1. Security approach
Opendot is designed to request only the access needed for Gmail tracking and notifications, and communicates with backend services over HTTPS.
2. Data we avoid storing
- Email bodies
- Email attachments
- Readable passwords
- Full payment-card numbers
3. Current safeguards
- Supabase authentication and token-based API access
- Database access controls, including Row Level Security where configured
- HTTPS encryption in transit
- Chrome Manifest V3 architecture
- Limited extension permissions
- Stripe-hosted card processing when billing is enabled
4. Security reports
Email support@opendot.app with a description, reproduction steps, affected version, and contact details. Do not access other users' data, disrupt the service, or disclose publicly before we have a reasonable opportunity to investigate.
5. Response
We aim to acknowledge credible security reports within two business days.