Security
How we protect things
- Every page is served over HTTPS with strict transport security
- Passwords are stored as one-way hashes and cannot be read back, by us or anyone
- Payment details never touch our servers — checkout happens inside the provider
- Extracted audio is deleted when a transcript completes; prepared downloads expire within hours
- Application code and configuration sit outside the public web folder
- Rate limits protect the sign-in form and the job endpoints against automated abuse
What you can do
Use a password you do not use anywhere else. Sign out on shared machines. Tell us immediately if something looks wrong with your account.
Reporting a vulnerability
If you find a security issue, please report it privately to support@vimagic.in before making it public, and give us reasonable time to fix it. We will not pursue action against researchers who act in good faith, avoid privacy violations and do not degrade the service.