Security
This page describes how GrabCast protects your data and how to report a security problem. For what we collect and why, see the Privacy Policy.
On this page
1. Privacy by design
- Most tools (image, PDF, video, audio, transcription and many more) process files in your browser. The files never reach our servers, so they can't leak from them.
- We collect only what a feature needs and delete it on short schedules (see retention). Comment text and account-level statistics from connected platforms are read live and not stored.
- We never publish a post or start spending on an ad without your explicit confirmation, and everything the Ads manager creates starts paused.
2. Encryption
- In transit: every connection to grabcast.click and our API uses HTTPS (TLS).
- Tokens and keys at rest: access and refresh tokens for connected platforms, AI provider keys, storage connections, app passwords and two-step verification secrets are encrypted with AES-256-GCM. The encryption key is kept in our server configuration, not in the database, and each encrypted value is bound to its own record and account, so a copied value can't be reused elsewhere. Tokens and keys are never sent to your browser and never written to logs.
- Passwords are stored only as bcrypt hashes. Invite links, approval links and their passwords, recovery codes, remembered-device tokens and one-time links are stored only as one-way hashes.
- Private files (media library, publishing copies) are kept in private storage and shared with platforms only through signed links that expire within hours.
3. Account security
- Optional two-step verification with an authenticator app, recovery codes and remembered devices (Account & Settings → Security).
- Email confirmation for new accounts, rate-limited sign-in and password reset, and bot protection (Cloudflare Turnstile) on sign-up forms.
- Role-based access in team workspaces (Owner, Admin, Editor, Client, Viewer): only Owners and Admins can connect ad accounts or approve ad spend, and every change is recorded in an audit log.
- Tips: use a unique password, turn on two-step verification, and use app passwords or dedicated API keys (with spending limits) for anything you connect.
4. Least-privilege access to your accounts
- We ask each platform only for the permissions a feature you turned on needs, and ad permissions are requested in a separate dialog.
- Google Drive, Docs and Sheets use only the
drive.filepermission: GrabCast can see only files you pick or that it creates. - For Bluesky we accept only app passwords, never your main password, and don't store them.
- You can see and revoke every connection in the Scheduler and at each platform (see Data deletion).
5. Infrastructure and operations
- We run on established cloud providers (Google Cloud, Cloudflare, Neon, Render, Firebase — see Subprocessors) with their physical and network security.
- Server requests to other services go only to fixed, allow-listed addresses; user-supplied links are checked to block access to internal networks.
- Content Security Policy and other security headers on sensitive pages, output escaping of user content, idempotent and audited money-related actions, and automated tests for access control between accounts and workspaces.
- Administrative access requires two-step verification and is logged.
6. Incidents
If we learn of a security incident that affects your personal data, we will investigate, contain it, and notify you and the relevant authorities without undue delay as required by law (for example within 72 hours to EU/UK authorities where GDPR applies).
7. Reporting a vulnerability
We welcome reports from security researchers. Email support@grabcast.click with the subject "Security report", a description, steps to reproduce and the affected URL. Please:
- test only against your own accounts and data, and stop as soon as you've confirmed a problem;
- don't access, change or delete other people's data, don't degrade the service (no denial-of-service or high-volume automated scanning), and don't use social engineering or physical attacks;
- give us reasonable time to fix the issue before disclosing it publicly.
We will acknowledge your report, keep you informed and credit you if you wish. We won't take legal action against good-faith research that follows these rules. GrabCast is free and we don't run a paid bug bounty.