Legal

Security

A plain description of the measures in place around your account, your listing photos and your payments.

Last updated August 10, 2026 · Questions: support@stageit.app

Accounts and sign-in

Sign-in runs through a managed identity provider, so we never handle or store your password. Sessions are issued as short-lived tokens and every request to our backend is validated before any data is returned.

Data separation

Properties, photos, scenes, renders and credit records are protected with row-level security rules that scope each row to the account that owns it. Requests carrying another user's identity cannot read or modify your rows.

Photo storage

Uploaded photos and rendered images live in a private storage bucket that is not publicly listable. Images are shown to you through time-limited signed URLs rather than permanent public links.

Transport and keys

Traffic between your browser and our servers is encrypted in transit over HTTPS. API keys for AI and payment providers are held as server-side secrets and are never exposed to the browser.

Payments

Card data is entered directly into our payment provider's hosted checkout. We receive only the confirmation of a charge and the plan or pack that was purchased, and webhook events are signature-verified before we grant credits.

Reporting a vulnerability

If you believe you have found a security issue, email support@stageit.app with steps to reproduce it. Please give us a reasonable window to respond before disclosing publicly, and avoid accessing other people's data, degrading the service or running destructive tests while investigating.

Your part

Keep the email account you sign in with secure, sign out of shared devices, and remove properties you no longer need so old listing photos are not retained longer than necessary.