible Disclosure Channel

We welcome vulnerability reports from independent security researchers. If you discover a security issue or vulnerability in our application, please report it to our security desk at [OWNER INPUT REQUIRED: Security Email].

Please include steps to reproduce and allow reasonable time for remediation before any public disclosure. We do not pursue legal action against researchers acting in good faith.