Security Policy

Last updated September 14, 2026

Security & Privacy at a Glance

At CloserGym, keeping your payment details, sales call data, and AI roleplay transcripts private and secure is our top priority. Here is how we protect you:

💳 Card Security

Payments are processed directly by Stripe and PayPal. We never handle or store your raw credit card numbers.

🔒 Private AI & Data

Your roleplays and transcripts are private. We use Google's paid Gemini API, whose terms do not allow your data to be used to train their models.

🛡️ Bank-Grade Encryption

All data in transit is protected with TLS 1.3 encryption, and saved data is encrypted at rest using industry-standard AES-256.

1. Infrastructure & Cloud Provider

CloserGym's applications and databases are hosted on Google Cloud Platform (GCP) and Firebase. We rely on Google’s globally managed cloud infrastructure, which maintains ISO 27001, SOC 1, SOC 2, and SOC 3 certifications to safeguard data availability and physical host security.

2. Encryption Standards

We use industry-standard encryption protocols across all services:

  • Data in Transit (TLS 1.3): All traffic between your browser, our API endpoints, and payment partners is encrypted using Transport Layer Security (TLS 1.2 minimum, defaulting to TLS 1.3).
  • Data at Rest (AES-256): All stored records, including call transcripts, user profiles, and performance metrics, are encrypted at rest using AES-256 encryption.

3. Authentication & Account Controls

User authentication is handled securely via Firebase Authentication, supporting encrypted email/password sign-in and OAuth 2.0 (such as Google Sign-In).

Database access is governed by strict, server-verified security rules that validate authorization tokens on every request. This ensures users can only view, edit, or access their own account data.

4. AI Processing & Privacy

We understand that sales conversations and objection practice contain sensitive business context. We maintain clear boundaries regarding AI data usage:

  • No AI Model Training: Speech processing and roleplay feedback run on Google's paid Gemini API. Under those terms, the prompts and responses sent for your sessions are not used to train Google's models.
  • Ephemeral Voice Audio: Live speech streams are processed in real time and are not retained on disk as raw audio files after the session concludes.
  • Tenant Isolation: Your roleplay sessions, transcripts, and feedback scores belong solely to your account or team workspace.

5. Payment Security & PCI Compliance

Billing is handled directly through Stripe and PayPal. Payment fields are rendered using secure, hosted iFrames provided directly by the payment processor. CloserGym never receives, processes, or stores raw credit card details on our servers.

6. Network Security & Monitoring

Our API gateways employ automated rate limiting and input validation to protect against unauthorized access attempts and brute-force attacks. System logs are monitored to ensure platform reliability and security compliance.

7. Reporting a Security Vulnerability

If you believe you have found a security vulnerability in CloserGym, email support@closergym.com with the subject line "Security vulnerability report". Include the affected page or endpoint, the steps to reproduce it, and what an attacker could do with it.

  • We aim to acknowledge reports within 24 hours and to share a remediation plan once we have confirmed the issue.
  • If a vulnerability is being actively exploited, or a breach affects your personal data, we will notify affected users and the relevant authorities within the timeframes the law requires.
  • We will not pursue legal action against anyone who reports in good faith, avoids accessing or changing other users' data, avoids degrading the service, and gives us reasonable time to fix the issue before disclosing it publicly.

Machine readable contact details are published at /.well-known/security.txt.

8. Reporting Abuse and Removal Requests

Profile photos, display names, and messages are visible to other users. To report a user, use the Report button in any conversation, or email support@closergym.com with the subject line "Content removal request".

If an image or message shows you, or someone you represent, in an intimate or sexual way without consent, including images that were digitally altered or generated, tell us where it appears and we will remove it within 48 hours of receiving a valid request. We will also make reasonable efforts to remove known copies.