Trust Center

Your posts, credentials and audience — handled with care.

This page is maintained by the PlanSched team to answer common security and privacy questions. It is not an independent certification.

Encryption everywhere

TLS 1.2+ in transit. AES-256-GCM at rest for connected social tokens using a per-project key.

Row-level security

Every table in our database is protected by row-level policies scoped to the authenticated user and workspace.

OAuth-based access

We use official platform OAuth flows. We never ask for or store your social platform passwords.

Hardened runtime

Server functions run on an isolated edge runtime with least-privilege service credentials — not shared VMs.

Role-based access

Owner, Admin, Editor, Approver and Viewer roles let agencies scope access per team member and per workspace.

Audit-ready logs

Publishing attempts, approvals, and API key usage are logged for accountability.

Incident response

Security contact reachable at security@plansched.com. We acknowledge reports within one business day.

Data portability

Export your posts, media and analytics on request. Delete your account and we remove your data within 30 days.

Shared responsibility

PlanSched secures the platform. Your workspace admins control who is invited, which roles they hold, and which social accounts are connected. Rotate revoked tokens promptly and use strong passwords for your PlanSched login.

What we never do

  • • Sell or share your content or audience data.
  • • Post on your behalf without a scheduled or approved action.
  • • Store social platform passwords — we use OAuth tokens only.
  • • Send marketing email to your followers or leads.

Subprocessors

Vendors that may process data on our behalf to deliver the service.

ProviderPurpose
Lovable Cloud (Supabase)Managed Postgres, auth, storage
CloudflareDNS, CDN, DDoS protection, edge runtime
Meta Graph APIFacebook, Instagram, Threads publishing
X (Twitter) APIPost publishing and analytics
LinkedIn APIPersonal and Company Page publishing
Google (YouTube API)YouTube Shorts and video publishing
TikTok APITikTok publishing and insights
Lovable AI GatewayCaption assistance and brand-voice models

Report a vulnerability

Found a security issue? Email security@plansched.com with steps to reproduce. We acknowledge every report within one business day and credit researchers who ask to be named.