Skip to main content

Data & privacy

How BESSMERA handles data today

This page describes the current BESSMERA beta. Accounts and personal-plan sync use Supabase; card payments are not connected yet.

Updated 30 September 2026

What is stored on your device and in your account

Before sign-in, your plan and progress are stored in browser localStorage under the key bessmera-session. After sign-in, BESSMERA syncs the allowed part of that state to your Supabase account while retaining a local copy for the interface.

Synced state can include country, step progress, family context, selected city, saved places, demo-document metadata, deadlines, cases, and contact fields you entered. Paid access is not trusted from the browser: entitlements are stored separately as server-controlled records.

Which cookies are used

The interface stores your selected language in a cookie. After sign-in, Supabase Auth also uses session cookies to maintain authentication across pages.

The current code does not include advertising or behavioural analytics that sends your questionnaire answers to third parties.

Speech through BESSMERA Assist

When neural speech is available and you start it, the phrase text is sent to the BESSMERA server and then to ElevenLabs to generate audio.

The audio response is returned with no-store caching. If neural speech is unavailable, the product may use the device or browser speech engine instead.

Checkout waitlist

If you leave an email in the package reservation form, the request is sent to the BESSMERA server (a webhook or an admin email notification, depending on deployment configuration).

We use that email only to notify you when card checkout opens. Without delivery configured, the request may stay only on your device — the interface will say so.

Accounts, passwords, and payments

Accounts and authentication are handled by Supabase Auth. BESSMERA does not store your password in its profile table. Profile data, synced plan state, and server-controlled entitlements live in a dedicated BESSMERA Supabase project protected by Row Level Security.

Card payments are not connected yet. Analytics events in the code are currently technical stubs: questionnaire answers, documents, message text, and other personal data are not sent anywhere through the analytics function.

How to reset plan and local data

Without sign-in, you can reset the local session in the product or clear site data in your browser. When signed in, “Reset plan” also syncs an empty route to your account.

Self-service account deletion is available under My account. The request deletes the Auth user and cascades related profile, synced-plan, and entitlement records; the local session on that device is also cleared.

What still needs to be added before public accounts and payments

Before broad public launch, BESSMERA must publish the legal entity/data controller, a privacy contact, the complete processor list (including Supabase), and server retention periods. Self-service account deletion is already implemented. Before checkout is enabled, seller details and payment/refund terms are also required.