StopAndDesist
Trust Center

Your data, handled with care

A single source of truth for how StopAndDesist protects the sensitive information you share to build a legal letter.

Encryption

TLS 1.2+ in transit. AES-256 at rest across Postgres, storage, and backups.

Row-level security

Every table storing user data uses Postgres RLS scoped to auth.uid(). You literally cannot read other users' rows.

Private evidence bucket

Uploads are stored in a private bucket. Files are served only via short-lived signed URLs generated for the signed-in owner.

Least-privileged keys

The browser only sees the publishable anon key. The service-role key never leaves the server.

No model training on your data

We invoke our drafting provider on a per-request basis. Your intake and letter contents are not used to train third-party models.

Deletion on request

Email us and we permanently delete your account, letters, intake data, and evidence within 30 days.

Subprocessors

Vendors we rely on to run the service. Each is bound by a data-processing agreement.

VendorPurposeRegion
SupabaseManaged Postgres, auth, and file storageUS
Letter drafting providerProfessional letter drafting via APIUS
Secondary drafting providerFallback drafting and support assistantUS
PaddleMerchant of record for paymentsGlobal
CloudflareCDN and edge runtimeGlobal

Compliance posture

GDPR / CCPA rights: Access, portability, correction, and deletion honored on request.

Security contact: support@stopanddesist.com, please report vulnerabilities responsibly.

Not a law firm: Content is self-help. We do not create an attorney-client relationship.

Trust and privacy FAQ