Security and data handling · private preview

Clear controls for your account and your data.

See what each control does, what it protects, and where its boundary remains.

Report a security concern

01 · account access

Sign-in has more than one gate.

Control

Password plus mandatory TOTP two-factor authentication; recovery codes are available for recovery sign-in.

Effect

Sessions use an opaque cookie, expire after 30 minutes idle or 8 hours absolutely, and can be revoked.

Limit

Recovery codes are single-use and stored as keyed hashes. No security control makes an account invulnerable.

02 · buyer details

Masking is not the same as a blur.

Control

Buyer masking withholds buyer-identifying facts from the client; it fails closed when the setting is absent or unreadable.

Effect

A separate display-blur treatment changes how visible content looks on screen. It does not replace masking or change stored data.

Limit

Unmasked buyer-data disclosure creates an audit row recording who, when, and which order—not the disclosed values.

03 · retention boundary

Retention follows the order, not a store setting.

Control

Buyer name, address, and contact facts are redacted 90 days after fulfillment or dispute closure.

Effect

The clock uses the later of fulfillment and dispute closure, while an open dispute or pending/active legal hold pauses it.

Limit

Ninety days is a floor, not a guaranteed erasure date. The retention window is fixed; stores cannot change it.

04 · backups and restore

A backup is checked before it counts.

Control

Backups are encrypted, read back, decrypted, authenticated, and checked against their manifest when created.

Effect

Backups contain inventory, mappings, settings, and redacted audit facts; credentials, sessions, MFA material, messages, and buyer addresses are excluded.

Limit

Restore needs two separate approval steps and recent reauthentication. Verification at creation is not a promise that every restore will succeed.

05 · scan photos

Uploading a scan is a choice with a boundary.

Control

The scan photo goes to api.brickognize.com for recognition. Saving it for a future in-house recognizer starts unticked on every scan.

Effect

Without consent, the photo is not kept. Consented photos can be deleted from the privacy settings danger zone.

Limit

Deletion is account-wide and irreversible, with no per-photo choice; it cannot untrain a model that already used a photo. There is no automatic retention sweep.

06 · connected services

Connections stay specific.

Control

BrickLink is used for marketplace reads when that connection is active. Its requests are credentialed and scoped to the supported read flow.

Effect

BrickLink is a user-directed marketplace, not automatically a Brick Pulse data processor. Pirate Ship is a CSV upload path, not an API integration.

Limit

Marketplace writes remain disabled and shadow-only in this preview. No live synchronization or write outcome is promised.

07 · questions and reports

Send a useful security report.

Email support@brickpulse.app with the task, screen, and exact error wording, after removing passwords, payment details, recovery codes, buyer exports, and other private data. This is an inbound reporting channel; the preview does not promise a response time or a public incident program.

Read the Privacy PolicyRead the Terms of ServiceReview provider boundaries