Information security policy.
Effective September 13, 2026.
Reclearly is operated by Turbo Link LLC. This policy describes how Reclearly protects the information account holders and their clients trust it with. It sits alongside the privacy policy, which explains what is collected and how long it is kept.
Scope
This policy covers the Reclearly application at app.reclearly.com, its client portals and public pages, its database and file storage, and the integrations an account holder connects.
Where data lives, and who processes it
Reclearly runs on established infrastructure providers rather than its own servers:
- Supabase for the database, authentication and file storage. The primary database is in AWS us-east-2, in the United States.
- Vercel for hosting.
- Stripe for payments. Reclearly never stores card numbers.
- Resend for email.
- Anthropic for the AI features described in the privacy policy.
Data is encrypted in transit with TLS and encrypted at rest by these providers.
Access control inside the product
- Every table holding customer data enforces row level security in the database, so an account holder can read only their own records, and teammates' profiles when they are on a team. This is enforced by the database itself, not only by application code.
- Anonymous database role privileges were audited and reduced in September 2026, and new tables are created without write access for anonymous visitors.
- Database functions that run with elevated rights are restricted to the roles that need them.
- Client portals use long, random links instead of passwords. An agent can revoke a portal link at any time, portal reads are rate limited, and documents are served through short lived signed links from private storage.
- Full contracts and government identifiers are kept off portals by design.
Access to production systems
- Production access is limited to Reclearly's operator. No one else holds production access.
- Administrative accounts for the hosting, database, payment and source control providers use multi-factor authentication.
- Secrets such as API keys are stored in the hosting provider's encrypted environment settings, never in source code. Source code is kept in private repositories.
Third party connections
- Nothing is connected by default. An account holder connects each integration themselves and can disconnect it in Settings at any time.
- Credentials for connected services are used only to provide the feature the account holder turned on, and are stored encrypted.
- Reclearly does not send email or text messages to an account holder's CRM contacts through a CRM integration.
Development and change management
- Changes are reviewed and merged one at a time, and automated checks (type checking, linting, and a test suite that includes access checks on protected pages) run before a change reaches production.
- Database changes are written as versioned migrations and checked for the privileges they grant before and after they are applied.
Backups and retention
- The production database is backed up in encrypted form, and backups age out after seven days. Point in time recovery is not enabled.
- Retention and deletion follow the privacy policy: account data is deleted two months after cancellation, and assistant conversations after ninety days.
Incidents
If Reclearly becomes aware of unauthorized access to customer data, it will investigate, contain the issue, and notify affected account holders within 72 hours of confirming it, and as the law requires.
Reporting a security concern
Write to support@reclearly.com. Reports are acknowledged and investigated, and Reclearly will not take action against anyone who reports a problem in good faith and does not access more data than needed to show it.
Changes to this policy
If this policy changes materially, the effective date above changes.
Contact: support@reclearly.com