Security

How we protect your data. Last updated: 3 August 2026.

All in reads your business data to compute analytics — so protecting it is the product, not an afterthought. Here is exactly how.

Read-only access
We ask only for read/analytics scopes at each provider. We never request write access to your store, ads, or email.
Encrypted at rest
Connector credentials are encrypted with AES-256-GCM before they touch the database, and decrypted only in memory during a sync.
Per-tenant isolation
Postgres row-level security: every query is scoped to your account. One customer can never read another's rows.
Least-privilege DB role
The app connects as a restricted, non-superuser role that cannot bypass row-level security.
Signed sessions
Read access requires an HMAC-signed session token bound to a single tenant. Everything is served over HTTPS.
Revoke anytime
You can disconnect any connector or delete your account and all data at any time.

Minimum scopes we request

Sub-processors

We use a small set of vetted providers to run the Service. They process data on our behalf under their own security terms.

ProviderPurposeLocation
Supabase (Postgres)Encrypted application databaseAWS ap-northeast-1
NetlifyStatic site & edge deliveryGlobal CDN
VultrApplication server (backend)EU (Frankfurt)
AI model providerGenerates copilot answers from your metricsContracted, no training on your data
StripeSubscription billing (card data never touches our servers)Global

Data processing & deletion

We keep your data only while your account is active and delete it within 30 days of a deletion request. We do not sell your data or use it to train third-party AI models. A Data Processing Addendum (DPA) is available on request for business customers.

Report a vulnerability

Found something? Email weare@linkrra.com and we'll respond quickly. Please give us a reasonable window to fix before public disclosure.

← Back to Linkrra All in