Trust & Security
This page is maintained by Vocally Global Inc. to answer common security and privacy questions about Vocally. It describes the controls currently enabled in the product and is editable project content — not an independent certification or audit attestation.
Shared responsibility
Vocally runs on Supabase-hosted infrastructure, which provides the underlying database, authentication, storage, and edge-function infrastructure. Vocally Global Inc. is responsible for application logic, access policies, and how user data is handled inside the product. Customers (students and tutors) are responsible for protecting their own account credentials and the content they exchange.
Authentication & access
- Email-and-password and Google sign-in are supported.
- Sessions are managed by the platform's authentication service; tokens are stored client-side and rotated on refresh.
- Administrative actions in the back office require an additional PIN check.
- Tutors and students have separate roles, and role checks are enforced on the server through row-level security and security-definer database functions — never by the client alone.
Data protection
- Row-level security is enabled on every user-facing table. Users can only read or change the rows that belong to them, except where an explicit policy or admin RPC grants broader access.
- Sensitive tutor fields — credential uploads, internal reminder counters, approval metadata — are excluded from the public Data API through column-level grants and are only readable via dedicated server functions.
- Data is encrypted in transit (TLS) between your browser, our edge functions, and the database.
Messaging & content controls
- In-app chat is filtered server-side for personal contact information and obfuscation patterns to discourage off-platform circumvention.
- Display names are masked publicly to first name and last initial; full names are visible only on a user's own profile and to administrators.
- Meeting links sent in lesson reminder emails are validated against an allowlist of approved video providers (Jitsi, 8x8, Zoom, Google Meet, Microsoft Teams, Whereby) plus Vocally's own domains.
Payments
Payments are processed by Stripe. Vocally does not store full card numbers on its servers. Lesson prices are recomputed server-side from each tutor's configured hourly rate; client-supplied prices are not trusted.
Subprocessors
- Supabase — database, authentication, storage, and edge functions; Vercel — web application hosting.
- Stripe — payments and tutor identity/tax verification.
- Resend — transactional email delivery.
- 8x8 JaaS (Jitsi) — embedded lesson video conferencing.
Retention & deletion
When an account is deleted, Vocally purges the user's profile, tutor profile, messages, bookings, reviews, reports, favorites, placement results, and policy acceptances, and removes the underlying authentication record. See the Privacy Policy for details on retention periods that apply to financial, tax, or dispute records.
Your privacy rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to withdraw consent for marketing communications. The Privacy Policy describes these rights and how to exercise them.
Reporting a security issue
If you believe you have found a security vulnerability in Vocally, please emailsecurity@vocallyglobal.com with a clear description and reproduction steps. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
Contact
Privacy Officer: privacy@vocallyglobal.com
General support: support@vocallyglobal.com