Trust & safety

Security

Last updated: 11 August 2026

This page is maintained by the UniDoodle team to describe the security controls in place today. It is not an independent certification.

Infrastructure

UniDoodle runs on Lovable Cloud with data stored in a managed Postgres database. Traffic is encrypted in transit with TLS. Backups and point-in-time recovery are managed by the platform.

Access controls

  • Row-level security policies on every user-owned table.
  • Role separation between students, teachers and organisations.
  • Server-side authentication with per-request middleware for privileged operations.
  • Least-privilege service credentials for background jobs.

Payments

All card payments are handled by Stripe (PCI-DSS Level 1). Webhook signatures are verified before any subscription state change.

Reporting a vulnerability

If you believe you have found a security issue, please email security@unidoodle.com. Please give us a reasonable time to remediate before public disclosure. We aim to acknowledge reports within five working days, keep you updated while we investigate, and will not pursue action against researchers who report in good faith and avoid accessing other people’s data.

Questions about this policy? Email privacy@unidoodle.com. UniDoodle is a product of Visuality Limited, registered in Ireland (company no. 751062).