Trust
Security at vPlan AR
For IT and vendor reviewers at restoration companies, carriers and firms deciding whether to approve vPlan AR. This page describes how the product works today: where data is hosted, how it is protected in transit and at rest, who can see a project, how accounts, API keys and webhooks are secured, and what we don’t offer yet. It is written from the code that runs the service, and we update it when that changes.
Last reviewed: Privacy PolicyTerms of Service
HTTPS only
HSTS for two years, including subdomains.
Row-level security
Database rules scope each account to its own data.
Private photo storage
Photos are served through short-lived signed links.
No card data
Payments are taken by Stripe or Apple, never on our servers.
Hosting and service providers
vPlan AR is operated by ValidPixel LLC and runs on established cloud providers rather than servers we manage ourselves.
- Supabase
- The Postgres database that holds accounts and projects, sign-in (Supabase Auth), the file storage for photos, and the server functions that call the AI model.
- Vercel
- Hosts the vplan.ai website and web app and its server routes, including the server-side rendering of PDF plan sets.
- Postmark
- Sends email: address confirmation, password resets, team invites, comment notices and product emails.
- Stripe
- Takes web payments for Pro and Business through Stripe Checkout and the Stripe billing portal.
- Apple and RevenueCat
- Apple takes in-app purchases on iPhone and iPad; RevenueCat tells us the resulting subscription status.
- Anthropic
- Runs the AI features (the assistant, damage suggestions, scope drafts and AI room names), and only receives data when you use one of them.
- The full list
- The Privacy Policy lists every sub-processor and what each one receives. This page and the policy describe the same providers; if they ever differ, tell us.
Encryption and browser protections
Data travels over HTTPS only. Encryption at rest is provided by our hosting providers.
- In transit
- Every response from vplan.ai carries Strict-Transport-Security (two years, subdomains included, preload), so browsers only connect over HTTPS. The web app talks to the database, sign-in and storage over HTTPS and secure WebSockets only, and webhooks we send to your servers must use HTTPS.
- At rest
- Stored data is encrypted at rest as provided by our hosting providers: Supabase for the database and file storage, Vercel for the website. We don’t add a separate encryption layer of our own on top of theirs.
- Browser headers
- A Content-Security-Policy limits where scripts, connections and frames can come from; X-Frame-Options and frame-ancestors stop the site being embedded in another page (clickjacking); X-Content-Type-Options stops content sniffing; the Referrer-Policy keeps full URLs from leaking to other sites; and the Permissions-Policy turns off camera, microphone and location access for the website. The signed-in app, share pages and admin pages are marked noindex so search engines don’t list them.
Access control
Postgres row-level security decides what each signed-in account can read and change, so the rules hold for the web app, the iOS app and anything else that talks to the database.
- Projects
- Projects are private to their owner until you turn on a share link; turning the link off makes the plan private again. On Business, an owner can move a project into their team: members open it in the web app, admins and editors can edit it, viewers can only view and comment, and access ends while the team is not on Business. Only the owner can share, move or delete a project.
- Photos, versions, comments and keys
- Row-level security is on for every table that holds customer data. Photo links and API keys are readable only by the account they belong to; a plan’s photos, comments and saved versions only by its owner and, for a team project, the team’s members (and comments, while review is on, by viewers of its share link, through our server). A photo record can only point at its uploader’s own files, on a project they own or edit as a team member.
- Plan and billing can’t be self-assigned
- A signed-in account can only change its own name, profession, email preferences and price book. Its plan, billing details and admin status are written by our servers, not by the apps.
- Server-only tables
- Tables only our servers use have row-level security switched on and no rule that lets an app or browser in, so only our servers can read them.
- Private file storage
- Photos and mood board images are stored in a private bucket, in a folder per account that only that account can read, write or delete. The apps show them through signed URLs that expire after an hour; a photo link signs a new URL on each visit that expires after 10 minutes.
- Staff access
- Staff tools have their own sign-in with limited attempts, and staff actions, such as changing or deleting an account, are recorded in an audit log.
Sharing you control
Nothing in a project is visible outside your account until you share it, and every kind of link can be turned off.
- Share links
- A share link shows the plan, and its photos, in any browser without an account. It is off until you create it. Turning sharing off stops the link working and also revokes the photo links for that project.
- Client review is off by default
- Letting viewers comment and mark up a shared plan is a separate switch on each link (Pro and Business), off until you turn it on. Reviewers can add comments, arrows and clouds but cannot change the plan, and you can delete any comment or turn review off again.
- Photo links in PDFs
- Each photo in an exported PDF prints with a link and QR code. Links are random 128-bit codes, not indexed by search engines. The public sees the photo at up to 2560 pixels on the long edge; a larger original can be downloaded only by its owner, signed in. A link stops working when you delete the photo or project, turn off sharing for the project, or use “Reset photo links” in the project’s Photos panel.
- Teams
- On the Business plan you can create a team and invite members by email, with roles.
- Activity log (Business)
- Settings → Activity log shows who did what and when: exports from the web app and the API, share links, client review and presentations turned on or off, photo links reset, projects moved into or out of a team or deleted, API keys created or revoked, and team members invited, removed or given another role. A team’s owner and admins also see the team’s activity. Entries are written by our servers and database, not by the apps, can’t be edited or deleted by anyone signed in, are kept for a year, and download as CSV.
Accounts and sign-in
Sign-in is handled by Supabase Auth, with checks of our own against throwaway and automated sign-ups.
- Passwords
- The sign-in and sign-up forms send your password to Supabase Auth, which stores it hashed. No vPlan table stores passwords.
- Email confirmation
- On the web, an account confirms its email address before its first export or share link. The confirmation link works for 48 hours, can be used once, and is stored only as a SHA-256 hash. Changing the account’s email needs a new confirmation.
- Throwaway sign-ups are refused
- Every new account, from the web, the iOS app or a direct API call, is checked before it is created: addresses at known temporary-email domains (a public list, refreshed weekly) are refused, and so are bursts of new accounts from one network.
- Rate limits
- Sending confirmation emails, rendering PDFs, posting review comments, calling the API and testing webhooks are each rate-limited per account, key or address. They guard against abuse.
API keys and webhooks (Business)
The REST API and webhooks are part of the Business plan and are built so a leaked or forgotten key can do as little as possible.
- Keys are stored as hashes
- An API key is shown once, when you create it. We store only its SHA-256 hash and the first few characters, so a key can’t be read back from our database.
- Scopes and expiry
- Each key carries only the scopes you pick (read projects, download exports) and a lifetime of 30 days, 90 days, 1 year, never (90 days unless you choose another). You can revoke a key at any time in Settings.
- Read-only, checked on every call
- The API only reads data. Every request checks that the key is valid, unexpired, unrevoked, has the scope the endpoint needs, and that the account is still on Business. Each key may make 60 requests a minute and render 10 PDFs every 10 minutes (20 per account).
- Signed webhooks
- Webhooks we send are signed with an HMAC-SHA256 of a timestamp and the body, using a secret per endpoint that you can roll at any time. We only call HTTPS addresses, never private or local network addresses, and don’t follow redirects. Delivery history is kept for 30 days. See the API reference for how to check a signature.
- Webhooks we receive
- Stripe’s notifications are checked against Stripe’s signature, and the RevenueCat and Postmark callbacks on vplan.ai are rejected unless they carry our shared secret.
How your data is handled
What is processed where, what leaves your account, and how to remove it.
- PDF exports
- PDF plan sets are rendered on our server from the plan, photos and project details you send, returned to you, and not stored. Your plan’s limits (watermark, paper sizes, levels) are applied on the server, not trusted from the browser.
- Photos
- Photos added on the web are resized to at most 2560 pixels on the long edge before upload, unless you keep the original (Pro). A resized copy doesn’t carry the camera’s metadata, including GPS location; a small JPEG that already fits, or an original you keep, is stored as it is.
- AI features
- Nothing is sent to the AI model until you ask for something. The assistant gets your question and a summary of the plan; damage suggestions get that room’s photos and notes; scope drafts and AI room names get the rooms on that level. Anthropic processes it only to produce the answer and, under its commercial terms, doesn’t train its models on it. The Privacy Policy lists exactly what each feature sends.
- Getting your data out
- Every plan exports as a PDF; Pro and Business add DXF, 3D models and Excel or CSV schedules, and Business adds IFC, XML and the read-only API.
- Deleting data
- Deleting a project in the web app deletes its photos and their files, its saved versions, its comments and its photo links. To delete your whole account, email support@vplan.ai from the account’s address; we delete the account, its profile and its projects, as described in the Privacy Policy.
Payment data
Card details never reach vPlan AR.
- On the web
- You pay on Stripe’s own Checkout page and manage billing in Stripe’s billing portal. Card numbers are entered on Stripe’s pages; we keep your Stripe customer ID and subscription status.
- On iPhone and iPad
- Apple takes the payment. We receive the subscription status through RevenueCat, never card details.
What we don’t offer yet
So you can plan around it, here is what vPlan AR does not have today.
- Certifications
- We don’t have a SOC 2 report or an ISO 27001 certification.
- Single sign-on
- There is no SAML or Google Workspace single sign-on, and no two-factor sign-in for customer accounts.
- Data region
- You can’t choose the region your data is stored in.
Reporting a vulnerability
If you think you’ve found a security problem in vPlan AR, email support@vplan.ai with “Security” in the subject. Tell us what you found, where, and the steps to reproduce it. Please don’t access, change or delete other people’s data, and don’t run tests that slow the service down for others. We don’t run a paid bug bounty.
Email support@vplan.aiQuestions
Is vPlan AR SOC 2 or ISO 27001 certified?
No. We don’t have a SOC 2 report or an ISO 27001 certification. This page describes the controls that are in place instead: HTTPS with HSTS, row-level security in the database, private photo storage with short-lived signed links, hashed and scoped API keys, signed webhooks, and payments handled entirely by Stripe or Apple.
Where is my data stored?
Accounts, projects and photos are stored with Supabase (a Postgres database and file storage), and the website and its server routes run on Vercel. Data is encrypted at rest as provided by those hosting providers. The Privacy Policy lists every provider we use.
Who can see my projects?
Projects are private to their owner until you turn on a share link; turning the link off makes the plan private again. On Business, a project you move into your team is open to its members in the web app (viewers can only view and comment). Only the owner can share, move or delete a project. Reviewers on a share link can comment and mark up only if you turn review on, and they can’t change the plan.
Is my data used to train AI models?
No. AI features send data to Anthropic only when you ask for something, such as an assistant answer or a scope draft. Anthropic processes it only to produce the answer and, under its commercial terms, doesn’t train its models on it.
Does vPlan AR support single sign-on (SSO)?
Not yet. There is no SAML or Google Workspace single sign-on and no two-factor sign-in for customer accounts today. Sign-in is handled by Supabase Auth.
How do I report a security issue?
Email support@vplan.ai with “Security” in the subject, and include what you found and the steps to reproduce it. Please don’t access other people’s data or run tests that disrupt the service.