Security

What this desk holds, and where.

Your account is on our server. Your list is not. Signing in creates an account — name, email, and a password we store only as a salted hash, never as text. The instruments you type, the briefs, the notes: those live in this browser’s own storage and are never transmitted to us.

That split is deliberate. We need an account to know which plan you are on. We do not need your renewal list, so we do not take it, and a breach of our server would not expose it.

The consequence is yours to manage: clearing this browser’s site data deletes the desk, and we hold no copy to restore. Take a backup from the Instruments page and keep it where you keep contracts.

What we never ask for. We do not connect to your bank and we do not pull transactions. We never ask for your Adobe, Figma or registrar passwords. CSV paste is the batch path, so you decide exactly what leaves your machine.

Payment. Checkout happens on Stripe. Card numbers are never collected on Noticewin pages and never reach our server; we receive the fact of payment and the email address you paid with.

How the site is served. HTTPS only, with HSTS. A Content-Security-Policy that allows scripts, styles, fonts and images from this origin alone — the typefaces are served from this domain, not a font host, and there are no third-party tags. The session cookie is HttpOnly, Secure and __Host- prefixed, so a neighbouring subdomain cannot set or read it. The app refuses to be framed.

Reporting a problem. If you find a security issue, write to hello@houseflax.com. Tell us what you found and how to reproduce it. We will confirm receipt within two working days and tell you what we are doing about it. Please give us a reasonable window to fix it before publishing, and do not access anyone else’s data while testing.

House Flax — Italy, VAT-ID 12786200969. A future bank connection, if we ever ship one, will be announced as a new thing — it is not here now.