Trust & Security
This page is maintained by the Planpaste team to answer common security and privacy questions about Planpaste. It describes the controls currently in place; it is not an independent certification or audit.
Authentication & access
- Accounts are protected with email/password or Google sign-in.
- Sessions are managed by our authentication provider with short-lived access tokens.
- Every request to your data is authorized server-side as the signed-in user.
Your data
- We store the chat text you paste, the tasks we extract from it, and any reminders you set.
- Row-level security policies on our database scope every row to the user who created it. Other users cannot read or modify your sessions, tasks, or reminders.
- You can delete any session, task, or reminder from the app, and the underlying records are removed.
Platform & hosting
- Planpaste runs on Lovable Cloud. Traffic is served over HTTPS, and data at rest is encrypted by the underlying platform.
- AI extraction is performed via the Lovable AI Gateway; pasted text is sent to the model for the sole purpose of extracting tasks for you.
- Internal errors are logged server-side and not exposed to end users.
Reporting a security issue
If you believe you've found a security issue, please email the Planpaste team. We aim to acknowledge reports promptly and will work with you on remediation.
This page reflects current app-level controls and is updated as the product evolves. It is not a certification or audit and does not create any contractual commitments.