Security & Data Handling
Last updated:
The short answer: Your listing data, documents, and conversations stay yours. We encrypt data at rest and in transit. We don't sell your information. The AI providers we use process data under API agreements that explicitly prohibit using your data to train models. Below is the full breakdown, provider by provider.
Encryption
In transit: All traffic between your browser and Selfana runs over HTTPS (TLS 1.2+). Plain HTTP requests are redirected to HTTPS automatically.
Documents and files at rest: Files you upload (photos, disclosure forms, contracts) are stored in Cloudflare R2. Cloudflare R2 encrypts all objects at rest using AES-256 by default. See Cloudflare R2 data security.
Database at rest: Account data, transaction records, and AI conversation history are stored in Neon (serverless PostgreSQL), which encrypts data at rest using AES-256.
Key access: Encryption keys are managed by the respective cloud providers (Cloudflare for R2 storage, the database host for the database). No Selfana employee has access to raw customer data outside of normal application-layer authentication.
Authentication
Selfana uses Better Auth for session management. Sessions use secure, httpOnly cookies that are not accessible to JavaScript. Passwords are hashed using bcrypt before storage.
OAuth sign-in via Google and GitHub is available as an alternative to password authentication. We store only the OAuth provider ID and access token — no password hash is created for OAuth accounts.
Two-factor authentication (2FA) is on the roadmap and will be added before Selfana handles any transaction funds.
AI provider — your data is not used for model training
Selfana uses the OpenAI API to power listing generation, offer analysis, and transaction coordination. This means your listing data, uploaded documents, and conversation history may be sent to OpenAI for processing.
Under OpenAI's API usage policy, data submitted through the API is not used to train or improve OpenAI's models by default. We do not use consumer products (ChatGPT) for processing customer data — all AI calls go through the business-grade API.
AI conversation monitoring
Selfana logs AI conversations (your prompts and the AI's responses) via LangSmith (a LangChain product) for quality assurance, safety monitoring, error detection, and legal compliance.
Logs are associated with an internal identifier — not your email address directly. Selfana staff or legal counsel may review logged conversations in connection with disputes, compliance audits, or safety investigations. This logging is a condition of using Selfana's AI features and is disclosed in our Privacy Policy.
Transaction-related AI conversations are retained for 7 years to support potential dispute resolution. Non-transaction AI conversations (e.g., general questions before you start a listing) are retained for 90 days.
Third-party processors
The following sub-processors handle customer data as part of delivering the service. Each link goes to that provider's security or privacy documentation.
- Stripe — payment processing. Stripe is PCI DSS Level 1 certified, the highest level of payment security compliance. Selfana stores only a Stripe customer ID — no card numbers.
- Resend — transactional email (password resets, notifications). Your email address is shared with Resend to deliver messages. See Resend's privacy policy.
- Cloudflare R2 — document and file storage. Files at rest are encrypted by default. Cloudflare Privacy Policy.
- PostHog — product analytics. PostHog is loaded only if you accept analytics cookies via our consent banner. No analytics data is collected without your explicit opt-in. See PostHog's privacy policy.
- LangSmith (LangChain) — AI conversation tracing and monitoring. AI prompts and responses are logged to LangSmith for quality assurance and legal compliance. See the AI conversation monitoring section above and LangChain's privacy policy.
Vulnerability disclosure
If you believe you've found a security vulnerability in Selfana, please report it to [email protected].
We acknowledge all reports within 2 business days and aim to resolve confirmed vulnerabilities within 30 days. We ask that you give us reasonable time to investigate and remediate before public disclosure.
We don't have a bug bounty program yet. We will credit researchers by name in our changelog if they'd like, after the issue is resolved.
Compliance posture
SOC 2 / ISO 27001: Selfana does not currently hold SOC 2, ISO 27001, or any other third-party security certification. We're an early-stage company. These certifications require time and resources we're building toward; we'll publish our status here when that changes.
Real estate compliance: MLS access and listing requirements are handled by our licensed broker partners per state. Each broker partner is a licensed real estate professional subject to their state real estate commission's rules and the National Association of Realtors' Code of Ethics and MLS policies. Selfana's role in the transaction is as a software platform; legal responsibility for MLS submission rests with the broker partner.
RESPA: If Selfana refers sellers to title companies, any compensation arrangement is structured to comply with the Real Estate Settlement Procedures Act (RESPA, 12 U.S.C. 2601). No vendor referral fees are accepted without a counsel-reviewed Marketing Services Agreement.
Incident response
If a confirmed data security incident affects your account, we'll notify you by email within 72 hours of confirming the breach. The notice will include:
- What data was involved
- When the incident occurred (if known)
- What we did to contain it
- What steps you can take to protect yourself
We will also notify regulators as required by applicable state and federal data-breach notification laws.
Questions
For security questions not covered here, email [email protected]. For general privacy questions, email [email protected]. See also our Privacy Policy for the full data-collection picture.