Security is foundational to Whistle. This page summarizes how we protect your account, your business data, and the platform connections you authorize. Whistle is in private beta and our practices continue to mature — this is an overview, not a certification.
1. Our approach
We collect the minimum data we need, encrypt it in transit, limit who and what can access it, and act only on connected platforms with your explicit approval.
2. Infrastructure
Whistle runs on reputable managed providers: Clerk for authentication, Supabase for database and file storage, and Stripe for any payments. Each maintains its own security and compliance program.
3. Access & tokens
Access tokens for platforms you connect (Instagram, Facebook, Google, and others) are stored securely and used only for the features you enabled. When you disconnect an integration or delete your account, the associated tokens are revoked and removed — see Data Deletion.
4. Data protection
- Encryption in transit (TLS) for data moving between you, Whistle, and our providers.
- Access controls so only authorized systems and staff can reach your data.
- Platform data used only for the features you enable — never sold, and deleted on disconnect or request.
5. Human approval by design
Whistle does not publish content or spend money without your explicit approval. Sensitive actions always require your sign-off, which limits the impact of any single mistake or account issue.
6. Report a vulnerability
Found a security issue? Please email privacy@cinematechs.ca with the details and steps to reproduce. We investigate reports promptly and appreciate responsible disclosure.
This overview is provided in good faith and does not constitute a warranty or certification. No system is perfectly secure.