Trust
Trust & security
Last updated July 2026
This page is maintained by the TodayPlanr team to answer common security and privacy questions about TodayPlanr. It describes our current practices and the platform features we have enabled. It is not a certification, an audit result, or an independent assessment.
Shared responsibility
TodayPlanr runs on the Lovable Cloud platform, which provides hosting, the managed database, and authentication infrastructure. We are responsible for how the app is configured, what data it collects, and how access rules are written. You are responsible for keeping access to your email inbox secure, since sign-in links are delivered there.
Sign-in and access
Accounts sign in with an emailed magic link or with Apple. We do not ask for or store a password. Sessions are issued by the managed auth service and can be ended by signing out. Signing in is optional — you can build a DayDeck as a guest without an account.
Data access rules
Every table that stores account data has row-level access rules enabled, so a signed-in account can read and write only its own rows. Server-side operations that need broader access run in our backend code, never in the browser.
Where your data lives
TodayPlanr is local-first. Guest planning data stays in your browser. If you create an account, eligible planning data syncs to our hosted database over HTTPS so it follows you across devices. Full detail is on the Privacy page.
Subprocessors and integrations
We use Lovable Cloud for hosting, database, and authentication; Stripe for membership payments; Anthropic for the optional Capacity Coach; and Meta for advertising measurement when you arrive from a Meta ad. We add subprocessors only when a feature requires one.
Payments
Card details are entered on Stripe’s systems and never reach ours. We store only the customer reference and subscription status needed to keep your membership active.
AI processing
The Capacity Coach is optional. If you use it, the sentence or two you write is sent to Anthropic, which returns suggested DayScan ratings. We do not save that text to your account and we do not use it to train models. The five-question DayScan works entirely without AI.
Retention and deletion
You can request a copy of your account data, or ask us to delete your account entirely, by emailing hello@todayplanr.com from the address you signed up with. Deleting an account removes your synced planning history, Do Points, and Duty Gallery from our systems. Guest data is removed by clearing your browser storage for this site.
Reporting a security concern
If you believe you have found a vulnerability, email hello@todayplanr.com with the words “security report” in the subject line and enough detail to reproduce the issue. Please do not test against other people’s accounts or data. We aim to acknowledge reports within two business days.
Compliance
TodayPlanr does not currently hold SOC 2, ISO 27001, or similar certifications, and we do not claim regulatory compliance beyond the practices described here. If your organisation needs specific assurances before using TodayPlanr, email us and we will answer honestly about what we can and cannot provide.
