You trust us with your customers' reviews, messages and contact details, and with access to the accounts they live in. This page explains how we look after them, in plain terms.
Every account’s data is walled off at the database, and production is checked for gaps in that wall every day.
TLS in transit, encryption at rest, and an extra layer of AES-256-GCM on your platform access tokens.
Our team cannot see your workspace unless you approve it. Access is read-only and expires in 24 hours.
Dinopix runs on established cloud providers rather than servers we manage ourselves. Your data is stored in Supabase on AWS in Singapore, background syncing runs on Railway in Singapore, and our website and app are served by Netlify and Cloudflare. Each provider, what it does and where it operates is listed on our sub-processors page.
Dinopix is a shared platform, so the most important guarantee is that one customer can never see another's data. We enforce that in the database itself, with row-level security on every table that holds customer data, rather than relying on the app to remember to filter.
Within your account, each person has a role (owner, admin, member or client) that controls what they can see and do. The same rules are enforced in the database, the server and the app, so hiding a button is never the only thing standing in the way. Sign-up and sign-in are protected against automated abuse.
On the Enterprise plan, an audit log records who changed what in your account, and you can connect your own systems through our API and webhooks.
Dinopix staff cannot open your workspace by default. If we need to look at something to help you, we send a request that the account owner can approve or decline in Settings. Approved access is read-only, never signs anyone in as you, ends automatically after 24 hours, can be revoked at any time, and is recorded.
AI-drafted replies and sentiment analysis are provided by Anthropic through its commercial API. We send only what is needed to draft or classify the review in front of you. Under Anthropic's commercial terms, that content is not used to train its models.
Your data is backed up daily, encrypted, and kept on a rolling 7-day window. When you delete your account or ask us to, we remove your data from the live service within 30 days, and it ages out of backups after that. Full details are in our Data Processing Agreement.
If a breach affects personal information we hold for you, we will tell you without undue delay and within 72 hours of becoming aware of it, with what happened, what was affected and what we are doing about it. We will also help you meet your own obligations under the Notifiable Data Breaches scheme and the GDPR.
We handle personal information in line with the Australian Privacy Principles and the GDPR. Our Data Processing Agreement applies automatically to every paid subscription, includes the EU Standard Contractual Clauses for international transfers, and commits us to 30 days' notice before adding a sub-processor. See also our Privacy Policy.
Dinopix is not currently SOC 2 or ISO 27001 certified. We would rather tell you that than show a badge we have not earned. If your organisation needs a vendor security review, we are happy to complete your questionnaire and walk your team through how the platform works.
If you believe you have found a security issue in Dinopix, please tell us through our contact page before disclosing it publicly. We will acknowledge your report, keep you updated while we investigate, and will not take action against good-faith research that avoids accessing other customers' data or disrupting the service.
Last updated October 2026. No system is perfectly secure. These measures reduce risk; they do not eliminate it, and we do not claim otherwise.