Security & data practices
This page describes how NoetaMind is operated today. We describe only what we actually do β we hold no third-party security certifications and don't claim any.
Encrypted in transit
noetamind.com and every API call are served over HTTPS/TLS. Accounts are authenticated with signed session tokens; we never store your password in our application database.
Per-user data isolation
Study data β conversations, topics, quizzes, progress β is stored with row-level security rules so a signed-in account can only read and write its own rows. Organisation data is scoped to members of that organisation.
Payments
Card payments are processed by Stripe and PayPal, both PCI-DSS Level 1 service providers. Card numbers never reach NoetaMind's servers; we store only a subscription reference and status.
Access and retention
Access to production data is limited to the people who operate the service and is used only to run and support the product. You can request an export or deletion of your account data at any time by emailing support.
Reporting a vulnerability
Found a security issue? Email support@noetamind.com with 'Security' in the subject and steps to reproduce. We aim to acknowledge reports within two business days and will keep you posted while we fix it. Please don't publicly disclose before we've had a chance to respond.
See also our privacy policy and terms of service.