Security & Trust
Last updated: June 14, 2026
Infrastructure
- Firebase Authentication with secure session cookies (httpOnly).
- Firestore and Storage secured with server-side rules and admin SDK for privileged operations.
- HTTPS everywhere via Vercel.
- Stripe handles payment card data; we never store full card numbers.
Moderation & abuse prevention
hCaptcha on sign-up, contact, and guest uploads. Automated NSFW screening on photo uploads. Rate limits on public APIs.
Report a vulnerability
Responsible disclosure: support@everlymagic.com with subject "Security".