Thursday, August 27, 2026
    Envira — Reporting on the Planet

    Trust & Security

    This page is maintained by AW3 TECHNOLOGY, Inc. to answer common security and privacy questions about Envira. It describes the controls that are currently enabled in the application. It is editable project content and is not a Lovable certification or independent audit.

    Shared responsibility

    Envira is operated by AW3 TECHNOLOGY, Inc. on top of the Lovable Cloud platform (powered by Supabase). Lovable Cloud provides the underlying hosting, database, authentication, and edge-function infrastructure. AW3 TECHNOLOGY, Inc. is responsible for the application code, configuration, content moderation, and how reader data is handled. Readers are responsible for safeguarding their account credentials.

    Access & authentication

    • Accounts are optional and used for posting comments and liking articles.
    • Authentication is handled by the Lovable Cloud auth service; passwords are stored as salted hashes — we never see them in plain text.
    • Administrative actions are gated by a server-side role check stored in a dedicated user-roles table; the client cannot grant itself admin access.
    • Row-level security is enabled on application tables so users can only read and modify their own records, except where content is intentionally public (e.g. published articles).

    Platform & hosting

    • The site is served over HTTPS.
    • The database and storage are hosted on Lovable Cloud (Supabase). Data in transit is encrypted via TLS and data at rest is encrypted by the platform provider.
    • Backend logic runs in managed edge functions; secrets are stored in the platform's secret store and are not shipped to the browser.

    Data we collect

    A full description is in our Privacy Policy. In summary:

    • Account email and hashed password (only if you create an account).
    • Newsletter email address (only if you subscribe).
    • Comments you post and likes you give to articles.
    • Anonymous usage analytics (page views, visitor and session identifiers) used to understand readership.

    Subprocessors & integrations

    • Lovable Cloud (Supabase): hosting, database, authentication, storage, edge functions.
    • Resend: delivery of newsletter and transactional email.
    • ElevenLabs: generation of article narration audio.
    • Perplexity & Lovable AI Gateway: assistive models used in our editorial pipeline; reader personal data is not sent to train third-party models.

    Cookies & analytics

    We use strictly-necessary cookies for authentication and session management, and first-party analytics to count page views and unique visitors. See the Cookie Policy for the full list and how to manage preferences.

    Retention & deletion

    Retention periods are listed in the Privacy Policy. You can request account or newsletter deletion at any time by emailing privacy@envira.press.

    Privacy requests

    EU/UK residents have GDPR rights and California residents have CCPA/CPRA rights, including access, correction, deletion, and portability. To exercise a right, email privacy@envira.press.

    Security contact & vulnerability reporting

    If you believe you have found a security vulnerability in Envira, please report it privately to security@envira.press. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We do not currently operate a paid bug-bounty programme.

    Compliance

    Envira does not currently hold independent certifications such as SOC 2, ISO 27001, HIPAA, or PCI DSS. We design the application to comply with applicable privacy laws (including the GDPR, UK GDPR, and CCPA/CPRA) as described in our Privacy Policy. Any future certifications will be listed here once obtained.