Security
RecorIt only holds the information you choose to put in your trackers, and we work to keep it private and secure.
Authentication
Sign-in uses Auth.js with Google OAuth and passwordless email magic links — there are no passwords for us to store or for you to reuse. Sessions are database-backed and can be signed out at any time.
Encrypted in transit
All traffic is served over HTTPS. We do not claim end-to-end encryption; your trackers are stored so that RecorIt can display and compute summaries on them.
Account isolation
Every request is scoped to your account. Access checks run on the server for every read and write, so you can only see and change your own trackers, records and reminders.
Where your data lives
Tracker data is stored in a managed Neon Postgres database. Payments are handled by Stripe — RecorIt never sees or stores your full card details.
What RecorIt never asks for
Standard trackers never require access to your bank account, your email inbox, or files in cloud storage. You only enter the information you want RecorIt to keep.
Export & deletion
You can export supported tracker data when available, and delete any tracker you no longer want. Deleting a tracker removes its records.
Reporting a concern
Found a security issue? Please email support@recorit.com and we'll look into it.