Security
October 8, 2026. What SuppyHQ does, and what it does not.
Stripe
SuppyHQ only reads who paid you. It does not charge, refund, or cancel.
It only accepts a restricted key (rk_). A secret key (sk_) is rejected. A restricted key can still be given write access in Stripe. SuppyHQ does not check that. The connect button asks Stripe for read access only.
Polar
You paste a token. SuppyHQ asks you to grant read access and does not enforce it. Use a read-only token.
Keys
Stripe and Polar keys are encrypted where they are stored. Incoming payment events are checked, and a fake one is dropped.
Your data
Each account's mail and customers live in their own database. Mail in and out goes through Postmark. The app only runs over HTTPS.
It runs on one Hetzner server, with Cloudflare in front. Backups run every 6 hours, encrypted, and are kept for 30 days.
Delete the account from settings. Conversations and files are wiped 15 days later. The address is retired, so nobody else can take it. Cancel any time before the wipe. You can export everything first.
AI
Summaries, suggested replies and spam sorting run through OpenRouter. It only uses AI providers that keep no copy of what they see and never train on it. TypeSafe sorts first-time senders and flags urgent mail. Each one only sees what its task needs. AI never sends on its own: agents start with read and draft, sending is a separate permission you turn on, and every send waits 30 seconds so you can cancel it. AI-sent replies are labeled.
Report a problem
Email karloscodes@suppyhq.com.
What this is not
- No SOC 2.
- No self-hosted version.