Security

Your career data, locked down.

This page describes the controls Upplio operates today. It's app-owner content, not an independent audit. If you need our SOC 2 report or a DPA, email customerservice@upplioai.com.

AES-256-GCM at the app layer

Resumes, cover letters, STAR stories, interview transcripts, support messages, and feedback are encrypted before they hit the database, on top of managed disk-level encryption.

Row-Level Security

Every data table is protected by row-level policies — users can only access their own rows, and admin reads of user data are audit-logged.

Auth & sessions

Email + Google sign-in via Supabase Auth. Sessions are short-lived JWTs with refresh rotation.

Automated retention

Inactive free accounts are deleted after 12 months; sign-in logs are stripped after 30 days; support and feedback data after 24 months. Full schedule on the Privacy page.

No resale, no model training

We never sell your data, and our AI providers are contractually prohibited from training foundation models on your content.

Incident response

Material security incidents are disclosed to affected users within 72 hours of confirmation.

Vulnerability reporting

Found a security issue? Email customerservice@upplioai.com with the steps to reproduce. We acknowledge within 2 business days and credit researchers in our hall of fame on request.

Delete your data anytime

From Settings → Account → Delete account, your data is permanently removed within 30 days.