← Back to BARKULATOR

Security & Compliance

Last Updated: February 24, 2026

At BARKULATOR, we take the security and privacy of your data seriously. This page outlines our security measures, compliance standards, and commitment to protecting your information.

92/100

Overall Cybersecurity Compliance Score

βœ… Compliant with GDPR, CCPA, and international data protection standards

Compliance Standards

πŸ‡ͺπŸ‡Ί GDPR

100%

Full compliance with EU General Data Protection Regulation

πŸ‡ΊπŸ‡Έ CCPA

100%

California Consumer Privacy Act compliant

πŸͺ Cookie Law

100%

ePrivacy Directive & Cookie Consent

Security Measures

πŸ”’

Data Encryption

In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (HTTPS)

At Rest: All data stored in our database is encrypted using AES-256 encryption

πŸ”

Secure Authentication

We use Supabase Auth for secure user authentication with:

  • Password hashing with bcrypt
  • JWT token-based sessions
  • Automatic token refresh
  • Secure cookie storage
πŸ›‘οΈ

Content Security Policy

Our site implements strict Content Security Policy (CSP) headers to prevent:

  • Cross-Site Scripting (XSS) attacks
  • Code injection attacks
  • Unauthorized third-party scripts
πŸ”

Regular Security Audits

We conduct regular security assessments including:

  • Dependency vulnerability scans
  • Code security reviews
  • Penetration testing (when applicable)
  • Compliance audits

Your Privacy Rights

We respect your data privacy rights under GDPR and CCPA:

Right Description How to Exercise
Access View all data we have about you Account settings β†’ Data Management
Rectification Correct inaccurate data Edit your profile directly
Erasure Delete your account and data Account settings β†’ Delete Account
Portability Download your data in JSON format Account settings β†’ Export Data
Object Object to certain data processing Email us at barkulator@gmail.com
βœ… Most privacy rights can be exercised directly from your account settings. No need to email us unless you need assistance.

Data Protection

What We Collect

What We DON'T Collect

How We Protect Your Data

  • πŸ”’ Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • πŸ” Access Control: Strict role-based access, least privilege principle
  • πŸ›‘οΈ Secure Infrastructure: Hosted on Supabase with enterprise-grade security
  • πŸ“ Audit Logs: All data access is logged and monitored
  • πŸ”„ Backups: Regular encrypted backups with 30-day retention

Data Breach Response

In the unlikely event of a data breach, we have a comprehensive response plan:

  1. Detection: Automated monitoring alerts us immediately
  2. Containment: Incident response team activated within 1 hour
  3. Assessment: Scope and impact evaluated
  4. Notification: Affected users notified within 72 hours (GDPR requirement)
  5. Remediation: Vulnerabilities patched and systems secured
  6. Reporting: Supervisory authorities notified if required
⚑ 72-Hour Notification: We comply with GDPR Article 33/34 requirements for breach notification. You will be informed promptly if your data is affected.

Third-Party Services

We use the following trusted third-party services:

Service Purpose Data Shared Privacy Policy
Supabase Database & Authentication Email, dog profiles View Policy
Google Fonts Typography None (no cookies) View Policy
GitHub Pages Hosting IP address (standard web hosting) View Policy

All third-party processors:

Cookie Policy

We use minimal cookies to ensure the service functions properly:

Essential Cookies (Always On)

Optional Cookies (Requires Consent)

Manage Your Preferences: You can change your cookie settings at any time using the Cookie Settings button in the footer.

International Data Transfers

Your data may be transferred to and processed in:

Safeguards in place:

Security Best Practices for Users

πŸ” Protect Your Account:

  • Use a strong, unique password
  • Don't share your login credentials
  • Log out on shared devices
  • Report suspicious activity immediately
  • Keep your email account secure (we send password resets there)

Continuous Improvement

Security is an ongoing process. We continuously:

Bug Bounty: If you discover a security vulnerability, please report it responsibly to barkulator@gmail.com. We appreciate the security research community's help in keeping BARKULATOR safe.

Security Contact

For security concerns, vulnerabilities, or data protection questions:

Email: barkulator@gmail.com
Subject Line: [SECURITY] Your concern here
Response Time: Within 24-48 hours

⚠️ Responsible Disclosure: If you find a security vulnerability, please:
  • Email us privately (do not post publicly)
  • Provide detailed steps to reproduce
  • Give us reasonable time to fix it before disclosure
  • Do not access or modify user data

Additional Resources:

βœ… Your security and privacy are our top priorities.
We're committed to maintaining the highest standards of data protection.