Security at Your Day

Security that works quietly.

Your Day Schedule protects account, scheduling, client, and meeting data with layered controls across the application, database, and infrastructure.

Last reviewed:

Our approach

Practical protection at every layer.

Security is part of how we build and operate Your Day—not a one-time checklist. We limit access, keep sensitive credentials on the server, and use independent payment processors for card data.

01

Data encryption

Data is protected with TLS 1.2 or later in transit. Our infrastructure providers encrypt stored data at rest with AES-256.

02

Tenant separation

Authentication and PostgreSQL row-level security isolate account data and restrict it to authorized users and operations.

03

Infrastructure protection

Your Day runs on Vercel and Supabase. Vercel's platform firewall provides automatic network and DDoS protection.

04

Application safeguards

We use security headers, request rate limits, server-side validation, and no-store rules for sensitive responses.

05

Payment separation

Stripe and Square process payment card details directly. Card numbers do not pass through or remain on Your Day servers.

06

Account deletion

Signed-in account owners can permanently delete their account and associated application data from Your Day settings.

How data is handled

We use focused controls for the information people trust Your Day to hold.

  • Account dataAuthenticated sessions and database policies scope access to the right user.
  • Connected servicesCalendar and integration credentials are stored server-side and are not exposed to browser code.
  • Files and meeting dataStorage access is authorization-controlled. Sensitive application and API responses are marked not to be cached.
  • Your controlUsers can disconnect integrations and delete account data. Retention and deletion details are in our Privacy Policy.
Responsible disclosure

Found a security concern?

Please report it privately. Include the affected page or feature, clear reproduction steps, and the potential impact. Do not include personal data you do not need to share.

support@yourdayschedule.com →
  • Avoid accessing, changing, or deleting data that is not yours.
  • Avoid disrupting the service or other users.
  • Give us reasonable time to investigate before public disclosure.