Trust & Security

We're a small company. We don't have a compliance department or a SOC 2 badge to wave around. What we do have is a clear accounting of exactly how your data is handled, stored, and protected. Stated plainly, without the corporate fog.

LensCherry

LensCherry generates professional photos using cutting-edge AI models. Here's the chain of custody for your images:

  • Reference photos are uploaded over HTTPS and stored in EU data centers (Hetzner object storage, Finland). They are used only to create your personal AI model. Never shared, never sold, never used to create any general-purpose model.
  • AI processing happens via Google Cloud infrastructure. Your images are processed to generate results, then discarded by the provider. Google does not use customer data to train its models when accessed through their API.
  • Generated photos are stored in your account until you choose to delete them or delete your account. They belong to you.
  • Deletionmeans deletion. When you delete photos or your account, the data is removed from our servers. No shadow copies, no “we keep it for 90 days just in case.”

Thicket

Thicket is a project management tool. Your project data (tasks, comments, files) lives on our infrastructure:

  • All traffic is encrypted via HTTPS. There is no unencrypted path to your data.
  • Data is stored in the United States: the application and its database run on dedicated Hetzner servers in Ashburn, Virginia, and uploaded files live in Cloudflare R2 (US region), encrypted at rest. File backups are replicated daily to a separate storage provider in the EU.
  • Row-level data isolation: every organization's data is isolated at the database level using PostgreSQL Row Level Security. Even in the event of an application vulnerability, one organization cannot access another's data. This is enforced by the database engine itself, not application code.
  • Authentication: email/password and Google SSO. Two-factor authentication (2FA) is available for all accounts, and organizations can require it for their members. Sessions are managed server-side with secure, HTTP-only cookies.
  • We don't read your projects. Your data is yours. We access it only if you explicitly ask us to for support purposes.

Infrastructure

Both products run on dedicated servers we control, not a multi-tenant platform where a neighbor's misconfiguration becomes your problem. Uploaded files live in managed object storage, encrypted at rest. Here's what we run:

  • Cloudflare in front: all web traffic routes through Cloudflare for DDoS protection and TLS termination. Application servers are never exposed directly to the public internet.
  • Daily automated backups: database and files, stored with a separate provider in a separate region from the production servers, so data is recoverable even if we lose the primary infrastructure entirely.
  • Key-only administrative access: password authentication is disabled, and administrative access is only possible over a private network — not reachable from the public internet.
  • Automated intrusion prevention: repeated failed access attempts are detected and the offending addresses banned automatically.
  • Default-deny firewall: nothing is reachable unless explicitly allowed. Only Cloudflare can reach the web ports; nothing else is exposed.
  • TLS everywhere: all public endpoints use HTTPS with modern cipher suites. Certificates are managed by Cloudflare.

Privacy

Three commitments, without qualification:

  • 1.We do not sell your data. Not to advertisers, not to data brokers, not to anyone. Our revenue comes from the products you pay for.
  • 2.You can delete everything.Your account, your data, your history. Contact us and it's done, or use the self-service options in each product.
  • 3.We tell you what changed.If our privacy practices change, we'll update our privacy policy and notify affected users. No silent edits.

What We Don't Claim

Honesty means saying what you haven't done, too:

  • We don't hold SOC 2, ISO 27001, or similar certifications. We're a small team and the cost/complexity isn't justified at our scale, yet.
  • We don't have a dedicated security team. Security is handled by the engineering team with the practices described above.
  • We haven't undergone a third-party penetration test. It's on the roadmap as we grow.

We believe honest specifics beat vague assurances. You deserve to know exactly where the line is.


Questions or Concerns

If you have a security concern, a data question, or just want to know more about how we handle something specific:

Open a support request →

For security-specific issues, email [email protected]


Trust is earned in specifics, not slogans.

Vesperion Gate Inc.