Vocally
Get started

Trust & Security

This page is maintained by Vocally Global Inc. to answer common security and privacy questions about Vocally. It describes the controls currently enabled in the product and is editable project content — not an independent certification or audit attestation.

Shared responsibility

Vocally runs on Supabase-hosted infrastructure, which provides the underlying database, authentication, storage, and edge-function infrastructure. Vocally Global Inc. is responsible for application logic, access policies, and how user data is handled inside the product. Customers (students and tutors) are responsible for protecting their own account credentials and the content they exchange.

Authentication & access

Data protection

Messaging & content controls

Payments

Payments are processed by Stripe. Vocally does not store full card numbers on its servers. Lesson prices are recomputed server-side from each tutor's configured hourly rate; client-supplied prices are not trusted.

Subprocessors

Retention & deletion

When an account is deleted, Vocally purges the user's profile, tutor profile, messages, bookings, reviews, reports, favorites, placement results, and policy acceptances, and removes the underlying authentication record. See the Privacy Policy for details on retention periods that apply to financial, tax, or dispute records.

Your privacy rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to withdraw consent for marketing communications. The Privacy Policy describes these rights and how to exercise them.

Reporting a security issue

If you believe you have found a security vulnerability in Vocally, please emailsecurity@vocallyglobal.com with a clear description and reproduction steps. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.

Contact

Privacy Officer: privacy@vocallyglobal.com
General support: support@vocallyglobal.com