Safety & Security

Last updated: June 10, 2026

How We Protect Your Data

  • Encryption — all traffic is encrypted in transit with TLS, and your data is encrypted at rest by our infrastructure providers
  • Tenant isolation — database row-level security policies ensure your dynasty data is only accessible from your authenticated account
  • Authentication — sign-in uses magic links or Google OAuth through Supabase; we never see or store a password for you
  • Payments — handled entirely by Stripe, a PCI DSS Level 1 certified processor; your card number never touches our servers
  • Infrastructure — we run on Google Cloud Platform and Supabase, with access to production systems limited to the founding team
  • Monitoring — automated error and anomaly monitoring helps us detect and respond to issues quickly
  • Screenshot handling — uploads are stored securely and used to power your dynasty and to improve the Service (including our AI extraction models); when you delete your account, they are deleted as described in our Privacy Policy

For details on what data we collect and how we use it, see our Privacy Policy.

Keeping Your Account Safe

  • Use an email account with strong security (a good password and two-factor authentication) — your email is the key to your Dynasty Central sign-in
  • Do not share magic link emails with anyone; a valid link grants access to your account
  • You can revoke Dynasty Central's access to your Google account at any time from your Google Account permissions page
  • If you suspect unauthorized access to your account, contact us immediately

Reporting a Vulnerability

If you discover a security vulnerability in Dynasty Central, we want to hear about it — and we appreciate responsible disclosure. Email infodynastycentral.gg with the subject line "Security" and include steps to reproduce the issue. We will acknowledge your report promptly, keep you informed as we investigate, and credit you for the find if you would like.

When testing, please act in good faith:

  • Do not access, modify, or delete data belonging to other users — use your own test accounts
  • Do not run denial-of-service tests or automated scanners against production
  • Give us reasonable time to fix the issue before disclosing it publicly

We will not pursue action against researchers who follow these guidelines and report in good faith.

Incident Response

If we become aware of a security incident affecting your personal data, we will investigate, contain it, and notify affected users as required by applicable law.