Trust & Safety
Last updated: March 15, 2026
Your trust is the foundation of Bronsik. This page explains the specific technical and organizational measures we use to protect your account, your conversations, and your data — honestly and without overpromising.
Encrypted in Transit
TLS 1.2+ on all connections
Encrypted at Rest
AES-256 on all stored data
Zero Data Selling
Your data is never sold
Bronsik's backend runs on Supabase — enterprise-grade cloud infrastructure that meets SOC 2 Type II and ISO 27001 compliance standards.
Your conversations are private by design. Here is exactly how they are handled:
All payment processing is handled by LemonSqueezy, a PCI DSS compliant payment processor. We never receive, transmit, or store your raw payment card number or banking details. LemonSqueezy tokenizes all payment information before it reaches our systems.
Our servers only receive a customer ID and subscription status — never raw financial data. Payment-related webhooks from LemonSqueezy are verified using cryptographic signature validation before processing.
We take platform safety seriously and have implemented multiple layers of abuse prevention:
We maintain basic monitoring to detect and respond to unusual patterns that may indicate security threats or abuse:
If we detect suspicious activity on your account, we may contact you at the email address on file to verify your identity before taking any action.
We carefully evaluate the security practices of every provider we integrate with. Our key providers:
We only share data with third parties to the minimum extent necessary to provide the Service. We do not sell user data to any third party.
We take security vulnerabilities seriously and appreciate responsible disclosure from the security community. If you discover a security issue with Bronsik, please report it privately before any public disclosure.
We do not take legal action against researchers who disclose vulnerabilities in good faith and follow responsible disclosure principles. We cannot offer bug bounties at this time, but we will publicly acknowledge contributions where the researcher consents.
In the event of a security incident affecting user data:
No system is perfectly secure. We have built Bronsik with security as a foundational concern — not an afterthought — but we are a small team and we will not make promises we cannot keep.
What we can honestly say: we follow industry-standard practices for encryption, authentication, access control, and abuse prevention. We use established, well-audited infrastructure providers. We monitor for anomalies and respond to incidents promptly.
What we will not claim: that we are impenetrable, that no breach is ever possible, or that our security is equivalent to that of large enterprises with dedicated security teams. We are honest about who we are and what we can do — and we are committed to continuous improvement.
If you ever have concerns about the security of your account or data, please contact us. We will always take your concerns seriously.
For security-related concerns or vulnerability reports, contact us directly: