Neron App Studio
Security

How we protect your data

Specific practices, not promises. Last updated: September 3, 2026.

Encrypted in transit

Every request to our sites and APIs travels over HTTPS. Plain HTTP is redirected, never served.

No client-side reads

Our database rules deny read, update and delete to every browser client. Those paths exist only on the backend.

Validation at the data layer

Writes are checked by the database itself — not just the app. Malformed input is rejected before it is stored.

We never see your card

Purchases are handled by Apple and Google. Card numbers and billing addresses never reach our systems.

Database access control

Our Firestore security rules are written deny-first. For the newsletter collection, browser clients may only create a record; read, update and delete are denied outright and happen only through server-side code. A leaked client key therefore cannot be used to read our data.

Input validation

Validation runs in the database rules, so it cannot be bypassed by calling the API directly: email addresses must match an address pattern, the source application must be identified, and a write is rejected unless every field is on an explicit allow-list. Unknown fields are refused rather than silently stored.

Authentication

Several of our apps use anonymous authentication: you get an account identifier without giving us a name, an email address or a password. Where an app offers cloud sync, signing in is optional and the app remains fully usable without it.

Payments

In-app purchases and subscriptions are processed by the App Store and Google Play through RevenueCat. We receive a purchase confirmation — never payment credentials. There is no card data in our systems to lose.

Diagnostics

Crash reports and usage analytics are collected through Firebase and are anonymised. They describe what the software did, not who you are.

What this page does not claim

We are a small studio. We do not hold SOC 2 or ISO 27001 certification, and we do not run a paid bug-bounty programme. We would rather tell you that plainly than imply a level of assurance we have not been audited for.

Reporting a vulnerability

If you find a security issue, email [email protected] with steps to reproduce it. Please give us a reasonable window to fix the issue before disclosing it publicly. We will confirm receipt and tell you what we found.

Your pathway

The cells you wired together, in the order you wired them. Make it a slide and you get one code per app, ready to scan or send.

Nothing wired yet. Open a cell and choose “Wire it into my pathway”.