Skip to content

Trust Center

How we protect your work & your audience

Deliny Insights is a bio-link platform used by coaches and consultants to run their public presence, collect inquiries, and email subscribers. This page summarizes the controls we have in place today. It is app content maintained by DelinyInsights — not an independent certification.

Last updated: 10 July 2026

Encrypted in transit

All traffic to delinyinsights.com is served over HTTPS.

Row-level isolation

Database policies scope every read and write to the signed-in account.

No card data stored

Paddle handles payments as Merchant of Record. We never see full card numbers.

Authentication & access

Accounts sign in with email + password or Google. Passwords are hashed by our auth provider — we never see them in plaintext. Each account can only view and edit its own profile, links, subscribers, inquiries, broadcasts, and billing; Row-Level Security policies enforce these boundaries at the database layer, not just in the app UI.

Admin actions (moderation, SSL queue, team roles) are gated by a separate server-checked role. Session tokens live in the browser and can be revoked by signing out or changing your password.

What we store

We store the fields you create: profile details, links, product links, subscriber emails you collect, inquiries sent to you, broadcast drafts, and anonymized analytics events (link clicks, referrer, coarse device type).

Public profile pages expose only the fields you publish (handle, display name, bio, avatar, headline, links, booking URL). Your account email and internal integration IDs are never returned to visitors.

Hosting & storage

The application runs on Lovable's edge runtime. The database, auth, and file storage are managed Postgres on Lovable Cloud (Supabase). Avatars and uploaded files live in a private bucket and are served through scoped URLs.

We rely on the platform's backups and encryption-at-rest for the managed database and storage. We do not export or copy your data to any location outside the subprocessors listed below.

Email & subscribers

Transactional emails (welcome, inquiry notifications, password recovery) and broadcasts are sent through Resend from our verified sending domain.

Every subscriber email includes a one-click unsubscribe link backed by a unique token. Unsubscribed addresses are automatically excluded from future broadcasts. Coaches are responsible for how they collected the emails they upload or link to their subscribe form.

Payments

Subscriptions and one-off product sales are processed by Paddle as Merchant of Record. Paddle handles tax, invoicing, and card storage. We only receive the transaction status and metadata needed to grant your plan or unlock a purchase.

Every Paddle webhook is signature-verified before any subscription or entitlement change is applied.

Cookies & analytics

We use a session cookie set by our auth provider so you stay signed in, and minimal local storage for UI preferences. We do not run third-party advertising or cross-site tracking pixels.

Public profile visits are recorded as anonymized events (page/link, referrer host, coarse device type) so coaches can see what's working. We do not sell this data.

Retention & deletion

You can delete your account at any time from Dashboard → Account. Deletion removes your profile, links, subscribers, inquiries, broadcasts, product links, and uploaded files.

Payment and invoice records held by Paddle are retained per their own policy and applicable tax law. Aggregated, non-identifying platform metrics may be retained for reliability and abuse prevention.

Subprocessors

  • Lovable Cloud (Supabase) — database, authentication, file storage.
  • Resend — transactional and broadcast email delivery.
  • Paddle — payments, tax, and invoicing as Merchant of Record.
  • Google — only when you choose to sign in with Google.

Shared responsibility

Platform (Lovable / subprocessors)

Infrastructure security, encrypted storage, backups, patching of the underlying database and edge runtime.

DelinyInsights

Application code, access rules, webhook verification, subprocessor choices, and responding to security reports.

You (the coach)

Protecting your password, keeping your recovery email current, and only emailing subscribers who opted in.

Report a security concern

If you believe you've found a vulnerability or privacy issue, please email info@delinyinsights.com with reproduction steps. We aim to acknowledge reports within a few business days. Please avoid testing that would affect other users' data.

Related: Privacy Notice · Terms of Service · Refund Policy