How we handle your data, plain English. No certifications we don't have.
Railway (US-East). Containerized FastAPI service.
Supabase Postgres (US-East). TLS in transit, encryption at rest via Supabase defaults.
Plain language so you don't have to read between the lines.
If you find a vulnerability, email security@coldconvert.net. We respond within 48 hours. We do not run a paid bug bounty yet — but we will credit researchers who report responsibly.
Related: /trust · /privacy · /terms · /disclaimer-agreement