Safeguards in this release
HTTPS and browser security headers protect delivery. Google Firebase authenticates users. Data and AI endpoints require a verified Firebase identity from a supported sign-in method and App Check. Firestore and Cloud Storage client rules deny direct access; the backend derives the owner from the verified identity. Backend-managed state separates drafts, simulations and any future real publications. Private images have no public download links. Google Cloud encrypts stored data at rest.
Development and operations
Development tests use local emulators and synthetic data. Test spaces are separate from production records. Input limits, per-account rate limits and instance limits bound usage. Idempotent storage and durable deletion jobs support recovery from interrupted requests. Application logs contain operational codes, not photos, model outputs, contacts or tokens. Dependencies and access rules are tested before release; this is not an independent penetration test or certification.
Administrative requirements
The sole employee/DPO owns access, incidents and reviews. Administrative accounts must use MFA, devices must use disk encryption, screen lock, firewall and malware protection, and updates must be maintained. Review permissions quarterly and after role changes. Keep credentials outside source code. This policy states operating requirements; device checks and exceptions are recorded separately. Report incidents to ymeghzifene@hotmail.com; contain affected access, preserve necessary evidence, remediate, test recovery and evaluate required notifications.