Loyanly
EN
Log in
Security

How we protect your data and your customers'.

EU-hosted, GDPR-ready, with a small surface area we actually audit.

Infrastructure

The application runs on Google Cloud Run in an EU region. The database is managed PostgreSQL (Neon) in the EU. All traffic is TLS 1.2+; data at rest is encrypted with standard cloud-provider keys.

Access

A handful of team members have administrative access, with two-factor authentication required on every account. Production database access is audited and goes through short-lived credentials.

Data handling

You own your data. Export any time. Deletion requests are honoured within 30 days (soft delete + backup expiry). We do not use customer data to train anything, and we don't sell it — ever.

Third parties

We use Stripe for payments (PCI SAQ-A scope), Google for OAuth login, and PostHog (EU cloud) for feature flags. No ad networks, no session replay, no behavioural tracking.

Responsible disclosure

If you think you've found a security issue, please email us before disclosing publicly. We'll acknowledge within two business days, investigate, and patch as quickly as we can.

Report a vulnerability
security@loyanly.app

For details on what data we store and why, see ourPrivacy.