Trust & security
Maintained by the PostingPilot team
A plain-language summary of how PostingPilot protects your workspaces, what data we hold, who processes it and how to reach us with questions.
Shared responsibility
PostingPilot runs on the Lovable Cloud platform. Platform-level features such as managed authentication, database row-level security, encrypted connections and hosting are provided by that platform.
PostingPilot, as the app owner, is responsible for how those features are configured: which data is collected, who can see it, how long it is kept and which third parties it is shared with.
You, as the customer, are responsible for the accounts you invite, the API keys you store, the content you publish and the permissions you grant to connected social platforms.
This page is maintained by the PostingPilot team to answer common security and privacy questions. It is a description of current practice, not a certification or an independent audit report.
Access and authentication
Every account signs in through managed authentication with email and password or Google sign-in. Passwords are never stored by PostingPilot.
Application data is separated per user and per workspace using database row-level security, so one workspace cannot read another workspace's posts, voice profiles, metrics or credentials.
Client portals are shared through unguessable, revocable links that expose only the posts and reporting you enable for that portal.
Privileged operations run server-side only. Service credentials are never sent to the browser.
Hosting and platform
The application is served over HTTPS. Application data is stored in a managed Postgres database, and uploaded or generated media is stored in private storage buckets accessed through short-lived signed links.
Server-side logic runs in a serverless runtime. Secrets such as third-party API keys are held in the platform's secret store and injected at runtime rather than committed to source code.
Data we collect
Account data: your email address, display name and workspace settings.
Content data: topics, drafts, posts, voice samples, brand kits, templates, media assets and schedules that you create or import.
Performance data: post metrics and publishing events retrieved from your connected scheduling account.
Product analytics: page views and key in-app events, recorded with a session identifier, referrer, coarse country, device and browser. We do not sell this data or use it for cross-site advertising.
Subprocessors and integrations
Lovable Cloud — application hosting, database, authentication and file storage.
Lovable AI Gateway — routes prompts to the AI models that draft posts, generate images and produce analyses. Prompts include the content you ask us to work on.
Replicate — AI video generation, when you use the video studio.
Stripe — subscription billing and invoices. Card details are handled by Stripe and never reach PostingPilot's servers.
Resend — transactional and authentication email delivery.
Retention and deletion
Workspace content is retained while your account is active so that analytics, recycling and reporting keep working.
Deleting a post, media asset, template or workspace removes it from the application. Deleting your account removes the records tied to it.
Billing records are retained as required for accounting and tax purposes.
To request export or deletion of your data, email the address at the bottom of this page and we will respond within 30 days.
Vulnerability reporting
If you believe you have found a security issue, email us with the details and steps to reproduce. Please do not publicly disclose the issue before we have had a chance to respond.
We will acknowledge reports and keep you updated while we investigate. Please avoid testing that degrades service for other customers or accesses data that is not yours.
Compliance status
PostingPilot does not currently hold SOC 2, ISO 27001 or comparable third-party certification, and this page should not be read as a claim to any of them.
If your procurement process requires a security questionnaire, a data processing agreement or a list of subprocessors in a specific format, contact us and we will work through it with you.
Questions? Email security@fcstudio.us.