Skip to content

Security and privacy

Private workspaces and explicit provider boundaries.

Wieser Social limits access by workspace, encrypts high-risk credentials, validates uploads, and keeps provider-owned restrictions visible instead of bypassing them.

Workspace isolation

Membership documents and role checks remain the source of truth for private workspace access.

Encrypted provider tokens

OAuth token sets and user-supplied AI keys are encrypted with authenticated encryption and never returned to the browser after storage.

Secure sessions

Firebase authentication is exchanged for secure session cookies, and protected routes do not fall back to demo content when a signed-in workspace fails.

Validated media

Finalization checks ownership, storage path and host, metadata, size, MIME type, and file signatures before an asset becomes durable.

Least-privilege provider access

Each provider requests only the scopes used by the implemented workflow. Restricted capabilities remain disabled until explicitly approved.

Abuse and retry safeguards

Durable transaction-based rate limits, expiring publishing leases, and targeted retries protect sensitive endpoints and partial publish failures.

Account control stays visible.

Disconnect a provider from Social Accounts to remove its stored Wieser Social connection and token. You can also revoke the app from the provider's own authorized-app settings.

Request complete account, workspace, or provider-data deletion through the published instructions. Privacy, Terms, data deletion, and contact links remain available throughout the public website.

Data deletion instructions

Interactive product demo

Review the working product without creating an account.

The demo opens the real planner, composer, inbox, analytics, media library, social account settings, and approval workflows with safe sample data.

Open interactive demo