Back to Fleura

Trust

Security

How player data is protected in Fleura, and how to reach us if you find a weakness.

Last updated 2026-08-19

Infrastructure

  • EU-hosted database, authentication and application hosting.
  • All traffic served over HTTPS; data encrypted in transit and at rest.
  • Automated backups of the database with point-in-time recovery.

Access control

  • Every table with personal data uses row-level rules, so a signed-in player can only reach their own rows and the groups they belong to.
  • Roles are stored separately from profiles, so a player cannot grant themselves admin.
  • Administrative pages are restricted to the account owner and sensitive actions are logged.

Accounts and payments

  • Passwords are hashed by our authentication provider; Fleura never sees them.
  • Email/password and Google sign-in, with email confirmation.
  • Card data is handled entirely by our payment provider — it never touches Fleura.

Reporting a vulnerability

Mail security@playfleura.com with steps to reproduce. Give us reasonable time to fix the issue before publishing, do not access other players' data, and do not run destructive tests. We answer within five working days.