Security policy

Potlee by QuickGroww · Version 1.0 · Effective 3 October 2026

Your saves are private to you. They are protected in transit and at rest, our team cannot view them without your permission, and every permitted view is shown to you. This page sets out exactly how, including the limits.

1Scope and data we hold

  • Covers the Potlee WhatsApp number, potlee.app and the earlier address reels.quickgroww.ai.
  • What you send: notes, links, photos, documents, voice notes and videos.
  • What the service creates from it: transcripts, contact details read from visiting cards, and search indexes.
  • Your WhatsApp number, display name and an optional backup email.

2Encryption

  • In transit. HTTPS only, with HTTP Strict Transport Security. The SSL Labs report above shows the exact protocol versions and ciphers.
  • At rest. Files and backups sit in Cloudflare R2, which encrypts all stored data on disk.
  • Per-account keys. The text of each save is encrypted with AES-256-GCM under a key unique to your account. Account keys are protected by a master key in AWS Key Management Service, Mumbai, held in FIPS 140 validated hardware. It cannot be exported, rotates yearly, and every use is logged.
  • Files (photos, documents, voice notes, videos) are stored privately with no public address and encrypted at rest by the storage provider. They are not yet encrypted with your account key.

To show, search and transcribe your saves, the service decrypts them in memory for that task only.

Limits. This is not end-to-end encryption: the service itself can decrypt your saves in order to show and search them. Tags, the time and type of each save, and your WhatsApp number are not encrypted with your account key. Preview images copied from public posts are served from a public address. WhatsApp keeps its own copy of messages you send. Saves are sent to OpenAI to transcribe, read cards and power search.

3Access control

  • Sign-in uses one-time codes sent to your WhatsApp. A new device triggers an alert, and replying LOGOUT signs out everywhere.
  • Saves never appear on staff screens. Support can view an account only after the user turns on Support can see my saves in Settings; each view is recorded and shown to the user.
  • Production access is limited to administrators, with two-step sign-in.In progress

4Retention and deletion

DataKept for
Saves and filesUntil you delete them or your account
Raw WhatsApp message copies30 days
Private disaster-recovery backups (taken every 6 hours)Every copy from the last 14 days, plus one per month for about 3 months
Deleted accountsRemoved from the service at once. Scheduled backups that still hold them age out within about 3 months; a few one-off safety copies taken before system updates are kept until we clear them by hand

5Service providers

ProviderRole
Meta (WhatsApp Business Platform)Carries messages to and from the service
OpenAI (API)Transcription, card reading, search by meaning. Not used for model training under their business terms.
RailwayApplication and database hosting
CloudflareFile storage and network protection
Amazon Web ServicesMaster key management, Mumbai
ResendSends the confirmation email if you add a backup email

Providers may process data outside India. We do not sell your data or use it for advertising.

6Testing

Every code change that ships is scanned automatically for exposed credentials, vulnerable dependencies and unsafe code, and the scans run again every week. The independent grades above were checked on 3 October 2026. An external penetration test is planned and will be listed here when complete.

7Incidents

If a security incident affects your data, we will tell you without undue delay and report it to the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires.

8Contact and vulnerability reports

Grievance Officer: Shakti Motani, [email protected]. Security reports go to the same address. We acknowledge within 3 working days and welcome good-faith research. Also published at /.well-known/security.txt.

What this means day to day — who opened your saves, downloading your data, deleting your account — is on the Privacy page.