Security
How we protect your data
A plain-English summary of how the Lens platform handles security, written for agency due-diligence. The full detail, including legal bases, retention periods and your rights, lives in our Privacy Policy.
Read-only by design
Lens connects to advertising and analytics accounts with read-only OAuth scopes wherever the provider offers them. It never creates, edits, pauses or deletes anything in a connected account.
Encrypted token storage
OAuth refresh tokens are encrypted at rest with AES-256-GCM using a per-deployment key. Plaintext tokens are never stored.
Encryption in transit
All traffic between your browser, Lens, and connected providers is encrypted with TLS 1.2 or higher.
Tenant isolation
Lens enforces row-level access control. An agency can only ever see its own data and its own clients' workspaces.
Disconnect any time
OAuth tokens are deleted immediately when you disconnect a data source, and account data is deleted within 30 days of an account-deletion request.
Google Limited Use
Use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data is used solely to display reporting in your own workspace.
Certifications
We do not currently hold SOC 2 or ISO 27001 certification and will update this page if that changes. We would rather tell you that plainly than imply otherwise.
Sub-processors
We use the following providers, each under a data-processing agreement. Cross-border transfers rely on the UK International Data Transfer Agreement and EU Standard Contractual Clauses.
| Provider | Purpose | Region |
|---|---|---|
| Clerk | Authentication | USA |
| Convex | Application database, encrypted token storage | USA |
| Tinybird | Analytics metrics store | EU (London) |
| Stripe | Billing | USA / UK |
| Vercel | Web hosting | USA / global edge |
| Sentry | Error monitoring | USA |
| Google (Ads / GA4 / YouTube APIs) | Data sources | USA |
| Data source | USA / Ireland | |
| Meta Platforms | Data source | USA / Ireland |
| TikTok / ByteDance | Data source | USA / EU |
Reporting a vulnerability
Found something? Email privacy@splitlight.co.uk or see security.txt. We read everything and respond quickly.