Skip to main content

OnePlanner Security Policy

This policy describes our current security practices and commitments. It is referenced from our Privacy Policy and Terms of Service.

Effective Date: July 29, 2026

1. Scope

We handle sensitive personal and financial data, including Clients' income, debt, insurance, investment, and retirement information entered by Planners. We apply security controls proportionate to that sensitivity.

2. Infrastructure and Data Storage

  • Data is stored in Supabase (managed PostgreSQL), with authentication handled by Supabase Auth.
  • Data in transit is encrypted using TLS.
  • Encryption-at-rest is provided by Supabase's managed infrastructure (AES-256, applied at the storage layer).

3. Access Control

  • Access to the platform is role-based (Owner / Planner / Client) and enforced at two layers: application-level authorization, and database-level Row Level Security (RLS) policies in Supabase/PostgreSQL.
  • RLS policies scope every client-related table so that a record is only readable or writable by: the Client it belongs to, the Planner assigned to that Client, or an Owner of the Planner's firm (via firm-membership records). This model is applied consistently across the platform's client-data tables.
  • We treat access control as an ongoing engineering discipline, not a one-time setup: gaps identified through internal review are tracked and closed as part of regular hardening work, and coverage is extended to new tables as they're introduced.
  • Administrative access to production systems is limited to authorized personnel on a need-to-know basis.
  • Firms are responsible for provisioning and deprovisioning their own Planner accounts promptly when staff join or leave.
  • Multi-factor authentication is available for Planner and Owner accounts.

4. AI Features

Data submitted to AI-assisted features (OpenAI, Google Gemini) is transmitted over encrypted connections to those providers, who act as our subprocessors. We select AI providers whose terms restrict use of submitted data for third-party model training beyond generating the requested output. See our Subprocessors page.

5. Subprocessor Management

We maintain a list of subprocessors on our Subprocessors page and review their security practices before onboarding them. We will provide notice before adding a new subprocessor that will process personal data, consistent with our B2B data processing commitments.

6. Personal Data Breach Response

In line with the PDPA, including the mandatory data breach notification requirement introduced by the PDPA (Amendment) Act 2024, if we become aware of a personal data breach that is likely to result in significant harm to affected individuals:

  • We will assess and contain the incident as soon as practicable.
  • We will notify the Personal Data Protection Commissioner within 72 hours of becoming aware of the breach, as required under the PDPA (Amendment) Act 2024.
  • We will notify the affected Firm(s) without undue delay so they can meet their own notification obligations to Clients and, if applicable, the Commissioner.

7. Data Retention

Client data is retained for as long as the Firm's subscription remains active. Following termination of a Firm's subscription, data is retained for up to 90 days to allow for export or reactivation, after which it is deleted from production systems, subject to any longer retention period required by applicable law.

8. Responsible Disclosure

If you believe you've found a security vulnerability in our systems, please report it to support@oneplannerapp.com. Please do not publicly disclose the issue until we've had a reasonable opportunity to investigate and remediate it. We will not pursue legal action against good-faith security research conducted consistent with this policy.

9. Independent Assurance

We build on infrastructure and service providers that maintain their own independent security certifications (for example, SOC 2 Type II), and we select subprocessors partly on that basis — see our Subprocessors page. Documentation of a specific subprocessor's certifications, or of our data processing agreement with them, can be provided to Firms on request at support@oneplannerapp.com.

10. Changes to This Policy

We will update the "Effective Date" above when this policy changes materially.

11. Contact

Security contact: support@oneplannerapp.com

Security Policy | OnePlanner | OnePlanner