Security
How we protect your TypeUI account, workspace, and Insights analytics.
Effective date: September 1, 2026
This page summarizes the security practices used to protect TypeUI accounts, workspaces, and Insights data. It intentionally describes controls at a customer-facing level rather than disclosing internal security procedures.
Layered safeguards
- Encryption in transit for TypeUI web traffic.
- Authentication, workspace authorization, optional MFA, and access controls for private account and analytics data.
- Authenticated service communications and validation around sensitive operations.
- Request validation, origin controls, rate limits, usage limits, and abuse and bot protections around analytics collection.
- Private storage and restricted access for analytics, previews, and recovery data.
- Authenticated encryption and privileged server-only access for optional connected-service credentials.
- Established infrastructure, authentication, billing, email, and support providers with their own security programs.
Connected-service credentials
When a workspace connects Polar, Stripe, or Paddle revenue synchronization, TypeUI stores the scoped credential in Supabase Vault. Vault applies authenticated encryption at rest, including in database backups and replication streams, while Supabase manages the project encryption key separately from the stored database value. TypeUI's application tables keep only a secret reference, and access to the decrypted token is limited to privileged server operations that read purchases from the selected provider.
TypeUI does not return the token to the browser after connection or put it in analytics records. Replacing or disconnecting the integration, or deleting the related Insights website, deletes the active Vault secret. Customers should grant only orders:read for Polar, Checkout Sessions and Invoices read access for Stripe, ortransaction.read for Paddle. They should leave every write permission off, set a reasonable expiry, and revoke a credential immediately if compromise is suspected. Encryption reduces risk but cannot guarantee that a credential will never be accessed through a compromised account, application, provider, or privileged system.
Data minimization
Insights is designed not to store typed text, form values, page content, query strings, URL fragments, full referrer URLs, raw IP addresses, or complete user-agent strings in customer analytics. Interaction and device information is limited to what is needed for the reports described in the Insights Data Policy.
Access and sharing
Analytics starts private and requires authorized workspace access. Website owners can deliberately enable read-only sharing with the visibility options shown in the product. Shared views cannot change website settings and omit restricted analytics fields.
Service protection and analytics accuracy
TypeUI uses validation, limits, and automated abuse detection to protect the service. These controls cannot perfectly classify every request, so analytics—including bot, location, device, engagement, and live visitor counts—may be delayed, incomplete, or estimated. A live visitor is a pseudonymous session with activity during the previous 90 seconds, not proof that an identifiable person is currently viewing the website.
Retention and recovery
We use restricted recovery copies and documented deletion periods to reduce operational risk. Recovery is best-effort and may not include the latest activity. The Data Retention page explains the customer-visible retention and deletion timeline.
Security and provider risk
No online service or provider can guarantee absolute security, uninterrupted availability, or complete recovery. TypeUI is not an archival or disaster-recovery service. Keep independent copies of information you must preserve. The Terms of Service explains the applicable limitations, liability cap, and mandatory rights.
Current certification status
TypeUI does not currently represent that it holds SOC 2, ISO 27001, or another independent security certification. This page is not an audit report, warranty, or guarantee.
Report a security issue
Report suspected vulnerabilities privately through the Bergside contact page. Do not access, modify, or retain data that does not belong to you.