Security

Security at Reeloop

Last updated August 8, 2026

This page describes the concrete measures we take to protect your account and content. We do not hold a formal certification (SOC 2, ISO 27001) yet - rather than claim one, we list here what is actually in place, and we rely on certified infrastructure providers for the layers underneath.

Infrastructure & data protection

Application security

Sub-processors

We rely on a small set of infrastructure providers, each covered by its own security program and DPA. The current list (Stripe for payments, Supabase for database/storage/auth, PostHog for analytics, and the AI providers that generate video, voice and avatars) is maintained in our Privacy Policy.

Data retention & deletion

Data is kept on fixed schedules enforced by an automated daily job (for example, intermediate tool outputs are deleted after 30 days, source voiceovers 7 days after render). You can delete your account and all associated data at any time from Settings → Account. The full retention schedule is in the Privacy Policy.

Reporting a vulnerability

If you believe you have found a security issue, please email support@reeloop.ai with the details. We ask that you give us a reasonable window to investigate and fix before any public disclosure. We do not currently run a paid bug-bounty program.

Security | Reeloop