Trust & security
How we protect your horse's life.
This page is maintained by the GaloPlan team to answer common questions about security, privacy and data handling. It is not an independent certification — it is our commitment, written in plain language.
Authentication & access
Access to GaloPlan requires creating an account with an email and password. Sessions are managed through secure tokens issued by Supabase Auth. Passwords are never stored in plain text: they are hashed by the authentication infrastructure.
Each horse has members explicitly invited by the owner. A member only accesses the horses they were invited to, and only with the role assigned to them (owner, rider, read-only).
Sharing between riders
Invitations are sent through a unique, time-limited email link. The recipient must use the invited email address to accept, which prevents a forwarded link from being reused.
iCal feeds (Google / Apple / Outlook Calendar sync) rely on a private token unique to each member. This token can be regenerated at any time from the settings, which immediately revokes existing subscriptions.
Hosting & data isolation
The app is hosted on secure cloud infrastructure, and the database and authentication run on Supabase (managed PostgreSQL, encrypted at rest and in transit).
Isolation between accounts is enforced at the database level through Row-Level Security rules: a query can only return rows for the horses the signed-in user explicitly belongs to.
What we don't do
- We don't sell your data.
- We don't use your content (notes, photos, logs) to train third-party AI models.
- We don't share the identity or contact details of a horse's members with commercial third parties.
- We don't display advertising in the app.
Retention & deletion
A horse's data (log, care, appointments, schedule) is kept as long as the owner keeps the horse profile active. When an account or a horse is deleted, the associated data is removed from the application database.
You can request the export or deletion of your personal data at any time by writing to the address below.
Security contact
Found a vulnerability, or have a question about the privacy of your data? Write to us at galoplan.com@gmail.com. We commit to acknowledging receipt within 72 business hours.