Security
On-device work does not upload the photo. Cloud uploads go to private object storage with a signed link, then expire: one hour signed out, 24 hours on an account, or sooner if you delete them.
The browser session cookie is httpOnly and signed. Payment webhooks are verified with the provider’s signature before any credit is granted. Access keys are stored securely and never exposed to the browser.
This page is an engineering description, not a penetration test. Do not send vulnerability reports to a personal inbox; use support@enhancerpro.ai.