Security and privacy

Last updated: September 26, 2026

We built Plannerr with security and privacy from the start. These are the practices we apply to protect the data of businesses and their customers.

1. Per-business isolation

Each business is an isolated space. Every operation requires a business context, and the system denies by default any access without one.

2. Encryption

All traffic uses HTTPS/TLS. WhatsApp access tokens are stored encrypted and are never exposed to the browser.

3. Authentication and least privilege

Dashboard access uses a dedicated authentication provider and per-business roles (owner and employee). The AI assistant runs with short-lived credentials and can only read or change the appointments of the customer it is talking to.

4. Data minimization

We only process the data needed to operate the service and do not use it to train AI models.

5. Traceability

Every request gets a unique identifier logged together with the business and the actor, which allows auditing and incident investigation.

6. Providers

We use established infrastructure providers. The full list is in the Privacy Policy.

See providers →

7. Incidents

We maintain processes to identify, contain, investigate and notify security incidents to affected businesses and, where applicable, to authorities and Meta.

8. Report a vulnerability

If you find a vulnerability, email support@3alphaia.com. Please do not disclose it publicly until we have fixed it.

9. Certifications

We do not claim certifications such as SOC 2, HIPAA or ISO 27001 unless expressly stated in writing.