Account and security
Where is my data stored?
In the EU, and the application is served from the same region. Row-level security means one account cannot read another's data, and it is enforced in the database itself rather than in application code. The Privacy Policy carries the full processor register, naming each provider and where it stores what.
Third-party tokens are encrypted at rest and only ever decrypted server side at the moment of a call; they are never logged and never sent to a browser. Inside your account, access follows your team's roles: an Analyst reads, an Owner and an Admin write.
Did this answer it? If not, a person who knows the product will.