The part they need.
Custom view or edit access covers Shot List, Setlist and Cheat Sheet. Cheat Sheet “safe” and “team” labels guide outward sharing; a tool grant gives access to the whole board.
A wedding brings people together. It doesn’t mean every detail belongs to everyone. Here is how access works in Plantoat today.
Reviewed . Formal policy status
Give broad access to a trusted lead or select only the tools and records someone needs. Private vows stay outside wedding-role access.
Custom view or edit access covers Shot List, Setlist and Cheat Sheet. Cheat Sheet “safe” and “team” labels guide outward sharing; a tool grant gives access to the whole board.
Schedule, run, comments and media have separate permissions. Schedule access alone does not expose media or comments. Contributors can remove their own media; removing others’ requires full edit scope.
Access can be scoped to a person’s looks, details, measurements, provider information and image metadata.
The current boundary: budget, checklist, guests, seating, check-in, vendors and readiness remain full-scope tools. Custom access does not grant these individually.
Manually saved vows and revisions sync to an author-only vault. An owner or superuser cannot read them through their wedding role. Local recovery text is separate from your saved draft.
Choosing to share with your partner creates a sealed snapshot. Its content is withheld until the server checks the recipient and reveal time. Deleting the wedding does not itself delete your vault or an existing partner share.
Available planning data is stored locally. Cached media can remain available offline; uncached media needs a connection.
Authorized edits and media transfer through cloud services with a valid session. Pending changes are not the same as uploaded changes.
Supabase and PowerSync support authorized synchronization. Each device needs time and a connection to receive current data.
Offline restoration needs a matching, previously verified identity from the last 30 days and a retryable connection failure. Initial authentication and account-security actions need a connection. This is not a promise of uninterrupted access.
The server rejects revoked access. Protected local data and caches are removed when the app receives and processes the change. A disconnected device cannot be remotely cleared immediately. Queued edits may be rejected after access changes; exported files cannot be recalled by changing a role.
Account deletion requires an online session, your password and an explicit confirmation. It removes your account and owned weddings. Operational records in other people’s weddings can remain without your actor identity. Formal backup and log retention terms are not published here.
Account deletion stepsThis page explains implemented product behavior. Formal legal terms and contact delivery are still awaiting publication and configuration in this website.