Trust, Security & Privacy
This page is maintained by Universal Law Community Trust to explain the controls currently enabled in our community platform. It is editable owner content and is not an independent certification.
Access & Authentication
- Email/password sign-in with leaked-password screening enabled.
- Optional Google sign-in for members who prefer it.
- Row-level security on member tables — each account only sees its own data.
- Administrative actions are restricted by server-verified roles, never by client checks.
Platform & Hosting
The platform runs on Lovable Cloud (managed Supabase + edge runtime). Data is stored in Postgres with encryption at rest, and traffic between your browser and our backend is served over TLS. Lovable provides the underlying infrastructure; the Universal Law Community Trust is responsible for the application logic, content, and access policies built on top of it.
Data We Collect
- Account profile: name, email, phone, member identifiers you supply.
- Assignment of Consent (AOC) submissions and supporting documents you upload.
- Community posts, messages, and ledger entries you create.
- Operational logs used to keep the service running and to investigate abuse.
We do not sell personal data.
Subprocessors & Integrations
- Lovable Cloud — hosting, database, file storage, edge compute.
- Razorpay — payment processing for contributions and top-ups.
- ProtonMail — outbound transactional and AOC archive email.
New subprocessors are added only when needed to operate a feature the membership has asked for.
Retention & Deletion
Member records are retained while the account is active. AOC documents and ledger entries are retained as part of the Trust's records. Members can request correction or deletion of personal data at any time using the contact email below; we will action requests within a reasonable period unless we are required to retain the record.
Privacy Requests & Security Contact
For privacy requests, security reports, or questions about this page, email aoc@universallawcommunitytrust.org. Please describe the issue and we will respond. Responsible disclosure of suspected vulnerabilities is welcomed — please do not include exploitation payloads against live member data.
This page describes controls currently enabled. It is not a certification, audit attestation, or legal guarantee. Members remain responsible for safeguarding their own credentials and for the accuracy of information they submit. See also our contact page.
