Trust & Security
Last reviewed June 18, 2026
This page is maintained by Project Soul to answer common security and privacy questions about our build, hosting, and maintenance services. It describes practices and platform capabilities that are currently in use β it is not an independent certification or third-party audit, and nothing here should be read as a regulatory compliance attestation.
Access & authentication
Customer accounts sign in with email + password or Google OAuth through our managed authentication provider. Sessions are bound to the signed-in user and gate every page under /dashboard and the project intake flow.
Internal admin tools are protected by a separate password and a signed, time-limited session cookie that expires automatically. Admin access is limited to Project Soul staff.
Server-side data access is enforced by row-level security policies on our database plus ownership checks in application code, so a signed-in customer can only read or modify their own orders, messages, and uploads.
Platform & hosting context
Project Soul runs on Lovable's hosting platform. TLS is enabled for all customer-facing traffic by default. Application servers run in a managed serverless runtime with no long-lived shell access for customers.
Lovable provides platform-level capabilities such as encrypted secret storage, managed authentication, and a managed database. These are platform features we rely on; they are not a Lovable-issued certification of this app.
Data we collect
The dashboard collects only what we need to deliver your site:
- Account: email address, and (for Google sign-in) your Google profile name.
- Project intake: company name, contact name, project description, page count, style preferences, optional uploaded reference files.
- For active promotions that include a physical gift, a shipping address you provide at checkout.
- Order messages and attachments you send to us through the dashboard chat.
- Affiliate metadata (referral code, click and conversion counts) if you opt into the affiliate program.
We do not store payment card numbers. Payments are processed by our payment partner (see Subprocessors).
Subprocessors & integrations
We use the following third parties to operate the service:
- Lovable β application hosting, managed database, authentication, secret storage.
- Whop β payment processing for build fees and monthly hosting, and affiliate payouts.
- Google β optional OAuth sign-in for customer accounts.
Each provider processes only the data needed for their function. We do not sell customer data.
Retention & deletion
Account, project intake, and order message records are retained for as long as your account is active so we can continue building, hosting, and supporting your website. If you ask us to close your account, contact us using the email below and we will remove your personal information from active systems, subject to limited records we are required to keep for tax, accounting, or fraud-prevention reasons.
Privacy requests
To request a copy of your data, correct it, or ask us to delete it, email the address in the Security contact section below from the email on your account. We will respond within a reasonable timeframe.
Security & privacy contact
Found a security issue, or have a privacy question? Email us and we will get back to you. Please don't publicly disclose a suspected vulnerability before we have had a chance to investigate.
Contact: support@projectsoul.dev
See also our Terms, Privacy, and Cookie Policy.
