Version 11, in effect since 16 September 2026
What changed
Version 11 · 16 September 2026Requests about your data now go to contact@planye.com, the one address for everything you send us. The old address is no longer the one to use. Nothing else changed.
Version 10 · 16 September 2026Writes down what Brazilian law already asked of us. We keep a record of which account used Planye from which IP address and in which hour, for six months, because the Marco Civil da Internet requires it: it outlives a closed account for that reason only, is deleted when the six months end, and is handed over only on a court order. Corrects the LGPD article our international transfers rest on, and says what they rest on where a provider has not adopted the ANPD's standard clauses. Says how quickly a breach is reported. Gives the reason we may hold the things the table of reasons had left out: the moments counted inside the app, a connected calendar, crash reports, the weekly email and a message you send us. Corrects two lines in that table that no longer matched the product: Google Analytics holds no visitor identifier, and the feature switches do keep your account's identifier and email address.
Version 9 · 7 September 2026Corrects what this document said about getting a copy of your planner. It said we would send you everything you have written, in a form you can read without Planye, on request. There is no such export — no button, and nothing behind the address either — so the sentence promised something that was not there, and it has been removed rather than left standing. Nothing about your rights changes, because those are not ours to give or take: under LGPD article 18 you can still ask us what we hold about you, ask to see it, correct it, have it deleted, and ask for it in a portable form, and we still answer within 15 days, or 30 under the GDPR. That clause is unchanged and is now the only place this subject is described. Separately, and not a change to what this document says: the table above has always said your profile picture is deleted when you close your account, and until today the app did not actually delete it, so a picture set on a closed account could still be opened by anyone holding its link. The app now removes it, in the same act as everything else. If you closed an account before today and set a picture on it, write to us and we will find it and delete it.
Version 8 · 1 September 2026Says what signing in with Apple hands over, now that the iPhone app offers it: your email address and, once and only on the first sign-in, your name. If you choose to hide your address, what we hold is the relay address Apple gives in its place, and your own never reaches us. Also writes down what the two apps keep on your device, which is the website's list with three differences: no language cookie, no page counting at all, and a second copy of your sign-in token in the app's own storage, so that a phone reclaiming space cannot sign you out. On Android a home screen widget keeps its own small copy of what it draws, and signing out empties it. Names the few moments we now count inside the app: that an account was created, that somebody signed in, your first task, your first habit, that the app was open on a given day, that you kept one of the ready-made lines a brand-new planner is offered, that a planner was kept in this browser before there was an account and later moved onto one, that we asked how the app is going or mentioned Planye+ without being asked and whether you opened it, and that a free trial started or turned into a subscription. They go to PostHog as your account, they say nothing beyond that they happened, and they are why the apps are no longer described as carrying no measurement at all. They carry these, and still no page counting. Those moments have a switch of their own, under Your account, and turning it off stops them on every device you are signed in on. Says, for the first time, that Planye can be opened with no account at all: while it is, everything you write stays in your own browser's storage and none of it reaches us or anyone named in this document. It becomes ours to hold only when you make an account and it moves onto one, and until then clearing your browser's data removes it with nothing here to put it back from.
Version 7 · 30 August 2026Closing your account is a button now, at the bottom of your account panel, and the page describes it instead of asking you to write to us. What goes, goes as you press it rather than within 30 days; encrypted backups still roll off within 90. Adds RevenueCat, which handles a subscription bought inside the iPhone or Android app: it is told your account's random identifier and what you bought, and never anything you wrote.
Version 6 · 25 August 2026Google Analytics now stores nothing on your device. It is told before it loads that it may keep no cookie and no identifier, so it still counts which pages people reach but can no longer tell that two visits were the same person. That is why this site has no cookie banner to dismiss. Also writes down three things that were true and were not written down: the one cookie Planye does set, which holds the language you picked; the crash reporter, including that it keeps a masked recording of the minute in front of some crashes; and the weekly email, which reads your week in order to write it and is off until you ask for it.
Version 5 · 16 August 2026Added Outlook calendars, which work the way Google's already did: read-only, drawn on your week, the permission held as an encrypted token. Says what disconnecting can and cannot revoke: a Google permission is also revoked at Google, while Microsoft offers no way to revoke from our side, so removing Planye from your Microsoft account's app permissions is done there.
Version 4 · 15 August 2026Added PostHog, which answers which optional features are switched on for your account. It receives who is asking (the random identifier your account has in our database and your email address, so a feature can be switched on early for accounts named by email) along with which of our sites you are using, the live one or the one we test on. Nothing else: no page address, no record of anything you did, and nothing you wrote. Says what it keeps on your device, which is the list of switches and no cookie.
Version 3 · 12 August 2026Added a clause on Google user data: what we read from a connected calendar follows Google's API Services User Data Policy and its Limited Use requirements, our access is read-only, and none of it is sold, advertised against or used to train a model. Says that the copy kept for a reconnect can be deleted on request rather than only when the account closes.
Version 2 · 10 August 2026Added what a connected calendar holds: the events we copy onto your week, anything you set on one of them, and the permission we keep to read them. Says what disconnecting removes and what it keeps.
Version 1 · 7 August 2026The first version, published with the beta.

Privacy Policy

This document is the binding statement of how Planye handles personal data. Where a help page summarises it, this document governs.

1

Who holds your planner

Planye is made and run by Riquetti Studio, CNPJ 41.011.161/0001-68, Rua Rodriguês do Prado, 150, Ermelinda, Belo Horizonte, MG, Brazil. Under Brazil's Lei Geral de Proteção de Dados we are the controller of everything described below.

Planye is open to readers anywhere, so where the GDPR, the UK GDPR or a comparable law reaches you, we act as controller under that law too, and this document is written to hold either way.

Anything in this document, or any request about your own data, goes to contact@planye.com.

One company is responsible, it is named here, and one address answers for all of it.
2

What we hold

A few kinds of thing, and they are worth telling apart.

One thing on that list can exist before we hold any of it. Planye opens without an account, and while it is open that way everything you write stays in your own browser's storage on your own device. None of it is sent to us, we cannot see it, and nothing about it reaches any of the companies named below. It becomes ours to hold, in the sense the rest of this document means, only when you make an account and it moves onto that account. Until then, clearing your browser's data removes it, and there is nothing here we could put back.

That is the whole list. There is no advertising network and no data broker, and we do not buy data about you from anyone. Two measurement tools and one crash reporter are named below. The first sees which of our pages get opened, never what is on them. The second answers which features are switched on for you, and is told who is asking (your account's identifier and email address) and nothing else about you. The crash reporter is told what broke, and around some crashes it keeps a recording of the screen with every letter and every photograph blocked out before it leaves your browser. Nothing you write into your planner is ever sent to any of the three.

WhatSpecifically
Your accountYour email address, whether it is confirmed, and the name you chose. A profile picture, if you set one: it is cropped to a small square in your browser before it is sent, which removes the location and camera details a photo normally carries. If you sign in with Google, the name, email address and profile picture Google passes over. If you sign in with Apple, the email address and, once and only on the first sign-in, the name Apple passes over. Apple lets you hide your address, and when you do, what reaches us is the relay address Apple gives in its place: that is the address we hold and the one we write to, and your own never arrives here at all. Your password is handled by Supabase Auth: it never reaches our server and we cannot read it.
Your plannerEverything you write into it. Weeks, categories and entries, habits and their marks, priorities, moods, cycle days and symptoms, budget lines, envelopes and holdings, projects, lists, wishes, your reading and watching shelf, year notes and memories, sealed capsules, and every journal page including the photos, video and voice notes on it. This is never shown to anyone but you.
A feature request you postIf you post one (Help, then Suggest a feature), the title and description you write are shown to every other signed-in account once we approve it; before that, only you can see it. It carries no name and no avatar, and nothing on the board tells another reader which account wrote it. We keep the author internally, only so we can limit how many requests one account posts in a day and let you take your own back down, and that is never sent to anyone reading the board. Voting works the same way: nobody else can see which requests you voted for.
RequestsOur server records the ordinary things a server records when your device syncs: the IP address the request came from, the time, the path, and the browser string. Separately, because the Marco Civil da Internet requires it of us, we keep a record of which account used Planye from which IP address and in which hour. Nothing in either record names what you wrote.
Usage measurementWe run Google Analytics on our own pages to see which ones people reach and where they give up. It receives the page address, the referrer, your browser and device type, and an approximate country worked out from your IP address. It is set up to store nothing on your device, so it is given no identifier that lasts beyond the page and cannot tell that two visits were the same person. It never receives the contents of your planner, your journal, your cycle or mood entries, or your email address.
A few moments inside the appThe page counting above cannot tell whether somebody came back, because it is set up to hold no identifier at all. So that we can, we count a short list of moments inside the app and send them to PostHog as your account: that an account was created, that somebody signed in, the first task and the first habit you write, that the app was open on a given day, that you kept one of the ready-made lines a brand-new planner is offered, that a planner was kept in this browser before there was an account and later moved onto one, that a guest planner was instead deliberately left behind, that we asked how the app is going or mentioned Planye+ without being asked and whether you opened what we mentioned, and that a free trial started or turned into a subscription. That is the entire list. Each of them says only that the thing happened, on what day: not which page you were on, not what you named a task or a habit, and nothing else from inside your planner. They are tied to the same random identifier and email address the row below describes, and to nothing else about you. You can turn this off: Your account, then Counting. With it off, nothing on that list is sent from any device you are signed in on, and the planner works exactly as it did.
Which features you getWe can turn a feature on for a few accounts before everybody has it, or switch one off if it misbehaves. To do that your browser asks PostHog which switches are on, saying who is asking: the random identifier your account has in our database, and your email address, which is what lets us name an account when turning a feature on early. That pair is what PostHog keeps as its record of your account, and it is the whole of what is sent about you. It is also told which of our sites you are using, the live one or the one we test on, so a feature can be switched on for testing without switching it on for everybody. That is a fact about our setup, not about you. It receives no page address and nothing you wrote. The only record of anything you did that reaches it is the short list of moments in the row above, sent as the same account.
A calendar you connectedIf you connect a calendar, Google's or Outlook's: the title, day and time of each event in a window running three months back and twelve months forward, so they can be drawn on your week. Also which calendars you chose, what you named them, and anything you set on one of those events yourself, such as a colour. We read your calendar and never write to it. Your permission is held as a token we keep encrypted. Disconnecting deletes that token and the events come off your week. For a Google calendar the permission is also revoked at Google. Microsoft offers no way for us to revoke from our side, so Planye stays listed in your Microsoft account's app permissions until you remove it there; with the token deleted we can read nothing more either way. We keep the copy, along with the account's address, so that connecting the same account again restores the week and everything you set on it. If you would rather it went now, ask at contact@planye.com and we delete it. Closing your account removes all of it either way.
When something breaksWhat broke and where: the error, which version of Planye you were on, the address of the page it happened on, and your account's random identifier, never your email address. For some crashes, the minute of screen activity in front of it, masked in your browser before it is sent so that every letter and every photo, video and voice note is blocked out. It records nothing while nothing is wrong.
The weekly email, if you turn it onA look back at your week, sent on Mondays and off until you ask for it. Building it reads your week's headline, your priorities, the habits you marked, how many tasks you finished each day and how many events a calendar you connected held, and what is on the week starting, including the titles of the first few of its tasks and events. The week just gone is counted rather than listed, so nothing you wrote on it is named in the email. Turning it off stops the sending and the reading both.
Your subscriptionIf you subscribe to Planye+: which currency you are billed in, the country that decided it, whether the plan is running, and the identifier Stripe gave your account there. If you subscribed inside the iPhone or Android app instead, it is which plan you bought, when it renews and whether it is still running, told to us by RevenueCat. Card numbers are typed on Stripe's or the store's own screen and never reach us, so we do not have one to hold, lose or show you.
Everything you write, plus your email, how your device reached us, which of our pages you opened, a short list of moments inside the app such as your first task or that you opened it today, which you can switch off in your account, which optional features are switched on for you, and what broke when something did. No advertising network, nothing bought from anyone, and no analytics anywhere near what you wrote. Your planner is private; the one exception is a feature request you choose to post, which other accounts see, without your name, once we approve it.
3

Health, money, and the things you would not say out loud

A planner is not a to-do app. Some of what Planye holds is genuinely sensitive: your cycle and its symptoms, how you felt on a given day, what you earn and what you spend, and a journal with your photographs in it. Under LGPD article 11 and GDPR article 9, cycle and mood entries are health data and carry a higher bar than the rest.

Nothing is filled in unless you fill it in. Cycle, Mood and Money are modules you choose to add from Customize, and a planner without them holds none of this.

It is used for one thing, which is showing it back to you: storing it, syncing it between your own devices, and drawing it on the page. There is no second purpose.

It is never sold, never shared with advertisers, and never used to train a machine-learning model, ours or anyone else's. This holds for all of your planner, not only the sensitive parts.

It also stays out of the two places people reasonably worry about. Our measurement receives page addresses on our public pages, and inside the app the bare fact that one of a few listed moments happened. It never receives page contents, so it cannot see a cycle day, a mood, a budget line or a word of your journal. None of those moments is about the modules this clause is written for: writing a cycle day, a mood or a budget line is counted nowhere at all. Whoever handles the payment (Stripe on the website, Apple or Google with RevenueCat inside the apps) receives what a payment needs and nothing from inside the app at all: subscribing to Planye+ tells them that somebody paid, never what they wrote.

Turning the mood or cycle tracker on is the consent. Turning it off takes it back. None of it is ever sold or used to train anything.
4

Google user data

If you connect a Google calendar, Planye's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. That policy is published at https://developers.google.com/terms/api-services-user-data-policy.

Four rules come with it, and they are Google's rather than promises we invented. What we read from your calendar is used for one thing, which is drawing those events on your week, and that is the feature you connected it for. It is never sold and never passed to an advertising network. It is never used to train a machine-learning model. And nobody here reads it, other than where you ask us to look at something for you, where we are investigating abuse or a security problem, or where a law requires it.

We ask Google for read access and nothing else. Planye cannot add, change or delete anything in your calendar, and no code in it tries to.

Read-only, drawn on your week, never sold, never advertised against, never used to train anything, and not read by a person.
5

Why we are allowed to hold it

Every law in this area asks the same question in a different accent: on what basis. Ours, per kind of data.

WhatOn what basis
Your accountPerforming our agreement with you, and keeping the account secure. LGPD art. 7, V; GDPR art. 6(1)(b).
Your planner contentThe same. Storing what you wrote and syncing it to your devices is the service you signed up for.
Cycle, symptoms and moodYour specific consent, given by adding those modules and writing in them. LGPD art. 11, I; GDPR art. 9(2)(a). You withdraw it by deleting the entries, removing the module, or closing the account.
A feature request you postOur legitimate interest in running a public request board, weighed against posting being entirely your choice and never carrying your name. LGPD art. 7, IX; GDPR art. 6(1)(f).
Request logsOur legitimate interest in keeping the service running and defending it from abuse. LGPD art. 7, IX; GDPR art. 6(1)(f).
The access recordA legal obligation: the Marco Civil da Internet, article 15, requires it. LGPD art. 7, II. Where the GDPR reaches you, a Brazilian obligation is not one that law recognises, so there the basis is our legitimate interest in obeying the law we operate under, GDPR art. 6(1)(f).
Usage measurementOur legitimate interest in knowing which pages work and which ones lose people, weighed against how little it holds: no planner content, and no identifier that outlasts the page. LGPD art. 7, IX; GDPR art. 6(1)(f). Because nothing in it could pick out your visits, the way to object is to block it in your browser, and Planye works the same without it.
A few moments inside the appOur legitimate interest in knowing whether people who start using Planye keep using it, weighed against how little each moment says and the switch that stops them. LGPD art. 7, IX; GDPR art. 6(1)(f).
Which features you getOur legitimate interest in releasing a change to a few accounts before all of them, and in being able to switch one off without waiting for a new version of the app. LGPD art. 7, IX; GDPR art. 6(1)(f). What is kept to do it is your account's identifier and email address, as the table above says.
A calendar you connectedPerforming our agreement with you: you connected it so its events would appear on your week. LGPD art. 7, V; GDPR art. 6(1)(b).
When something breaksOur legitimate interest in finding and fixing what broke, weighed against the masking described above. LGPD art. 7, IX; GDPR art. 6(1)(f).
The weekly email, if you turn it onYour consent, given by turning it on and withdrawn by turning it off. LGPD art. 7, I; GDPR art. 6(1)(a).
A message you send usAnswering it, which is what you asked for by sending it. LGPD art. 7, V; GDPR art. 6(1)(b).
Your subscription and its payment recordsPerforming our agreement with you, plus the legal obligation to keep tax records. LGPD art. 7, II and V; GDPR art. 6(1)(b) and 6(1)(c).
6

Where it lives, and who else touches it

Two copies. One is on your device, in the browser's own database, and it is the copy Planye reads from: that is why the app works with the network off and never spins waiting for a server. The other is on ours, so a new phone gets your planner back.

We do not run our own data centre. The companies that hold a piece of it on our behalf are listed in the Subprocessors document, each under a contract that lets them process it only on our instructions. That list is part of this policy and changes to it are announced the same way.

Your device holds a full copy, which is why it works offline. The server copy is what a new phone restores from.
7

Your data leaves Brazil

It has to. The companies in the Subprocessors list run in data centres outside Brazil, mostly in the United States and the European Union, so operating Planye at all means an international transfer.

Where a provider has adopted the ANPD's standard contractual clauses, the transfer rests on them, which is the route LGPD article 33, II, b sets out. Where the transfer is needed to give you the service you signed up for, it also rests on article 33, IX. Where GDPR chapter V applies, transfers rest on the European Commission's standard contractual clauses. If you would like to know which provider sits in which region, or to see the clauses that apply, ask and we will tell you.

8

What is stored on your device

One cookie, and it is one you create yourself by choosing a language. No advertising cookie, no measurement cookie, and nothing here follows you to another company's website. Five things are stored, and three of them are ones the app cannot work without.

Your sign-in token, in local storage if you asked to stay signed in on this device and in session storage if you did not, in which case it is gone when the tab closes.

Your planner, in IndexedDB, one database per account, so two people sharing a laptop never see each other's pages.

Your dress: theme, pinned spine and view preferences, which also sync so a second device opens looking the same.

The fourth is the list of which features are switched on for you, kept in local storage rather than a cookie, beside the identifier and email address the question is asked with. It is there so a page opens the way it opened last time, instead of changing shape a moment after it draws. It holds no record of anything you did.

The fifth is the cookie, and it holds one word: the language you picked. It has to be a cookie rather than anything else because our server reads it before the page is built, which is what lets the page arrive already in your language instead of turning over after you have started reading. It is written when you choose, removed again when you have chosen nothing, and it lasts a year. Nobody outside Planye can read it.

Google Analytics is not on that list, and it used to be. It counts which of our pages people reach, and it is now told before it starts that it may store nothing on your device at all: no cookie, and no identifier that outlives the page you are on. That is why this site does not ask you to accept cookies. There is nothing to accept, and a banner shown in order to be dismissed is not a choice.

The iPhone and Android apps keep the same list in the same places, with three differences worth naming. There is no language cookie, because an app reads the language from the device itself. There is no page counting at all: Google Analytics is left out of what we build for the stores rather than switched off inside it, so no address of a page you opened is counted anywhere in the apps. The few moments listed further up are counted there as they are on the website, because they are how we tell whether the app is worth keeping; they name no page either. And your sign-in token is kept a second time, in the app's own storage rather than the web page's, because iPhones treat a web page's storage as cache and may empty it whenever the phone needs the room, which would sign you out for no reason you could see. Only the sign-in token is copied there, only when you asked to stay signed in on that device, and signing out removes it.

On Android, a home screen widget keeps its own small copy of what it draws, which is the habits on your week and today's entries. It is separate from everything above and it is there because a widget has to draw before the app has opened. It holds nothing else, nothing reads it back into your planner, and signing out empties it.

Clearing your browsing data clears all five. That signs you out and empties the local copy. It does not touch the server copy, which comes back the next time you sign in. In the apps the same is done by signing out, which empties the widget's copy with it, or by removing the app.

Three things the app needs, one list of which features are on, and one cookie holding the language you picked. No advertising cookie and no measurement cookie, which is why you are never asked to accept any. Clearing your browser data empties this device and nothing else.
9

How long it is kept

Your planner is kept for as long as your account exists. We do not expire old weeks, thin out last year, or delete a journal page because it is large.

One thing here is worth being straight about. Deleting something in Planye does not erase the row at once: it marks the row deleted and keeps the marker. That is what carries the deletion to your other devices, and it is what makes the five-second undo possible. The content is no longer shown anywhere and no longer counts toward anything, but the marker sits in the database until the account is closed.

Close your account (the button is at the bottom of your account panel) and the whole of it goes, on this timetable.

WhatGone within
Your planner, including deletion markers and every file in the media bucketAt once, when you close the account
Your sign-in record with Supabase, and your profile picture if you set oneAt once, in the same act
Encrypted backups holding any of it90 days, as they roll off
Request logs30 days, on a rolling basis
The access record (which account, which IP address, which hour)Six months, as the Marco Civil da Internet requires, then deleted. It is handed over only on a court order, and it outlives a closed account for that reason and no other
Usage measurement14 months for the page counting, which is the shortest retention Google Analytics offers, and a year for the moments counted inside the app. Neither holds planner content to begin with
Payment and invoice recordsKept as long as Brazilian tax law requires, currently five years, and for nothing else. They outlive a closed account for that reason and no other
A delete inside the planner is not instant, and this says so rather than pretending. Closing the account is what actually removes everything, and that part happens as you press it.
10

What you can ask us for

Under LGPD article 18 you may ask us to confirm whether we hold data about you, to show you it, to correct it, to anonymise, block or delete it, to hand it to you in a portable form, to tell you who we have shared it with, and to withdraw a consent you gave.

Under the GDPR and UK GDPR you additionally have the rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to a purely automated decision. Planye makes no automated decisions about anyone.

Deletion you can do yourself, at the bottom of your account panel, and it takes effect as you press it. Everything else on those two lists goes to contact@planye.com from the address on the account, and we answer LGPD requests within 15 days and GDPR requests within 30. It costs nothing, unless a request is repeated so often that it stops being a request.

If California law reaches you: we do not sell or share personal information as the CCPA defines those words, we have never done so, and there is nothing here to opt out of.

If you think we have got this wrong, you can complain to the ANPD in Brazil, or to your own supervisory authority in the EEA or the UK. We would rather you wrote to us first, but you do not have to.

One email, from the address on your account, and a person answers it.
11

How it is protected

Everything travels over TLS. Every request to our server carries a token that is verified before a single row is read, and every table is keyed on your account id, so one account cannot address another's rows. Journal media is filed under your account id too, which means cross-account reach is not so much blocked as impossible to express. Your password never touches our server.

What we will not tell you is that this is perfect. No service can promise that, and Planye is a beta run by a small team. If a breach ever puts your data at risk we will tell you and the ANPD within three working days of learning of it, as Brazilian law requires, and any other authority we owe a report to within its own deadline, which under the GDPR is 72 hours.

12

Age

Planye is not built for children and is not offered to anyone under 13, or under 16 where local law sets that age for using a service like this one without a parent. If you believe a child has an account with us, write to contact@planye.com and we will remove it.

13

If this document changes

We will publish a new version, dated, with a note saying what changed. If a change materially affects what we hold or what we do with it, you get an email and a notice in the app at least 30 days before it takes effect, and for anything that needs your consent we will ask rather than assume.

14

The company behind Planye

Planye is made and run by Riquetti Studio, CNPJ 41.011.161/0001-68, Rua Rodriguês do Prado, 150, Ermelinda, Belo Horizonte, MG, Brazil. Planye is the product; that company is the legal person these documents bind.

Questions about this document, or a request about your own data?contact@planye.com