How We Keep Your Data Secure
Last updated: September 2026 · All data hosted in the United States · AI services from Anthropic, OpenAI and Google
We can't see your data. Ever. Your submissions, uploaded documents, and Coach interaction history are protected by Row-Level Security rules at the data layer — not just by policy. Platform administrators have access to aggregate usage metrics (review counts, scores, activity levels) for operational support, but the content of your work is inaccessible to anyone outside your explicit sharing. Here's exactly how we enforce that.
Encryption in Transit & at Rest
All data transmitted between your browser and Halfhour's servers is encrypted using TLS 1.2+. Data stored in the database — including your submissions, feedback, and documents — is encrypted at rest using AES-256, the same standard used by financial institutions and government agencies.
Row-Level Security & Access Control
Every record in the database is protected by Row-Level Security (RLS) rules enforced at the data layer — not just the application layer. Submissions and uploaded documents are readable only by the submitter and the leader whose Coach was used. Platform admins (Sagely Advisory staff) can access aggregate usage metrics — review counts, scores, activity levels — for operational support, but have no access to the content of submissions, documents, or Coach interaction history.
Account-Level Isolation
All data is scoped to your user account at the application layer. Records are protected by Row-Level Security rules that restrict access to the account holder and explicitly shared team members. Your data cannot be accessed by other users on the platform.
File Storage
Files you upload — drafts, context documents, work samples — are stored in cloud storage, each at a long, unguessable address. The files are not password-protected: anyone who has a file's exact link can open it.
Backend Security
All AI processing and sensitive operations run in isolated backend functions — never in your browser. API keys (for our AI providers and Stripe) are stored as server-side environment secrets and are never included in any response payload or exposed to frontend code. Backend functions verify identity before performing any operation.
Authentication & Session Management
Every API call is bound to your authenticated session token, which is verified server-side on every request. Sessions are time-limited and invalidated on logout. We do not use persistent session cookies that survive browser restarts.
Have a specific security question?

