Security and trust

How Modou protects your connected business data

Modou connects to business tools through scoped authorisation, keeps customer data separated by account, encrypts traffic and stored platform data, and requires approval for actions that another person can see. Customers control their connections and can request deletion of their data.

Reviewed 22 July 2026

Authentication and permissions

Accounts use Supabase authentication. Tool connections use OAuth or a customer supplied credential where required. Modou receives only the permissions accepted during connection, and credentials are never displayed in the browser after they are saved.

Encryption and separation

Traffic uses HTTPS. Platform data stored in Supabase is encrypted at rest. Row level security and customer identifiers keep one account from reading another account's rows.

Approvals and activity records

Messages, posts and other actions visible to third parties are proposed first. Approved and executed actions are recorded so the customer can review what happened.

AI model processing

Modou currently uses Google Gemini through Vertex AI. Relevant task context may be sent to the model to produce an answer or plan. Customer prompts and tool data are not used by Modou to train a shared model.

Data location

The production database is hosted by Supabase in the European Union. AI processing may use Google's global infrastructure, so Modou does not claim that every AI operation remains inside the European Union.

Deletion and limitations

Customers can disconnect tools and delete their account. No online service can promise zero risk. If a connection expires or a provider fails, Modou pauses or reports the problem instead of claiming the action succeeded.

Report a security concern

Send security questions or responsible disclosure reports to hi@modou.io. Include the affected page or feature and enough detail for us to reproduce the issue.