Security

How we protect Everly and your events

Infrastructure

Data is stored in Google Firebase (Firestore) with owner/member access rules. Public invitation data is served via server-side Admin SDK only — clients cannot read other events or invite tokens.

Authentication

Email/password and Google OAuth via Firebase Auth. API routes verify ID tokens on every protected request.

Responsible disclosure

If you discover a security issue, please report it responsibly to support@everlymagic.com with the subject line "Security report". Include steps to reproduce and impact. We aim to respond within 72 hours.

Privacy Policy