This page is maintained by the PlanSched team to answer common security and privacy questions. It is not an independent certification.
TLS 1.2+ in transit. AES-256-GCM at rest for connected social tokens using a per-project key.
Every table in our database is protected by row-level policies scoped to the authenticated user and workspace.
We use official platform OAuth flows. We never ask for or store your social platform passwords.
Server functions run on an isolated edge runtime with least-privilege service credentials — not shared VMs.
Owner, Admin, Editor, Approver and Viewer roles let agencies scope access per team member and per workspace.
Publishing attempts, approvals, and API key usage are logged for accountability.
Security contact reachable at security@plansched.com. We acknowledge reports within one business day.
Export your posts, media and analytics on request. Delete your account and we remove your data within 30 days.
PlanSched secures the platform. Your workspace admins control who is invited, which roles they hold, and which social accounts are connected. Rotate revoked tokens promptly and use strong passwords for your PlanSched login.
Vendors that may process data on our behalf to deliver the service.
| Provider | Purpose |
|---|---|
| Lovable Cloud (Supabase) | Managed Postgres, auth, storage |
| Cloudflare | DNS, CDN, DDoS protection, edge runtime |
| Meta Graph API | Facebook, Instagram, Threads publishing |
| X (Twitter) API | Post publishing and analytics |
| LinkedIn API | Personal and Company Page publishing |
| Google (YouTube API) | YouTube Shorts and video publishing |
| TikTok API | TikTok publishing and insights |
| Lovable AI Gateway | Caption assistance and brand-voice models |
Found a security issue? Email security@plansched.com with steps to reproduce. We acknowledge every report within one business day and credit researchers who ask to be named.