Trust, Security & Privacy at GroupVeto

This page is maintained by GroupVeto to answer common security and privacy questions about how the app handles your group's data. It reflects current, app-visible controls — not an independent certification.

100% Account-Free

Guests join a room with a code — no email, no password, no social profile required. We never request or store login credentials for participants.

Anonymous Canvas

Availability picks, budget caps, and vetoes are tied to ephemeral room participant tokens — not a permanent identity. The group only sees aggregated totals, never who voted for what.

Secure Infrastructure

Every table uses Row-Level Security. The server resolves the active participant from the authenticated session (auth.uid()) — clients can't impersonate other members. Admin RPCs are revoked from public roles.

Shared responsibility

GroupVeto secures the platform: encrypted transport, row-level access rules, server-side identity checks, and minimum-necessary data collection. You help by keeping your room codes inside the group chat they were meant for — anyone with a room code can join that room as a participant.