Security policy
Potlee by QuickGroww · Version 1.0 · Effective 3 October 2026Your saves are private to you. They are protected in transit and at rest, our team cannot view them without your permission, and every permitted view is shown to you. This page sets out exactly how, including the limits.
1Scope and data we hold
- Covers the Potlee WhatsApp number, potlee.app and the earlier address reels.quickgroww.ai.
- What you send: notes, links, photos, documents, voice notes and videos.
- What the service creates from it: transcripts, contact details read from visiting cards, and search indexes.
- Your WhatsApp number, display name and an optional backup email.
2Encryption
- In transit. HTTPS only, with HTTP Strict Transport Security. The SSL Labs report above shows the exact protocol versions and ciphers.
- At rest. Files and backups sit in Cloudflare R2, which encrypts all stored data on disk.
- Per-account keys. The text of each save is encrypted with AES-256-GCM under a key unique to your account. Account keys are protected by a master key in AWS Key Management Service, Mumbai, held in FIPS 140 validated hardware. It cannot be exported, rotates yearly, and every use is logged.
- Files (photos, documents, voice notes, videos) are stored privately with no public address and encrypted at rest by the storage provider. They are not yet encrypted with your account key.
To show, search and transcribe your saves, the service decrypts them in memory for that task only.
Limits. This is not end-to-end encryption: the service itself can decrypt your saves in order to show and search them. Tags, the time and type of each save, and your WhatsApp number are not encrypted with your account key. Preview images copied from public posts are served from a public address. WhatsApp keeps its own copy of messages you send. Saves are sent to OpenAI to transcribe, read cards and power search.
3Access control
- Sign-in uses one-time codes sent to your WhatsApp. A new device triggers an alert, and replying LOGOUT signs out everywhere.
- Saves never appear on staff screens. Support can view an account only after the user turns on Support can see my saves in Settings; each view is recorded and shown to the user.
- Production access is limited to administrators, with two-step sign-in.In progress
4Retention and deletion
| Data | Kept for |
|---|---|
| Saves and files | Until you delete them or your account |
| Raw WhatsApp message copies | 30 days |
| Private disaster-recovery backups (taken every 6 hours) | Every copy from the last 14 days, plus one per month for about 3 months |
| Deleted accounts | Removed from the service at once. Scheduled backups that still hold them age out within about 3 months; a few one-off safety copies taken before system updates are kept until we clear them by hand |
5Service providers
| Provider | Role |
|---|---|
| Meta (WhatsApp Business Platform) | Carries messages to and from the service |
| OpenAI (API) | Transcription, card reading, search by meaning. Not used for model training under their business terms. |
| Railway | Application and database hosting |
| Cloudflare | File storage and network protection |
| Amazon Web Services | Master key management, Mumbai |
| Resend | Sends the confirmation email if you add a backup email |
Providers may process data outside India. We do not sell your data or use it for advertising.
6Testing
Every code change that ships is scanned automatically for exposed credentials, vulnerable dependencies and unsafe code, and the scans run again every week. The independent grades above were checked on 3 October 2026. An external penetration test is planned and will be listed here when complete.
7Incidents
If a security incident affects your data, we will tell you without undue delay and report it to the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires.
8Contact and vulnerability reports
Grievance Officer: Shakti Motani, [email protected]. Security reports go to the same address. We acknowledge within 3 working days and welcome good-faith research. Also published at /.well-known/security.txt.
What this means day to day — who opened your saves, downloading your data, deleting your account — is on the Privacy page.