Last updated: August 5, 2026
This page explains, in plain language, how we protect your data — and where the honest limits are. If you're evaluating Cadento for a brand you don't personally own, or you're a partner reviewing us on someone else's behalf, this is written for you.
Cadento is a marketing calendar for DTC brands. It connects to your existing tools via read-only OAuth — we don't connect to raw email inboxes (like Gmail or Outlook). The integrations we support:
We never receive or store passwords for any of these services. OAuth handles authentication, and access can be revoked at any time from the third-party service or from your Cadento settings.
Every database query is scoped by user ID at the query layer. Users cannot see each other's campaigns, tokens, or account information. Our API endpoints authenticate every request and reject any attempt to read another user's data.
We request the smallest OAuth scopes needed to make Cadento work:
accounts:read campaigns:read templates:readfile_content:readWe can't send emails, modify campaigns, or write to any connected account.
| Data | Location | Protection |
|---|---|---|
| Account & campaign data | Neon (Postgres) US East (AWS) | Encrypted at rest + in transit |
| OAuth tokens | Neon (Postgres) US East (AWS) | AES-256-GCM + at rest encryption |
| Email screenshots | ScreenshotOne CDN Cached 30 days | HTTPS in transit |
| Backups | Neon automated backups Retained 7 days | Encrypted at rest |
All infrastructure is US-based. We do not currently offer EU data residency.
We use vendors for hosting, storage, and rendering. Each has their own security posture and privacy policy:
Full vendor list and a signable DPA are available on the DPA page.
We're a small, focused company. Here's where we are honestly, so you can make an informed decision:
We'd rather be upfront about all of this than let you find out later.
If we discover a security incident that affects your data, we'll notify you by email within 72 hours of confirming impact, with what we know, what we're doing, and what — if anything — you should do.
Found something? Please email hello@cadento.co with details. We'll acknowledge within one business day and work to resolve promptly. We don't currently run a paid bounty program, but we'll credit responsible disclosures on request.
If you're a partner or brand reviewing us and you have specific security questions, email hello@cadento.co and we'll answer them directly. We'd rather have the conversation than have you guess.
Related: Privacy Policy · Terms of Service · Data Processing Agreement