Legal
Security
Last updated 2026-08-24
01Hosting
The product runs on Cloudflare’s edge platform. Customer data for this deployment is stored in Cloudflare-managed stores. We do not pin a single named data-center region. The subprocessors page lists who processes data and for what.
02Authentication
Sign-in is a one-time email code or a passkey on devices and browsers that support one. A successful sign-in issues the signed session cookie described in the cookie notice. The browser does not hold a separate long-lived API token for the product.
03Staff and coach access
Coach or operator access to a customer workspace only exists when your service model includes it, and it is a distinct membership role scoped to that workspace — not a blanket staff override. Everyone with access appears on Settings → Access. Specialists see only the workspaces they have been granted; they do not get a cross-customer staff login.
04Credentials and integrations
Credentials for connected accounts and backend integrations stay on the server for this deployment. They are never shipped in browser code. Features that need an integration refuse to run if that integration is missing or unhealthy — they do not guess or silently continue.
05Spend limits and stopping sending
Sends, connection attempts, email lookups, and AI drafts are metered against monthly limits and rolling daily hard caps that block further use rather than let a runaway job overspend. Workspace owners and staff can both halt all sending for a workspace immediately.