Security & providers

Know where the boundaries are.

A practical account of what Seamline checks, what each provider receives, and where to ask for help. Building in public before launch.

Current controls

Creator-scoped data

Subscriber records belong to one creator. Database row policies and server checks scope creator reads and writes.

Subscriber data stays out of AI

AI uses creator-approved content and voice settings, feedback on generated copy, and aggregate activity counts. Creator email addresses, subscriber identities, and event guest details stay out of prompts.

Server-side plan checks

Plan limits are decided from server-side creator records. A browser cannot grant itself a paid tier or a larger generation allowance.

Email choices

Creator marketing sends check unsubscribe and subscriber preferences before contacting the email provider. Event service messages are handled separately.

Verified sender setup

Subscriber mail waits for a verified creator sender. A recorded signup is not presented as proof that an email was delivered.

Browser protections

Public responses set a content security policy, transport security and same-origin framing controls. Private signed-link pages prevent referrer sharing.

Service providers

These providers support specific product tasks. Subscriber identities are never sent to the AI provider. See the privacy policy for collection and retention details.

  • Supabase

    Database and account authentication, including creator and subscriber records.

  • Anthropic / Claude

    AI uses creator-approved content and voice settings, feedback on generated copy, and aggregate activity counts. Creator email addresses, subscriber identities, and event guest details stay out of prompts.

  • Jina Reader

    Reads the public URL a creator chooses to import or compare. Receives that URL and retrieves its page content; account credentials and subscriber records are not sent.

  • Stripe

    Payment processing and subscription records.

  • Brevo

    Email dispatch and delivery events. Receives the recipient address and the message needed to deliver the email.

  • Cloudflare

    Hosting, content delivery, custom-domain routing and first-party aggregate analytics.