Trust & Security
How we protect your messages.
Last updated: 1 July 2026
This page is maintained by Yurify Pte. Ltd. to answer common questions about how the Yurify application handles your data. It is not an independent certification.
What Yurify sees
Yurify analyses the message text you paste, plus the context you optionally add (relationship, sender name, notes). We do not scrape your inbox, calendar, or workplace tools. Nothing leaves the browser until you click Run analysis.
Screenshot uploads are OCR'd server-side and the extracted text is treated the same as pasted text.
Access & authentication
- Email + password and Google sign-in. No anonymous accounts.
- Sessions are managed by our backend provider (Lovable Cloud, built on Supabase). Access tokens are stored in browser storage and rotated on refresh.
- All application data is protected by row-level security policies: your saved analyses and stakeholder memory are only readable by you.
- Team-level roles (admin/member) are enforced server-side, not by the client.
Data at rest & in transit
- All traffic between your browser and Yurify is served over HTTPS/TLS.
- Application data is hosted on Lovable Cloud infrastructure. Encryption at rest is provided by the underlying database platform.
- We do not sell, share, or use your messages to train third-party models.
Subprocessors
Yurify uses a small set of subprocessors to operate the service:
- Lovable Cloud for application hosting, database, authentication, and storage.
- Google (Gemini via Lovable AI Gateway) for AI inference on message analysis. Inputs are transmitted for the duration of the request only.
A full subprocessor list and Data Processing Addendum (DPA) are available on request. Please email info@yurify.co.
Retention & deletion
- Saved analyses and stakeholder memory persist until you delete them or delete your account.
- Account deletion requests are honoured within 30 days. Email info@yurify.co.
- Server logs (used for reliability and abuse prevention) are retained for up to 30 days.
Regional compliance
Yurify is designed to support customer obligations under the EU General Data Protection Regulation (GDPR / DSGVO) and India's Digital Personal Data Protection Act (DPDP). For enterprise pilots in Germany or India, we can review specific data-residency and controller-processor commitments on request.
Incident response
If we identify or are notified of a security incident that affects your data, we will notify affected account owners without undue delay, describe what we know, and share the steps we're taking to contain and remediate. Contact info@yurify.co.
Vulnerability disclosure policy
For security researchers.
Reporting a vulnerability
If you believe you've found a security vulnerability in Yurify Communication Intelligence, please email info@yurify.co. Include a clear description, steps to reproduce, the affected URL or endpoint, and any proof-of-concept material.
Our machine-readable contact is at /.well-known/security.txt (RFC 9116).
Response targets
- Acknowledgement: within 3 business days.
- Triage and severity assessment: within 10 business days.
- Status updates: at least every 14 days until resolution.
- Public credit (with your permission) after a fix ships.
Scope
In scope:
- The Yurify application at this domain and its API endpoints.
- Authentication, session, and authorisation flows.
- Server-side data handling and stored content.
Out of scope:
- Findings from automated scanners without a working proof-of-concept.
- Denial-of-service, volumetric, or stress-testing attacks.
- Social engineering, phishing, or physical attacks against staff.
- Third-party infrastructure we do not operate (e.g. Lovable Cloud, Google).
- Email SPF/DMARC/DKIM configuration of marketing domains.
- Self-XSS, missing best-practice headers without demonstrable impact.
Safe harbour
We will not pursue legal action against researchers who, in good faith:
- Comply with this policy and applicable law.
- Avoid privacy violations, destruction of data, and service disruption.
- Only interact with accounts they own or have explicit permission to test.
- Give us a reasonable window to remediate before public disclosure.
This policy does not authorise actions that violate Singapore's Computer Misuse Act or equivalent laws in your jurisdiction.
Bounty
We do not currently operate a paid bug-bounty programme. We are happy to provide public credit and a written acknowledgement for valid reports.
Contact
info@yurify.co. Yurify Pte. Ltd., 168 Robinson Road, #20-01, Capital Tower, Singapore 068912.
See also our privacy policy and terms of service.
