Skip to content

Security & Data Trust

Last updated: September 26, 2026

Newplans holds company plans, competitor intelligence, PR relationships and creative work — information teams don't want anywhere but their own workspace.

This page explains, plainly, how workspace data is separated, who can access it, and how AI processing works. For the full legal detail, see the Privacy Policy.

Workspace separation

Each organization works inside its own workspace. Campaigns, projects, competitor tracking, PR records, creative assets and messages created inside a workspace belong to that workspace, and are not visible to other workspaces on Newplans.

Where Newplans supports client access, a client can be given access to one brand's work inside a workspace, scoped to that brand only — not to the rest of the workspace.

Who can access your data

Access inside a workspace is controlled by roles and permissions set by the workspace's own owners and administrators, using the controls under Settings → Members and Settings → Access.

Newplans staff do not access workspace content as a matter of course. Access for support or troubleshooting is limited to what's needed to resolve the specific request.

Roles and permissions

Workspace owners and administrators manage who can join a workspace, what role each member holds, and what that role can see and do.

  • Workspace owners and administrators configure membership and workspace-wide settings.
  • Members work within the permissions their role grants.
  • Client roles are scoped to the specific brand they were invited to.

AI and data handling

AI features run only when you use them — Newplans does not run AI processing over your workspace in the background without a request that triggers it.

When you use an AI feature, the information needed to complete that specific request (for example, the campaign, brief or competitor data involved) is sent to the AI provider required to generate the response.

AI output is a draft for your review, not an automatic action — material changes remain subject to your own review before publishing or sending.

See the AI features section of the Privacy Policy for more detail.

Encryption and infrastructure

Traffic to and from Newplans is encrypted in transit (HTTPS/TLS). Authentication uses hashed credentials — Newplans does not store passwords in plain text.

Newplans runs on established cloud infrastructure providers rather than self-managed hardware, and relies on their underlying physical and network security controls.

Subprocessors

Newplans uses a limited set of third-party providers to operate the service — for example, hosting and infrastructure, database and storage, email delivery, billing (Stripe) and the AI providers used for AI-assisted features.

[Published subprocessor list with named providers and purposes — to be added — to be confirmed before publication]

Certifications

[Security certifications (e.g. SOC 2) — not yet completed; this page will be updated if and when a certification is obtained — to be confirmed before publication]

Reporting a concern

If you believe you’ve found a security issue, please tell us through the support form with as much detail as you can share, and we’ll follow up.

[Dedicated security contact (optional) — to be confirmed before publication]