Security
Security & Data Handling
Poprica treats your images, brand assets, and payment data with the highest priority. Here is how we protect them, technically and operationally.
Business use of generated files
You may use generated files for your business and commissioned promotional work, subject to the Terms. Review all copy and rights before publishing, printing, or delivering them.
Data protection in transit and at rest
All traffic is encrypted with TLS. Uploaded images and generated files are stored in access-controlled cloud storage.
- All pages and APIs served over HTTPS (TLS)
- Database access protected with role-based controls, including row-level access control (RLS)
- Uploads are managed under your account
Payment information
Card details never touch our servers — they are processed directly by Stripe, a PCI DSS-compliant payment provider. We never hold or store your card number.
Infrastructure
The application runs on Vercel; the database, authentication, and storage run on Supabase — both managed cloud platforms with industry-standard security.
Accounts and authentication
Authentication uses email or Google (OAuth), and passwords are stored hashed. We never see your password in plain text.
Data retention by plan
Generated files are retained in storage for the following periods. After expiry, you can regenerate for 1 coin if needed.
Contact
For questions about security or data handling, contact us at support@poprica.app.