
How We Keep Your Payments and Account Secure
Card details are entered on our payment provider and never touch our servers. We store only what we need to match an order to a payment, such as an order reference and status.

Layers of protection 🛡️
| Layer | What it protects | How it helps |
|---|---|---|
| Payment processor | Card data | Card numbers never reach our systems |
| Account login | Panel access | Protects credits and tokens from theft |
| Token scoping | Per-app access | Revoke one token without touching the rest |
| Rate limiting | Abuse | Blocks automated guessing and flooding |
Your side of the deal 🤝
- Use a unique password for your account
- Keep tokens in environment variables, not in code
- Create a separate token per application
- Rotate tokens when a teammate leaves
If something looks wrong 🚨
Delete a leaked token immediately and create a new one; there is no penalty for rotating. Then contact support with your order number and the time window so we can review account activity.
Frequently asked questions ❓
Do you store my card number?
No. Card details are handled entirely by our payment processor and never reach our servers.
What should I do if a token leaks?
Revoke it in the panel and create a replacement right away. Rotation is free and immediate.
Can I use one token for everything?
You can, but separate tokens per app are safer because you can revoke one without disrupting the others.
How do you prevent abuse?
We apply rate limiting and review unusual activity, alongside the moderation and spam filtering used across the site.
Comments (0)