Security
A factual map of safeguards that are present, controls that are not claimed, and responsible reporting.
- Effective
- 2026-08-10
- Last updated
- 2026-08-10
- Version
- 2026-08-10
Implemented safeguards
sexxWise uses Firebase Authentication, HTTP-only server sessions, owner-scoped Firestore rules, server-only writes for sensitive collections, separate Together reveal rules, server-only billing and AI credentials, data minimization, Privacy Mode, Discreet Mode, raw export, and scoped deletion.
App Check
App Check is supported by configuration but no site key is present in the current environment, so sexxWise does not claim active App Check protection.
Controls sexxWise does not claim
sexxWise does not claim end-to-end encryption, zero-knowledge architecture, encrypted private-note fields, perfect security, bank-level or military-grade security, a formal security certification, or an active bug-bounty program.
User security and privacy controls
Users can sign out, use Privacy and Discreet modes, hide Explore navigation, withdraw optional adult-content access, delete scoped data, export raw data, and request account deletion. Sensitive-section reauthentication and session management are not represented as complete until fully wired.
Responsible vulnerability reporting
Send a clear description, affected URL, reproduction steps, and impact to support@sexxwise.com. Do not access another person's data, disrupt the service, use social engineering, publish unresolved sensitive details, or demand a bounty. sexxWise does not promise payment.
Security incidents
sexxWise maintains an internal incident-response draft covering detection, containment, data-category assessment, provider coordination, jurisdiction analysis, notification, documentation, and special handling of health and sexual-wellness data. The operational procedure requires security, privacy, and legal review.