Security

Security at Lyrlio

How Lyrlio protects your data today, and what we're honest about not having yet.

Encryption in transit

All data sent between the Lyrlio app and our servers is encrypted in transit over HTTPS/TLS.

Database security

Lyrlio is built on Supabase and Postgres. Application tables use Row Level Security (RLS) policies so a user's queries can only reach their own data; administrative tables (like our institutional plans) are locked down by default and only reachable from trusted server-side code.

Access controls

Only authenticated requests can read or write your account data. Operations that need elevated (service-role) access run exclusively on our servers — those credentials are never sent to or exposed in the browser.

Account deletion

You can request deletion of your account and associated content at any time by contacting us.

We don't sell your data

We do not sell your personal data or your content to third parties.

Our roadmap, honestly

Lyrlio is designed with privacy in mind, and we continue to invest in our security practices as the product grows. We do not currently hold formal certifications such as SOC 2, and we do not claim compliance with frameworks such as FERPA or COPPA. If your institution requires specific compliance documentation as part of a procurement process, contact us and we'll work with you directly.

Questions

Read our Privacy Policy for how we collect and use data, or contact us with any security question.