Encryption in transit
All data sent between the Lyrlio app and our servers is encrypted in transit over HTTPS/TLS.
Database security
Lyrlio is built on Supabase and Postgres. Application tables use Row Level Security (RLS) policies so a user's queries can only reach their own data; administrative tables (like our institutional plans) are locked down by default and only reachable from trusted server-side code.
Access controls
Only authenticated requests can read or write your account data. Operations that need elevated (service-role) access run exclusively on our servers — those credentials are never sent to or exposed in the browser.
Account deletion
You can request deletion of your account and associated content at any time by contacting us.
We don't sell your data
We do not sell your personal data or your content to third parties.
Our roadmap, honestly
Lyrlio is designed with privacy in mind, and we continue to invest in our security practices as the product grows. We do not currently hold formal certifications such as SOC 2, and we do not claim compliance with frameworks such as FERPA or COPPA. If your institution requires specific compliance documentation as part of a procurement process, contact us and we'll work with you directly.
Questions
Read our Privacy Policy for how we collect and use data, or contact us with any security question.