Security
How we protect your data.
Plain language — no buzzwords.
Authentication
User accounts are managed by Supabase Auth — an open-source, battle-tested authentication layer. Sessions use short-lived JWT tokens. Passwords are hashed using bcrypt and never stored in plain text. We also support Google OAuth as an alternative to passwords.
Payments
All payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor. We never see, store, or handle your card number — it goes directly to Stripe. We only store a Stripe customer ID in our database to link your subscription status.
Data storage
Your account, session history, tasks, focus sessions, brain dumps, goals, journal entries, routines, check-ins, and other saved workspace content are stored in a Supabase (PostgreSQL) database with row-level security. Data is encrypted at rest and in transit (TLS).
AI processing
The text you submit is sent to Anthropic's Claude API to generate responses. According to Anthropic's policy, API data is not used to train their models. Text is transmitted securely over HTTPS and is not stored by Anthropic after processing. We don't log your session content beyond what's needed for your history.
Local storage
If you use Resistaa without an account, your usage count is tracked in your browser's localStorage only — it never leaves your device. With your consent (via the cookie banner), we use Google Analytics, Google Tag Manager, and Plausible for product analytics — if you decline, no analytics cookies are set. The only cookies set without consent are Supabase auth session cookies (required for login to work).
No advertising
We use no advertising networks or tracking pixels, and we never sell your data. With your consent, we use Google Analytics and Plausible for aggregate product analytics — never for ad targeting or profiling. We don't share your data with anyone except the processors listed above (Supabase, Anthropic, Stripe) and, if you've consented to analytics, Google and Plausible — only to the extent necessary to run and improve the service.
Your data controls
You can delete your account at any time from Settings → Danger zone. Your data is permanently removed within 24 hours of deletion. You can also clear your session history at any time from Settings → Data controls without deleting your account.
Security concerns or vulnerabilities
If you discover a security issue, please email us at hello@maisongr.com before disclosing publicly. We take security reports seriously and will respond within 48 hours.
Last updated: July 2026 · Questions: hello@maisongr.com