BrekkyMetrics security

What we store, how it moves, and how to report a problem. This page matches the privacy policy. It does not claim SOC 2, pentests, or a bug bounty.

What we store

Visitor events you send (page URL or screen name, referrer, timestamp, first-party visitor and session identifiers, user agent, and country from IP). Optional identify traits you choose to send. Account email, project names, and write keys.

We do not store payment card numbers. Stripe handles cards for paid plans. Do not send passwords, card numbers, or government IDs in events.

How it is protected

Traffic to the marketing site, app, docs, tracker, and ingest uses HTTPS (encryption in transit). The product is hosted SaaS. Database, auth, and realtime run on Supabase, as described in the privacy policy.

What we do not do

  • We do not sell visitor data.
  • We do not run an ad network or drop ad pixels from BrekkyMetrics.
  • We do not show IPs in the dashboard. Country comes from IP on ingest.

Report a vulnerability

Email hello@brekkymetrics.com with enough detail to reproduce. There is no public bug bounty program on this site.

Related