Trust & Security

This page is maintained by Plot My Retirement to answer common security and privacy questions about our website and community forum. It describes our current practices and the platform features we rely on. It is not a third-party certification or audit.

Platform & hosting

Plot My Retirement is built on Lovable Cloud, which provides our backend database, authentication, and serverless functions on managed infrastructure. Lovable Cloud's underlying database and authentication services are provided by Supabase.

Lovable provides the platform; we are responsible for our application code, our configuration, and the content we choose to collect.

Authentication & account access

Forum accounts use email and password sign-in. Passwords are hashed and managed by our authentication provider — we never see or store your password ourselves.

Sessions are issued as bearer tokens stored in your browser. You can sign out at any time from the forum header.

Data we collect

Newsletter signup: your email address, used to send retirement destination insights.

Forum accounts: your email, a display name you choose, and the topics and replies you post.

Calculator inputs: the budget, savings, and lifestyle numbers you enter are processed in your browser to show recommendations. We do not store them server-side.

Database access controls

Every table that stores user-generated content has Row-Level Security enabled. Forum topics and replies are publicly readable so the community can grow. Only the signed-in author of a post can edit or delete it; designated moderators can remove content that violates community guidelines.

Role assignments cannot be changed by signed-in users through the public API — only the project owner can grant moderator or admin roles.

Subprocessors & integrations

  • Lovable Cloud / Supabase — database, authentication, serverless functions.
  • Mailchimp — newsletter delivery and welcome emails for the email signup.

When you sign up for the newsletter, your email is transmitted to Mailchimp and stored in our Mailchimp audience.

Privacy requests, retention & contact

To request a copy of your data, unsubscribe from the newsletter, delete your forum account, or report a security concern, please contact us at the email address listed on the homepage.

For full details on data handling and your rights, see our Privacy Policy and Terms of Use.

Last reviewed: July 2026. This page reflects our current practices and is updated as the product evolves.