Your leads are your business.
We treat them that way.
This page is maintained by Legion AI to answer common security and privacy questions. It describes the controls we operate today, our subprocessors, and how to reach us with security questions.
This is an app-owner-maintained trust page, not an independent certification.
Security controls
The practices and platform capabilities protecting your workspace.
Encryption in transit & at rest
All traffic to Legion AI uses TLS 1.2+. Customer data is stored encrypted at rest on managed cloud infrastructure using AES-256.
Authentication
Email + password with hashed credentials, optional Google SSO, and session tokens rotated on sign-out. Enterprise plans support additional SSO on request.
Row-level access controls
Every record in our database is scoped by workspace and role. Users can only read and write data belonging to their organization.
Managed cloud hosting
Legion AI runs on Lovable Cloud, which provisions Supabase-managed Postgres, storage, and edge functions on hardened cloud infrastructure with automated backups.
Backups & recovery
Daily automated database backups with point-in-time recovery on our production plan. Backups are encrypted and retained for 30 days.
Least-privilege access
Only a small number of Legion engineers have production access, gated by SSO and audit-logged. Access is reviewed quarterly.
Continuous monitoring
Runtime error tracking, uptime monitoring, and automated security scans run against every deploy. Vulnerabilities are triaged within one business day.
Incident response
Documented internal runbook for security incidents. If your data is materially affected, we will notify the primary account contact without undue delay.
Shared responsibility
Security is a partnership. Here's how responsibility splits between Legion AI, our infrastructure provider, and you as a customer.
Lovable Cloud (infrastructure)
- •Hardened database + storage
- •Physical + network security
- •Managed backups
Legion AI (application)
- •App-layer access controls
- •Data encryption + secrets management
- •Vulnerability triage + patching
You (customer)
- •Strong passwords + SSO where available
- •Managing team member access
- •Only sending data you're authorized to process
Subprocessors
Third-party services that process customer data on our behalf.
| Provider | Purpose | Region |
|---|---|---|
| Lovable Cloud (Supabase) | Managed Postgres, auth, storage, edge functions | US |
| OpenAI / Anthropic / Google (via Lovable AI Gateway) | LLM inference for AI agents | US |
| Twilio | SMS + programmable voice | US |
| Resend | Transactional email | US / EU |
| Stripe | Billing & payments | US |
| Cloudflare | CDN, DNS, DDoS protection | Global |
Data we collect
- • Account info (name, email, workspace)
- • Leads and contacts you import or capture
- • Conversation transcripts (calls, SMS, email)
- • Product usage + diagnostics
Retention & deletion
Customer records are retained while your account is active. Deleted records are removed from production within 30 days and from backups within 60 days. Full account deletion can be requested at any time.
Common questions
Do you sell customer data?
No. We never sell, rent, or share customer data with third parties for marketing or advertising. Data is used only to operate and improve the service for you.
Do you train AI models on my data?
No. Prompts and lead data sent to LLM providers through the Lovable AI Gateway are configured to opt out of training. Your data is used to power AI responses in your workspace only.
Where is my data stored?
Production data is stored in US-region managed Postgres on Lovable Cloud (Supabase). Backups are region-locked. Enterprise customers can request additional deployment options.
Can I delete my data?
Yes. You can delete individual records in-app at any time. On account cancellation you can request a full export and permanent deletion by emailing security@thelegionai.com.
Do you have SOC 2 or HIPAA?
Legion AI is not currently SOC 2 or HIPAA certified. We follow the practices described on this page and can provide a security questionnaire on request. Enterprise customers can request a security review before onboarding.
How do I report a vulnerability?
Email security@thelegionai.com with reproduction steps. We acknowledge reports within one business day and will keep you updated on remediation.
Security questions or a report to file?
Reach our security team directly. We acknowledge every report within one business day.
Legion AI