Your data, handled with care
A single source of truth for how StopAndDesist protects the sensitive information you share to build a legal letter.
TLS 1.2+ in transit. AES-256 at rest across Postgres, storage, and backups.
Every table storing user data uses Postgres RLS scoped to auth.uid(). You literally cannot read other users' rows.
Uploads are stored in a private bucket. Files are served only via short-lived signed URLs generated for the signed-in owner.
The browser only sees the publishable anon key. The service-role key never leaves the server.
We invoke our drafting provider on a per-request basis. Your intake and letter contents are not used to train third-party models.
Email us and we permanently delete your account, letters, intake data, and evidence within 30 days.
Subprocessors
Vendors we rely on to run the service. Each is bound by a data-processing agreement.
| Vendor | Purpose | Region |
|---|---|---|
| Supabase | Managed Postgres, auth, and file storage | US |
| Letter drafting provider | Professional letter drafting via API | US |
| Secondary drafting provider | Fallback drafting and support assistant | US |
| Paddle | Merchant of record for payments | Global |
| Cloudflare | CDN and edge runtime | Global |
Compliance posture
GDPR / CCPA rights: Access, portability, correction, and deletion honored on request.
Security contact: support@stopanddesist.com, please report vulnerabilities responsibly.
Not a law firm: Content is self-help. We do not create an attorney-client relationship.
