Security

Protecting your shelf

Your notes, links, and moments are personal. We design Shelf so your context stays yours — with care at every layer we control.

Our approach

While Shelf is in early access, we focus on the fundamentals: encrypted connections in transit, least-privilege access to production systems, and careful handling of waitlist and account data.

  • HTTPS everywhere for the marketing site and future product surfaces
  • Access to customer data limited to people who need it to operate the service
  • Dependencies and infrastructure reviewed as we ship toward launch

What you can expect at launch

As Shelf rolls out on iOS, web, and Mac, we’ll publish clearer detail on authentication, device sync, and how content is stored. This page will grow with the product — not stay a placeholder.

Report a vulnerability

If you believe you’ve found a security issue, please email security@shelf.app with enough detail for us to reproduce it. Please don’t publicly disclose the issue until we’ve had a reasonable chance to investigate and fix it.

General questions? Visit Contact.