Security, data and payments — including what we don't have
An AI agent with access to live ad accounts deserves scrutiny, so this section documents how credentials are stored, what data is kept, who processes payments, and which certifications we hold — and which we don't. Every claim here maps to something in the product rather than to a marketing goal.
OAuth tokens are encrypted with AES-256-GCM, the production key fails closed rather than falling back, and every credential is scoped to one organization. What that means in practice.
Every write pauses for human approval, and account state is re-read immediately before a change applies — so an approved-but-aged recommendation can't fire against an account that has since moved.
Which data lives in our systems, which is fetched on demand and never persisted, how organizations are isolated, and what actually gets deleted when you ask.
Subscriptions run through Clerk Billing and one-time credit top-ups through Stripe Checkout. Card details are entered on their hosted pages — we never see or store them.
The infrastructure, authentication, payment and model providers Agent Planners depends on, and what each one handles.
An honest statement of Agent Planners' compliance position — the data-subject rights we support and the platform requirements we meet, plus the certifications we do not currently hold.