This page is maintained by the JokeDADAbase.ai team to answer common questions about how the app protects your account and your clips. It describes the app-visible controls we have in place today — it is not an independent audit or certification.
Where clips live by default
Every capture starts on your device. Nothing leaves your phone or laptop unless you explicitly tap Back up to cloud. Signed-out and free users never upload clips.
Cloud vault (Pro only)
When you back up a clip, it is uploaded over TLS to a private storage bucket. Files are encrypted at rest by our storage provider using AES-256. The bucket has no public URLs — direct access is blocked.
Playback uses short-lived signed URLs (1 hour for video, 6 hours for posters). URLs are issued only to your authenticated session and expire on their own.
Sharing links
Share links you create are time-limited and use an unguessable slug. Anyone with the link can watch until it expires — treat share links like a house key and only send them to people you trust.
Access control
Row-level security policies scope every read and write to your account. Admin/service credentials are used only for verified webhooks and maintenance, never for ordinary reads.
You can wipe every cloud clip from your account at any time from Your account.
Retention
If your Pro subscription lapses, cloud clips remain viewable for 30 days and then are permanently deleted by a nightly job. We'll email you before anything is deleted, and you can download them from your vault before that window closes.
What we do not claim
JokeDADAbase.ai is not HIPAA, SOC 2, or PCI certified, and we do not claim end-to-end encryption today — our servers can technically decrypt your clips to serve them back to you. If E2EE is important for your family, keep clips on-device.
Report a security issue
Please email security@jokedadabase.aiwith details. We'll respond quickly and won't take action against good-faith reports.