Security
Last updated October 8, 2026
How we handle your key, your manage link and your data.
Read-only keys
- Stripe: we accept only live restricted keys (
rk_live_). Full secret keys, publishable keys and test keys are refused before they leave your browser. - RevenueCat, Paddle, Polar, Dodo Payments, Creem and Whop: the guide on the add page walks you through creating a key with read access only.
- Lemon Squeezy: its keys can't be limited to read-only. We only ever use the key to read.
- When you add a key we check right away that it can read your revenue. We can't always tell from a key whether it could also make changes, so please create a read-only one where your provider offers it. We never move money, issue refunds or change anything in your account.
How your key is stored
- Encrypted (AES-256-GCM) before it's stored, and only ever decrypted on our servers to read revenue.
- Never sent back to your browser. Your manage page shows only its last four characters.
Your manage link
- A long random token. We store only its hash, so we can't look it up or send it to you again.
- Anyone with the link can edit or delete your startup, so keep it private.
- Lost it? Recover it with a read-only key from the same payment account: you get a new link and the old one stops working.
The rest of your data
- The database can't be reached from the browser; only our servers read and write it.
- For the recovery page's rate limit we store a hash of your IP address, never the address itself.
- Your card, startup details and the revenue metrics on the card are public. See the Privacy Policy for everything we collect.
Revoking access
Delete the key in your provider's dashboard at any time; your card then stops updating. To remove your startup and everything we store about it, use Delete on your manage page.
Reporting a problem
Found a security issue? Email hi@slabbedmrr.com. Please give us a chance to fix it before sharing it publicly.