Data & Security

Effective August 28, 2026

Praxify holds photographs of the inside of other people’s homes and a record of who was in them and when. We treat that as the most sensitive thing about this business. This page says plainly where that data lives, who can reach it, and what we do and do not promise.

Praxify is operated by Aegora, LLC, a Puerto Rico limited liability company. We are a small team. This page describes real controls, not a certification we have not earned.

What we hold

DataWhere it lives
Owner accounts, company settings, SOPs, jobs, timestamps, metricsManaged Postgres (Supabase), United States
Photos captured in the field appObject storage (Supabase), United States
Payment method and billing historyStripe. We never see or store card numbers.
Transactional email (invites, reports, notifications)Resend
Application hosting and logsVercel, United States

We do not collect GPS location. We do not record audio or video. We do not use property photos for advertising or to train third-party AI models.

Separation between companies

Every table that holds customer data is protected by database-level row-level security. Access is scoped to the company that owns the record and enforced by the database itself, not only by application code — so a bug in a screen cannot hand one cleaning company another’s jobs, photos, or crew.

Encryption

All traffic to Praxify is served over TLS. Data at rest in our database and object storage is encrypted by the provider. Uploads from the field app are authenticated — a photo cannot be written into an account by someone who is not signed in to it.

Report links and photos

Host Reports are shared by link so an owner can open one without an account. Those links and the photo files behind them use long, unguessable identifiers and are not indexed. They are secret URLs, not passwords: anyone who has the link can open the report. Share them deliberately, and tell us if one needs to be revoked.

Who can reach production

Administrative access to the production database, storage, hosting, and billing is limited to Aegora’s founder. We have no offshore support desk and no contractor with a standing key. We do not access a customer’s data except to operate the Service, investigate a problem, respond to a support request, or comply with law.

Our providers (Supabase, Vercel, Stripe, Resend) each run their own audited security programs and are bound by their own commitments. A current list of subprocessors is in the Privacy Policy.

Application controls

Public endpoints are rate-limited and honeypot-guarded. Privileged database writes run server-side with credentials that are never exposed to a browser. Sessions are cookie-based and scoped to a single company. Dependencies are kept current.

Resilience

The Service runs on managed infrastructure with provider-level redundancy. We do not offer an uptime guarantee or a service level agreement, and we do not promise that data will never be lost. Export anything you would be sorry to lose. Your data is exportable at any time and for 30 days after you cancel. That right, and its limits, are in our Terms of Service.

If something goes wrong

If we learn of a security incident affecting customer data, we will investigate immediately, contain it, notify affected customers without undue delay and as required by law, and tell you what we know, what we do not yet know, and what we are doing about it. We would rather send an early, incomplete notice than a late, tidy one.

Reporting a vulnerability

Email clinton@getpraxify.com with “Security” in the subject. Report in good faith, do not access or alter data that is not yours, do not degrade the Service, and give us a reasonable chance to fix it — and we will not pursue you.

What we do not claim

We are not SOC 2 certified, not ISO 27001 certified, and not HIPAA or PCI in scope (Stripe handles cards). We do not currently publish third-party penetration test results. If your procurement process requires any of that today, we are not the right vendor yet — and we would rather tell you now than sell around it.

Your side of it

Use a strong, unique password. Remove crew members in the dashboard when they leave. Treat Host Report links as private. Tell your cleaners, before they use the field app, what Praxify records — the Terms require it, and the Privacy Policy explains it in plain language you can forward.

Changes

We will post the new effective date here. If a control on this page changes materially, we will say so.