Security

Security & Data Handling

Poprica treats your images, brand assets, and payment data with the highest priority. Here is how we protect them, technically and operationally.

Business use of generated files

You may use generated files for your business and commissioned promotional work, subject to the Terms. Review all copy and rights before publishing, printing, or delivering them.

Data protection in transit and at rest

All traffic is encrypted with TLS. Uploaded images and generated files are stored in access-controlled cloud storage.

  • All pages and APIs served over HTTPS (TLS)
  • Database access protected with role-based controls, including row-level access control (RLS)
  • Uploads are managed under your account

Payment information

Card details never touch our servers — they are processed directly by Stripe, a PCI DSS-compliant payment provider. We never hold or store your card number.

Infrastructure

The application runs on Vercel; the database, authentication, and storage run on Supabase — both managed cloud platforms with industry-standard security.

Accounts and authentication

Authentication uses email or Google (OAuth), and passwords are stored hashed. We never see your password in plain text.

Data retention by plan

Generated files are retained in storage for the following periods. After expiry, you can regenerate for 1 coin if needed.

Free7 days
Light30 days
Standard90 days
Business180 days

Contact

For questions about security or data handling, contact us at support@poprica.app.