Last updated 15 September 2026
Security
Report a vulnerability
If you believe you've found a security issue in Limechop, email security@limechop.com. We acknowledge reports within 3 working days, keep you informed, and don't take legal action against good-faith research that avoids harming users or data. Please don't test against other people's accounts or run automated scans against production.
How Limechop is built
- Meta access tokens are encrypted at rest with AES-256-GCM; the key lives only on the application server, never in the database.
- Tokens are never displayed after you connect, and are deleted on disconnect, on account deletion, or after 90 days without use.
- All traffic uses TLS. The application runs on servers in Germany (Hetzner); the database is hosted in the EU (Supabase).
- Limechop can only create paused ads. It has no code path that activates an ad or changes the budget of a running one.
- Access to production is limited to the founders and logged.