Help
Security and privacy
How Buildliy protects your account, your projects and your app's data, who owns what you build, and how to report a security problem.
You're trusting Buildliy with your ideas, your code and, once your app is live, your customers' data. This page explains in plain English how each of those is protected, what Buildliy can and can't see, and what you can do to keep things safe.
For the full legal details, read the privacy policy and the security page.
Protect your Buildliy account
Your Buildliy account controls your apps, your domains and any payouts, so it's worth a few minutes to lock it down.
Ways to sign in
You can sign in with an email and password, or with Continue with Google or Continue with GitHub. If you sign up with an email and password, you confirm your email address before you can sign in. Passwords must be at least 8 characters, and Buildliy stores only a scrambled (one-way hashed) version, so nobody can read it.
To see which methods are linked to your account, open Settings → Security and look under Sign-in methods. To add another one, sign out, then sign back in with that method using the same email address. It links up automatically.
Turn on two-step sign-in
Two-step sign-in asks for a code from an authenticator app (such as Google Authenticator, 1Password or Authy) after your password. Someone who learns your password still can't get in.
Start setup
Open Settings → Security and click Set up two-step sign-in.
Scan the code
Open your authenticator app and scan the QR code. If you can't scan it, type the key shown under it into the app instead.
Confirm it works
Type the 6-digit code your app shows and click Turn on.
Save your backup codes
Buildliy shows 10 backup codes, once. Click Copy or Download, keep them somewhere safe like a password manager, then click I've saved them.
Each backup code gets you in once if you lose your phone. Using one turns two-step sign-in off, so you can set it up again on a new phone. You can get a fresh set at any time with Get new backup codes (your old ones stop working).
If you lose your phone and your backup codes, email support@buildliy.com from your account's email address.
Other account protections
- Sign out of every device. In Settings → Security, under Active sessions, click Sign out of every device if you think someone else has access. You'll need to sign in again everywhere, including on this device.
- Change your password in Settings → Security, or use Email me a reset link.
- Sensitive actions ask you to confirm it's you. Downloading your data or deleting your account asks for your authenticator code (or, without two-step sign-in, a fresh sign-in) unless you've done that in the last 10 minutes.
Who can see your projects
Your projects are visible only to you, any teammates you invite to your team, and Buildliy admins when it's needed for support, billing or safety. Admins use tools built for fixing problems and handling support, such as reviewing a failed build and the prompt behind it. Admin actions such as refunds are logged.
Two things are open to anyone who has the link:
- Your preview. Don't put real customer data or private information into an app you're still testing unless you're comfortable with that.
- Your published app. That's the point of publishing. If you want to limit who can see it, see Password protection.
Your prompts and the code Buildliy generates are never used to train AI models.
Your app's data
When your app saves information, such as sign-ups, orders or messages, it's stored in your app's own database on your behalf. Several layers help keep that data safe.
Keeping each person's data apart
When your app has accounts, the AI builds it so that anything a person saves is linked to them, and your app's server code checks who is signed in before it reads or saves it. In a new app on Buildliy hosting, the database enforces this too: your app connects with a restricted login, and the database only shows each person their own rows, even if a page forgets to check. In apps made earlier, that protection is only in the app's code, so it relies on every page doing the check. The launch checklist reminds you of this with Each person's data is kept apart by your app's code, a suggestion that doesn't stop you from publishing. Before you publish, the safety check (below) looks for pages and data links that show people's details to the wrong people, and blocks publishing when it's sure it found one.
Keys and secrets stay on the server
Keys your app needs, like a payment or email service key, are stored as secrets in Manage → Secrets. They're encrypted when stored, kept out of your app's code, and handed to your app's server when it runs. A key you type into a chat card never appears in the chat or your app's code. If a key does end up in code that visitors' browsers download, the launch checklist blocks publishing (see below). Keys for connectors are kept encrypted too, and every key is checked with the service before it's saved (if the service can't be reached right then, it's saved and marked as not checked yet). See Secrets and API keys.
Publishing is blocked for critical problems
The launch checklist runs before every publish. Most items are advice, but critical problems block publishing until they're fixed, including:
- A private key that's visible in your app's code.
- Sign-in missing when your plan says people sign in.
- Private data from a connected account (such as your accounting books or staff records) shown in an app with no sign-in.
- A build that can't run, or no homepage.
- Serious findings from the safety check below, such as a page that shows people's details to anyone.
Some older apps, made on Buildliy's earlier database setup, also get data-access checks on their tables (Unprotected tables, Row-level security not tested and Data access check failed) that block publishing until they pass. These don't apply to new apps.
In the Publish dialog, blockers show as Serious items in the Safety check before publishing card, and hovering over Publish shows how many issues are left to fix.
The safety check before publishing
When you click Publish, the dialog also runs a Safety check before publishing. It reads your app's code for ways it could be misused and, while your preview is running, also opens your app's data links without signing in, the way a stranger would. It reports things like:
- "Anyone can see …" or "Any signed-in account can read …" someone else's details
- "Someone could change a price before paying"
- "Anyone can download people's details from" one of your pages
- "Your AI feature could run up your … bill"
Each problem is marked Serious or Worth fixing, with Details and a Fix button. When the check is sure about a data problem, it's serious; when it's less sure, it's worth fixing. Serious problems must be fixed before you can publish; the others are optional. Fixes are made by the AI as a normal build, so they use credits.
The AI asks before sensitive steps
Some changes have real consequences for your customers, your money or your data: making a list public, removing a sign-in check, emailing everyone, taking real payments, or deleting a lot of something. Before the AI makes a change like this, it stops and shows a card with a question such as "Turn off your app's sign-in rules?" The card explains What happens, Who it affects, Can it be undone? and the Cost, and gives you three choices: keep things safe, Do it differently…, or go ahead.
You can choose how often the AI asks. Open Workspace → Knowledge and find How careful should I be?:
| Setting | When the AI asks first |
|---|---|
| Ask about anything touching customers, money or data (recommended) | Before showing people's details to visitors, removing a sign-in, emailing your whole list or taking real payments. |
| Only ask about big, hard-to-undo things | Making data public, real payments, emailing everyone and removing big parts of a page. Smaller changes get a heads-up instead. |
| Ask before every change I flag | Including small ones. Bigger changes, like new pages or saved data, also get a plan to approve first. |
The setting applies from your next build. Only the project owner or an Admin on the team can change it.
When a website tries to trick the AI
While it builds, the AI sometimes reads web pages, search results or files you attach. Some of these contain hidden instructions aimed at AI tools. When Buildliy spots them, the AI is told to ignore them and you see a line in the chat such as "A page I read had instructions for AI tools. I ignored them."
Your code and data belong to you
You own the prompts you write and the code Buildliy generates for you. You can take it with you at any time:
- Download your app's code as a ZIP from the Code tab. See View and download code.
- Send it to your own GitHub account. See GitHub.
- Get a copy of your whole account (every project's plan, notes and latest code, your chats, credit history, domains and connected services) from Settings → Danger zone → Email me my data. Buildliy emails you a link that works for 7 days. Keys and passwords are never included.
When you delete a project, it's permanent: within 24 hours its chat history and database are removed and its published app goes offline. Files uploaded to it or generated for it, such as images, stay in storage until you ask for them to be deleted. To delete your whole account, use Settings → Danger zone → Delete account. You get 30 days to change your mind, and your apps keep running until then.
For data requests, such as a copy of everything or deletion, you can also email privacy@buildliy.com.
Certifications
Buildliy itself doesn't hold a security certification such as SOC 2. The infrastructure providers it runs on maintain SOC 2 Type II reports. Your data, including data from customers in the EU, may be processed in the United States. If you have specific compliance requirements, get in touch.
Report a security problem
If you think you've found a security issue in Buildliy, email security@buildliy.com. The team aims to acknowledge reports within 24 hours and to triage them within 72 hours. There's no paid bug bounty yet.
To report an app built on Buildliy that's a scam, asks for passwords it shouldn't, spreads malware or pretends to be another company, use the Report an app form, or email abuse@buildliy.com. See Get help.
Related
Still stuck? Read the FAQ or contact us.