Security
How we protect your TypeUI account, workspace, and Insights analytics.
Effective date: August 20, 2026
This page summarizes the security practices used to protect TypeUI accounts, workspaces, and Insights data. It intentionally describes controls at a customer-facing level rather than disclosing internal security procedures.
Layered safeguards
- Encryption in transit for TypeUI web traffic.
- Authentication, workspace authorization, optional MFA, and access controls for private account and analytics data.
- Authenticated service communications and validation around sensitive operations.
- Request validation, origin controls, rate limits, usage limits, and abuse and bot protections around analytics collection.
- Private storage and restricted access for analytics, previews, and recovery data.
- Established infrastructure, authentication, billing, email, and support providers with their own security programs.
Data minimization
Insights is designed not to store typed text, form values, page content, query strings, URL fragments, full referrer URLs, raw IP addresses, or complete user-agent strings in customer analytics. Interaction and device information is limited to what is needed for the reports described in the Insights Data Policy.
Access and sharing
Analytics starts private and requires authorized workspace access. Website owners can deliberately enable read-only sharing with the visibility options shown in the product. Shared views cannot change website settings and omit restricted analytics fields.
Service protection and analytics accuracy
TypeUI uses validation, limits, and automated abuse detection to protect the service. These controls cannot perfectly classify every request, so analytics—including bot, location, device, engagement, and live visitor counts—may be delayed, incomplete, or estimated. A live visitor is a pseudonymous session with activity during the previous 90 seconds, not proof that an identifiable person is currently viewing the website.
Retention and recovery
We use restricted recovery copies and documented deletion periods to reduce operational risk. Recovery is best-effort and may not include the latest activity. The Data Retention page explains the customer-visible retention and deletion timeline.
Security and provider risk
No online service or provider can guarantee absolute security, uninterrupted availability, or complete recovery. TypeUI is not an archival or disaster-recovery service. Keep independent copies of information you must preserve. The Terms of Service explains the applicable limitations, liability cap, and mandatory rights.
Current certification status
TypeUI does not currently represent that it holds SOC 2, ISO 27001, or another independent security certification. This page is not an audit report, warranty, or guarantee.
Report a security issue
Report suspected vulnerabilities privately through the Bergside contact page. Do not access, modify, or retain data that does not belong to you.