Trust
Connecting your revenue means trusting us with the data your livelihood runs on. So here it is in plain sight: exactly what we read, what we never touch, where it lives, who can reach it, and how to remove it anytime.
Where your data goes, start to finish
- Your toolsWhere you already get paid, starting with Stripe
- An encrypted linkOver TLS, your Stripe token sealed with AES-256-GCM
- Your private workspaceWalled off to you, reachable by no other account
- Your proven resultsEvery dollar Measured, back to the work that earned it
It reads where your money already moves, and can create a checkout link to trace a sale. It never gets the keys to move your money.
What we read, and why
- Your Stripe paymentsso we can prove which work earned you money, to the dollar
- Your customers and subscriptionsso we can spot a renewal slipping before it lapses
- Your productsso a recovered sale is tied to the exact offer that made it
What we never do
- Move your money, issue refunds, or charge your customers
- Send, post, or spend anything without your explicit yes
- See your Stripe password or login (you approve through Stripe itself, or paste a limited key you make)
- Sell your data, use it for third-party ads, or train third-party AI on it
Where does it live?
In your own workspace on our managed database (Supabase, US region). Never on your device, never in a shared pile.
Who can see it?
You. Row-level security is on, the browser has no direct database access, and every read runs scoped to your account. No other account can reach your data.
How is it protected?
Encrypted in transit over TLS, and your connection keys are encrypted at rest with AES-256-GCM before they are stored. The plaintext key never lands in our database.
How do you remove it?
You hold the kill switch. Revoke our access in your Stripe dashboard, by removing the app or deleting the key you made, and it ends immediately, with no action needed from us. To export or delete your account, ask us at privacy@cerqular.ai and we act within the timeframes the law requires.
Your data, your control
Security posture, in plain words
We are an early-stage company and do not yet hold formal third-party security certifications. We would rather tell you that plainly than imply otherwise. The protections shown above are real, running today, and you can verify most of them from inside the product. We describe the exact mechanism (encryption in transit over TLS, AES-256-GCM on stored connection keys, account isolation with row-level security on) and never dress it up in superlatives.
The honesty system
Every revenue figure Cerqular shows carries one of three labels. Measured: a real transaction, attributed to the action that earned it. Estimated: derived from real data, not yet confirmed by a transaction. Modeled: a projection, and never shown as fact. Receipts, not claims. If a number ever falls short of that standard, that is a bug, and we treat it as one.
Uptime posture
Cerqular runs on managed infrastructure (Vercel, Render, and Supabase) with continuous error monitoring. We do not publish an uptime percentage we have not earned yet; what we promise is honest, prompt communication when an incident affects you, and a fix as fast as we can ship one.
Responsible disclosure
Found a vulnerability? Tell us at security@cerqular.ai. We acknowledge reports quickly, keep you informed while we fix, and do not pursue good-faith security research. Please give us a reasonable window to fix before public disclosure.
The paperwork
The detail lives in the Privacy Policy, the Terms of Service, and the Data Processing summary.