Official OAuth
QueueTempo requests only the approved scopes needed for the selected capability. It never asks for social passwords or automates a consumer site.
Security & privacy
QueueTempo is designed to keep brand data scoped, social credentials encrypted, publishing inspectable, and administrative power narrow and auditable.
Security foundations
Each control below is part of how QueueTempo is built and operated, covering infrastructure, external accounts, controlled live tests, restore drills, and monitoring.
QueueTempo requests only the approved scopes needed for the selected capability. It never asks for social passwords or automates a consumer site.
Social access and refresh tokens use versioned authenticated encryption. Keys live in a secret store, with rotation and compromise runbooks.
Every Organization-owned query, file, cache key, background event, and authorization decision stays scoped to that Organization.
Membership and permission checks happen on the server. Owners, Admins, Publishers, Approvers, and Analysts receive distinct authority.
Sensitive Organization, publishing, billing, membership, and support actions record the actor, target, time, and safe reason.
Self-serve checkout and payment-method management use Stripe-hosted flows. Signed webhooks-not success-page parameters-drive billing state.
Encrypted backups, documented retention, point-in-time recovery where the provider supports it, and rehearsed restore drills.
Account and Organization export, deletion, token revocation, active-data purge, backup aging, and legal-hold behavior follow documented workflows.
Customer prompts, brand facts, sources, unpublished drafts, media, and private analytics are not QueueTempo marketing inventory.
Authorization path
A valid session is only the first check. The server resolves the Organization, loads active membership, verifies the exact permission, and fetches the target inside that Organization scope before a transaction can change it.
Protected mutation
Publishing credentials
A Connection exposes safe identity, capabilities, scopes, health, and reconnect actions-not decrypted OAuth credentials.
Claims ledger
A security page should separate the controls QueueTempo operates from the third-party certifications it does not hold.
Every Connection runs through the provider's own consent screen. QueueTempo never collects a provider password or drives a browser session on your behalf.
Required controlVersioned encryption, redaction, rotation, revoke, and compromise procedures.
Required controlNo report is claimed on this site.
Not establishedNo certification is claimed on this site.
Not establishedQueueTempo is not marketed as a system for protected health information.
Not offeredNo public numerical SLA is claimed. Enterprise terms exist only by contract.
Not establishedSubprocessor categories
Subprocessors
QueueTempo’s subprocessor list names the hosting, database, AI, payment, email, storage, and monitoring providers it relies on, what each one processes, and the relevant data location.
OpenAI and other AI providers receive only the customer-selected context needed for the requested draft. QueueTempo does not send hidden reasoning to customer logs and does not use private customer content as general marketing material.
Set the next beat
Start free, keep automatic publishing off until you trust the setup, and use Organization-level pause controls whenever you need them.