Trust & safety
Security
Last updated: 11 August 2026
This page is maintained by the UniDoodle team to describe the security controls in place today. It is not an independent certification.
Infrastructure
UniDoodle runs on Lovable Cloud with data stored in a managed Postgres database. Traffic is encrypted in transit with TLS. Backups and point-in-time recovery are managed by the platform.
Access controls
- Row-level security policies on every user-owned table.
- Role separation between students, teachers and organisations.
- Server-side authentication with per-request middleware for privileged operations.
- Least-privilege service credentials for background jobs.
Payments
All card payments are handled by Stripe (PCI-DSS Level 1). Webhook signatures are verified before any subscription state change.
Reporting a vulnerability
If you believe you have found a security issue, please email security@unidoodle.com. Please give us a reasonable time to remediate before public disclosure. We aim to acknowledge reports within five working days, keep you updated while we investigate, and will not pursue action against researchers who report in good faith and avoid accessing other people’s data.
Questions about this policy? Email privacy@unidoodle.com. UniDoodle is a product of Visuality Limited, registered in Ireland (company no. 751062).

