Security & data

How you sign in, how the Stripe connection works, and what we store.

Your sign-in

  • Passwords are at least 8 characters.
  • Change password is on Settings → General. This browser stays signed in; other devices need to sign in again. A billing lapse doesn't block this.
  • A Google-only account has no password.
  • Sign out in the sidebar ends only this device.
  • Forgot password? sends a link valid for 30 minutes, usable once. For safety, the confirmation message is always the same, whether the email exists or not.

The Stripe connection

  • churnhook uses Stripe Connect (Standard) with OAuth. You approve access on Stripe's site, and can revoke it there — or disconnect from Settings — at any time.
  • No secret key of your account is ever stored by churnhook.
  • A workspace is bound to one Stripe account. Test and live are that same account, and their data never mixes.

Your data

  • Your customers, subscriptions, survey answers, and recovery runs belong to your workspace alone — every query is isolated by organization.
  • Disconnecting Stripe stops syncing but keeps your already-imported data.

Emails

Recovery emails go out on your brand. The links inside them are churnhook-issued tokens: they open a secure Stripe session only when clicked, never before. Card details are always entered on Stripe, never on churnhook.

Your churnhook subscription

Your churnhook subscription (the €79 + packs plan) runs on a Stripe account fully separate from your connected account. Managing or cancelling it never touches your customers' data.

Security & data — churnhook