Last updated: October 2026
Security
You trust us with your voice — the most personal data there is. Here is, honestly, what we do to protect it and where our limits are.
What we do
- Encryption in transit: all traffic to kodalang.com uses HTTPS (TLS). Your audio and account data are never sent in the clear.
- Encryption at rest: your data is stored in a managed PostgreSQL database (Supabase) with disk-level encryption.
- Passwords: handled by Supabase Auth and stored only as salted hashes — our team cannot see or recover your password.
- Payments: processed by Stripe, which is PCI-DSS compliant. Card numbers never touch our servers.
- AI processing: prompts sent to our AI providers are stripped of directly identifying information first, and our speech-to-text provider is instructed not to retain audio after transcription.
- No sale of data: we do not sell personal data to anyone, for any purpose.
What we ask of you
- Use a unique password for KodaLang.
- Never share your login, and sign out on shared devices.
Responsible disclosure
Found a vulnerability? Email us with the details and give us a reasonable time to fix it before any public disclosure. We will acknowledge every good-faith report and keep you updated on the fix.
Honest limits
No system is unhackable, and we will not pretend otherwise. What we promise is this: industry-standard protections, prompt patching, transparent communication if something ever goes wrong, and a standing rule that your data is never the product.
Questions about this page? Write to us at contact@kodalang.com — a human reads every message.