Skip to content

Security

Your accounts are
carried carefully.

Spuro connects to the accounts your business runs on. We treat that responsibility as part of the product. Here is how your data is handled, in plain words.

One workspace, one boundary.

Everything you store in Spuro belongs to your workspace and is scoped to it at the database layer (row-level security in Postgres), not just in application code. Every request that touches tenant data verifies the resource belongs to your organization before acting.

Connected-account credentials are encrypted.

Tokens for the platforms you connect are encrypted at rest with a dedicated key, on top of full-database encryption at rest. They are used server-side only and never shipped to the browser.

Least privilege by default.

We request the narrowest platform scopes that make a feature work, and every publishing action runs through guarded server routes.

Transport is locked down.

All traffic is HTTPS with HSTS preload, a strict Content-Security Policy, and frame embedding disabled. The marketing site sets no advertising trackers.

Your content stays yours.

Ad copy, creatives, and results generated for your workspace are yours. We do not sell your data, and we do not use your private business data to train AI models.

Deletion is a request away.

You can request deletion of your account and its data at any time (see the Data deletion page); connected platforms can be disconnected whenever you want, which revokes Spuro's access.

Questions, or something you think we should harden further? Tell us: jerry@datamindmedia.com. Security reports get read first.