Security & privacy

Practise in private

Suave is a place to be a little vulnerable. Here's plainly how we protect what you practise.

Encrypted in transit

Every request between your browser and Suave is served over HTTPS/TLS. Your conversations are never sent in the clear.

Passwords are hashed

We store a bcrypt hash of your password, never the password itself. Sessions use signed, HTTP-only cookies.

Private by default

Your practice conversations are tied to your account and are never sold, shared, or shown to anyone else.

Reputable infrastructure

The app runs on managed cloud hosting and a managed Postgres database. AI responses are generated by established model providers under their data terms.

Delete anytime

Deleting your account removes your profile, your conversations, and your credit history from our database — for good.

Honest about where we are

Suave is a young product. We follow the sensible security practices above, but we don't claim formal certifications or audits we haven't completed — and we won't display badges we haven't earned. As we grow, we'll add stronger controls and say so here when we do.

Found something that looks off? Please email privacy@suave.social and we'll look into it quickly.

See also our Privacy Policy and Cookie Policy.