Security
How we protect your account and your data.
Encryption
- Data encrypted at rest by our database provider (AES-256).
- All traffic encrypted in transit (TLS 1.3).
- HTTP Strict Transport Security (HSTS) enforced, with preload.
- Row-level security policies protect user data tables so accounts can only access their own records.
Authentication
- Optional two-factor authentication (TOTP).
- Passwords require at least 8 characters and are stored only as secure hashes.
- Rate limiting on authentication endpoints.
- Bot protection on sign-in and sign-up via Cloudflare Turnstile.
- Signed, expiring tokens for shared plan links.
Privacy
- No third-party ad tracking (no Google Analytics, no advertising pixels).
- No targeted advertising and no sale of personal data.
- Global Privacy Control (GPC) signals honored.
- We do not train AI models on your personal data without your opt-in consent.
Your Data, Your Control
- Self-service data export from your account settings.
- Self-service account deletion; we act on deletion requests promptly.
- The information you enter belongs to you.
Reporting Vulnerabilities
If you discover a security vulnerability, please report it responsibly to security@tag-planner.com. We aim to acknowledge reports promptly and to keep you updated as we investigate and resolve confirmed issues. Please do not access, modify, or delete other users’ data while testing, and give us a reasonable window to fix an issue before disclosing it publicly. We appreciate researchers who help keep our users safe.