How SweetFlow AI protects your data

Encrypted in transit and at rest, isolated per business inside the database, and stored in the EU

Encrypted in transit and at rest
Stored in the EU (Frankfurt)
Database-level isolation (RLS)

Encryption in transit and at rest

Your data travels over TLS and is stored encrypted (AES-256) in the database and file storage. This is transport and storage encryption, not end-to-end: SweetFlow AI's servers read your business data in order to compute your orders and finances.

  • TLS on every connection
  • AES-256 encryption at rest
  • Not end-to-end: the service computes your finances

Data isolation in the database

Every business's rows are isolated by Postgres Row-Level Security policies enforced by the database itself, not by the app. Each query is filtered to your business before any row is returned, so another account cannot read your data even if the client is tampered with.

  • Postgres Row-Level Security on every business table
  • Enforced by the database, not the browser
  • Team roles applied by the same policies

Where your data lives

Your data is stored in AWS Frankfurt (eu-central-1), inside the European Union, and handled under the GDPR.

  • Region: eu-central-1 (Frankfurt, Germany)
  • Inside the EU
  • Handled under the GDPR

Sign-in and sessions

Authentication is Supabase Auth with OAuth 2.0 and managed sessions. You can turn on two-factor authentication (TOTP) in Settings. Cloudflare sits in front of the application and Cloudflare Turnstile guards the sign-in and sign-up forms.

  • Supabase Auth, OAuth 2.0, managed sessions
  • Optional two-factor authentication (TOTP)
  • Cloudflare Turnstile on the sign-in forms

Payments

Paddle is the Merchant of Record for SweetFlow AI subscriptions. Card details are entered on Paddle's checkout; SweetFlow AI never sees or stores them.

  • Paddle is the Merchant of Record
  • Card details never reach SweetFlow AI
  • Subscription billing handled by Paddle

Your control

Team access is role-based, per module, and enforced in the database's Row-Level Security policies. Deleting your account purges your business's data. Error reports redact share tokens and auth fragments from URLs before anything leaves the browser.

  • Role-based team permissions, per module
  • Account deletion purges your business's data
  • Error monitoring redacts tokens before sending

How it is built

SweetFlow AI runs on Supabase (Postgres in AWS Frankfurt) behind Cloudflare and is hosted on Vercel. Every business table carries Row-Level Security policies, sessions are managed by Supabase Auth, and payments are handled by Paddle. If you have a security question, write to us.