Legal
Security Policy
Last updated: July 30, 2026
This page is maintained by the operator of nowican.app to answer common security questions about the app. It describes the controls currently in place — it is not an independent audit, certification or guarantee.
Accounts and access
Accounts are created with email and password or Google sign-in, handled by the app's authentication provider; passwords are never stored by the app itself. Signing in issues a session token in your browser, and signing out ends it. Anonymous sign-ups are disabled.
Administrative actions, such as the recipe importer, are restricted to accounts with an admin role checked on the server. Roles are stored separately from user profiles.
Data protection
Every private table — saved recipes, journal entries, batches, pantry items and privacy requests — is protected by row-level access rules so a row can only be read or changed by the account that owns it. Traffic to the site is served over HTTPS, and data is encrypted in transit and at rest by the hosting platform.
Journal photos live in a private storage bucket and are shown only to their owner through short-lived signed links. Public content is limited to submitted recipes, their photos, comments, display names and aggregate heart counts.
Platform and hosting
nowican.app runs on Lovable Cloud, which provides hosting, the database, authentication and file storage, including managed backups and platform-level patching. Describing these platform capabilities is not a claim of certification by the platform or by us.
Shared responsibility
The platform secures the underlying infrastructure. As the app owner we configure access rules, admin roles and what is public. As a user, you're responsible for keeping your login details secure, using a unique password, and not posting sensitive personal information in public comments or recipe submissions.
Reporting a vulnerability
If you believe you've found a security issue, please report it privately through the contact details published on the site before disclosing it anywhere else. Include the steps to reproduce it and what you were able to access. Please don't run automated scanning that degrades the service, access or modify other people's data, or use social engineering. We'll acknowledge legitimate reports and work on a fix.
Your data rights
You can request a copy of your data or ask for your data to be deleted from data requests. See the Privacy Policy for what we collect and how long it's kept.