Privacy Policy
This document is the binding statement of how Planye handles personal data. Where a help page summarises it, this document governs.
Who holds your planner
Planye is made and run by Riquetti Studio, CNPJ 41.011.161/0001-68, Rua Rodriguês do Prado, 150, Ermelinda, Belo Horizonte, MG, Brazil. Under Brazil's Lei Geral de Proteção de Dados we are the controller of everything described below.
Planye is open to readers anywhere, so where the GDPR, the UK GDPR or a comparable law reaches you, we act as controller under that law too, and this document is written to hold either way.
Anything in this document, or any request about your own data, goes to contact@planye.com.
What we hold
A few kinds of thing, and they are worth telling apart.
One thing on that list can exist before we hold any of it. Planye opens without an account, and while it is open that way everything you write stays in your own browser's storage on your own device. None of it is sent to us, we cannot see it, and nothing about it reaches any of the companies named below. It becomes ours to hold, in the sense the rest of this document means, only when you make an account and it moves onto that account. Until then, clearing your browser's data removes it, and there is nothing here we could put back.
That is the whole list. There is no advertising network and no data broker, and we do not buy data about you from anyone. Two measurement tools and one crash reporter are named below. The first sees which of our pages get opened, never what is on them. The second answers which features are switched on for you, and is told who is asking (your account's identifier and email address) and nothing else about you. The crash reporter is told what broke, and around some crashes it keeps a recording of the screen with every letter and every photograph blocked out before it leaves your browser. Nothing you write into your planner is ever sent to any of the three.
| What | Specifically |
|---|---|
| Your account | Your email address, whether it is confirmed, and the name you chose. A profile picture, if you set one: it is cropped to a small square in your browser before it is sent, which removes the location and camera details a photo normally carries. If you sign in with Google, the name, email address and profile picture Google passes over. If you sign in with Apple, the email address and, once and only on the first sign-in, the name Apple passes over. Apple lets you hide your address, and when you do, what reaches us is the relay address Apple gives in its place: that is the address we hold and the one we write to, and your own never arrives here at all. Your password is handled by Supabase Auth: it never reaches our server and we cannot read it. |
| Your planner | Everything you write into it. Weeks, categories and entries, habits and their marks, priorities, moods, cycle days and symptoms, budget lines, envelopes and holdings, projects, lists, wishes, your reading and watching shelf, year notes and memories, sealed capsules, and every journal page including the photos, video and voice notes on it. This is never shown to anyone but you. |
| A feature request you post | If you post one (Help, then Suggest a feature), the title and description you write are shown to every other signed-in account once we approve it; before that, only you can see it. It carries no name and no avatar, and nothing on the board tells another reader which account wrote it. We keep the author internally, only so we can limit how many requests one account posts in a day and let you take your own back down, and that is never sent to anyone reading the board. Voting works the same way: nobody else can see which requests you voted for. |
| Requests | Our server records the ordinary things a server records when your device syncs: the IP address the request came from, the time, the path, and the browser string. Separately, because the Marco Civil da Internet requires it of us, we keep a record of which account used Planye from which IP address and in which hour. Nothing in either record names what you wrote. |
| Usage measurement | We run Google Analytics on our own pages to see which ones people reach and where they give up. It receives the page address, the referrer, your browser and device type, and an approximate country worked out from your IP address. It is set up to store nothing on your device, so it is given no identifier that lasts beyond the page and cannot tell that two visits were the same person. It never receives the contents of your planner, your journal, your cycle or mood entries, or your email address. |
| A few moments inside the app | The page counting above cannot tell whether somebody came back, because it is set up to hold no identifier at all. So that we can, we count a short list of moments inside the app and send them to PostHog as your account: that an account was created, that somebody signed in, the first task and the first habit you write, that the app was open on a given day, that you kept one of the ready-made lines a brand-new planner is offered, that a planner was kept in this browser before there was an account and later moved onto one, that a guest planner was instead deliberately left behind, that we asked how the app is going or mentioned Planye+ without being asked and whether you opened what we mentioned, and that a free trial started or turned into a subscription. That is the entire list. Each of them says only that the thing happened, on what day: not which page you were on, not what you named a task or a habit, and nothing else from inside your planner. They are tied to the same random identifier and email address the row below describes, and to nothing else about you. You can turn this off: Your account, then Counting. With it off, nothing on that list is sent from any device you are signed in on, and the planner works exactly as it did. |
| Which features you get | We can turn a feature on for a few accounts before everybody has it, or switch one off if it misbehaves. To do that your browser asks PostHog which switches are on, saying who is asking: the random identifier your account has in our database, and your email address, which is what lets us name an account when turning a feature on early. That pair is what PostHog keeps as its record of your account, and it is the whole of what is sent about you. It is also told which of our sites you are using, the live one or the one we test on, so a feature can be switched on for testing without switching it on for everybody. That is a fact about our setup, not about you. It receives no page address and nothing you wrote. The only record of anything you did that reaches it is the short list of moments in the row above, sent as the same account. |
| A calendar you connected | If you connect a calendar, Google's or Outlook's: the title, day and time of each event in a window running three months back and twelve months forward, so they can be drawn on your week. Also which calendars you chose, what you named them, and anything you set on one of those events yourself, such as a colour. We read your calendar and never write to it. Your permission is held as a token we keep encrypted. Disconnecting deletes that token and the events come off your week. For a Google calendar the permission is also revoked at Google. Microsoft offers no way for us to revoke from our side, so Planye stays listed in your Microsoft account's app permissions until you remove it there; with the token deleted we can read nothing more either way. We keep the copy, along with the account's address, so that connecting the same account again restores the week and everything you set on it. If you would rather it went now, ask at contact@planye.com and we delete it. Closing your account removes all of it either way. |
| When something breaks | What broke and where: the error, which version of Planye you were on, the address of the page it happened on, and your account's random identifier, never your email address. For some crashes, the minute of screen activity in front of it, masked in your browser before it is sent so that every letter and every photo, video and voice note is blocked out. It records nothing while nothing is wrong. |
| The weekly email, if you turn it on | A look back at your week, sent on Mondays and off until you ask for it. Building it reads your week's headline, your priorities, the habits you marked, how many tasks you finished each day and how many events a calendar you connected held, and what is on the week starting, including the titles of the first few of its tasks and events. The week just gone is counted rather than listed, so nothing you wrote on it is named in the email. Turning it off stops the sending and the reading both. |
| Your subscription | If you subscribe to Planye+: which currency you are billed in, the country that decided it, whether the plan is running, and the identifier Stripe gave your account there. If you subscribed inside the iPhone or Android app instead, it is which plan you bought, when it renews and whether it is still running, told to us by RevenueCat. Card numbers are typed on Stripe's or the store's own screen and never reach us, so we do not have one to hold, lose or show you. |
Health, money, and the things you would not say out loud
A planner is not a to-do app. Some of what Planye holds is genuinely sensitive: your cycle and its symptoms, how you felt on a given day, what you earn and what you spend, and a journal with your photographs in it. Under LGPD article 11 and GDPR article 9, cycle and mood entries are health data and carry a higher bar than the rest.
Nothing is filled in unless you fill it in. Cycle, Mood and Money are modules you choose to add from Customize, and a planner without them holds none of this.
It is used for one thing, which is showing it back to you: storing it, syncing it between your own devices, and drawing it on the page. There is no second purpose.
It is never sold, never shared with advertisers, and never used to train a machine-learning model, ours or anyone else's. This holds for all of your planner, not only the sensitive parts.
It also stays out of the two places people reasonably worry about. Our measurement receives page addresses on our public pages, and inside the app the bare fact that one of a few listed moments happened. It never receives page contents, so it cannot see a cycle day, a mood, a budget line or a word of your journal. None of those moments is about the modules this clause is written for: writing a cycle day, a mood or a budget line is counted nowhere at all. Whoever handles the payment (Stripe on the website, Apple or Google with RevenueCat inside the apps) receives what a payment needs and nothing from inside the app at all: subscribing to Planye+ tells them that somebody paid, never what they wrote.
Google user data
If you connect a Google calendar, Planye's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. That policy is published at https://developers.google.com/terms/api-services-user-data-policy.
Four rules come with it, and they are Google's rather than promises we invented. What we read from your calendar is used for one thing, which is drawing those events on your week, and that is the feature you connected it for. It is never sold and never passed to an advertising network. It is never used to train a machine-learning model. And nobody here reads it, other than where you ask us to look at something for you, where we are investigating abuse or a security problem, or where a law requires it.
We ask Google for read access and nothing else. Planye cannot add, change or delete anything in your calendar, and no code in it tries to.
Why we are allowed to hold it
Every law in this area asks the same question in a different accent: on what basis. Ours, per kind of data.
| What | On what basis |
|---|---|
| Your account | Performing our agreement with you, and keeping the account secure. LGPD art. 7, V; GDPR art. 6(1)(b). |
| Your planner content | The same. Storing what you wrote and syncing it to your devices is the service you signed up for. |
| Cycle, symptoms and mood | Your specific consent, given by adding those modules and writing in them. LGPD art. 11, I; GDPR art. 9(2)(a). You withdraw it by deleting the entries, removing the module, or closing the account. |
| A feature request you post | Our legitimate interest in running a public request board, weighed against posting being entirely your choice and never carrying your name. LGPD art. 7, IX; GDPR art. 6(1)(f). |
| Request logs | Our legitimate interest in keeping the service running and defending it from abuse. LGPD art. 7, IX; GDPR art. 6(1)(f). |
| The access record | A legal obligation: the Marco Civil da Internet, article 15, requires it. LGPD art. 7, II. Where the GDPR reaches you, a Brazilian obligation is not one that law recognises, so there the basis is our legitimate interest in obeying the law we operate under, GDPR art. 6(1)(f). |
| Usage measurement | Our legitimate interest in knowing which pages work and which ones lose people, weighed against how little it holds: no planner content, and no identifier that outlasts the page. LGPD art. 7, IX; GDPR art. 6(1)(f). Because nothing in it could pick out your visits, the way to object is to block it in your browser, and Planye works the same without it. |
| A few moments inside the app | Our legitimate interest in knowing whether people who start using Planye keep using it, weighed against how little each moment says and the switch that stops them. LGPD art. 7, IX; GDPR art. 6(1)(f). |
| Which features you get | Our legitimate interest in releasing a change to a few accounts before all of them, and in being able to switch one off without waiting for a new version of the app. LGPD art. 7, IX; GDPR art. 6(1)(f). What is kept to do it is your account's identifier and email address, as the table above says. |
| A calendar you connected | Performing our agreement with you: you connected it so its events would appear on your week. LGPD art. 7, V; GDPR art. 6(1)(b). |
| When something breaks | Our legitimate interest in finding and fixing what broke, weighed against the masking described above. LGPD art. 7, IX; GDPR art. 6(1)(f). |
| The weekly email, if you turn it on | Your consent, given by turning it on and withdrawn by turning it off. LGPD art. 7, I; GDPR art. 6(1)(a). |
| A message you send us | Answering it, which is what you asked for by sending it. LGPD art. 7, V; GDPR art. 6(1)(b). |
| Your subscription and its payment records | Performing our agreement with you, plus the legal obligation to keep tax records. LGPD art. 7, II and V; GDPR art. 6(1)(b) and 6(1)(c). |
Where it lives, and who else touches it
Two copies. One is on your device, in the browser's own database, and it is the copy Planye reads from: that is why the app works with the network off and never spins waiting for a server. The other is on ours, so a new phone gets your planner back.
We do not run our own data centre. The companies that hold a piece of it on our behalf are listed in the Subprocessors document, each under a contract that lets them process it only on our instructions. That list is part of this policy and changes to it are announced the same way.
Your data leaves Brazil
It has to. The companies in the Subprocessors list run in data centres outside Brazil, mostly in the United States and the European Union, so operating Planye at all means an international transfer.
Where a provider has adopted the ANPD's standard contractual clauses, the transfer rests on them, which is the route LGPD article 33, II, b sets out. Where the transfer is needed to give you the service you signed up for, it also rests on article 33, IX. Where GDPR chapter V applies, transfers rest on the European Commission's standard contractual clauses. If you would like to know which provider sits in which region, or to see the clauses that apply, ask and we will tell you.
What is stored on your device
One cookie, and it is one you create yourself by choosing a language. No advertising cookie, no measurement cookie, and nothing here follows you to another company's website. Five things are stored, and three of them are ones the app cannot work without.
Your sign-in token, in local storage if you asked to stay signed in on this device and in session storage if you did not, in which case it is gone when the tab closes.
Your planner, in IndexedDB, one database per account, so two people sharing a laptop never see each other's pages.
Your dress: theme, pinned spine and view preferences, which also sync so a second device opens looking the same.
The fourth is the list of which features are switched on for you, kept in local storage rather than a cookie, beside the identifier and email address the question is asked with. It is there so a page opens the way it opened last time, instead of changing shape a moment after it draws. It holds no record of anything you did.
The fifth is the cookie, and it holds one word: the language you picked. It has to be a cookie rather than anything else because our server reads it before the page is built, which is what lets the page arrive already in your language instead of turning over after you have started reading. It is written when you choose, removed again when you have chosen nothing, and it lasts a year. Nobody outside Planye can read it.
Google Analytics is not on that list, and it used to be. It counts which of our pages people reach, and it is now told before it starts that it may store nothing on your device at all: no cookie, and no identifier that outlives the page you are on. That is why this site does not ask you to accept cookies. There is nothing to accept, and a banner shown in order to be dismissed is not a choice.
The iPhone and Android apps keep the same list in the same places, with three differences worth naming. There is no language cookie, because an app reads the language from the device itself. There is no page counting at all: Google Analytics is left out of what we build for the stores rather than switched off inside it, so no address of a page you opened is counted anywhere in the apps. The few moments listed further up are counted there as they are on the website, because they are how we tell whether the app is worth keeping; they name no page either. And your sign-in token is kept a second time, in the app's own storage rather than the web page's, because iPhones treat a web page's storage as cache and may empty it whenever the phone needs the room, which would sign you out for no reason you could see. Only the sign-in token is copied there, only when you asked to stay signed in on that device, and signing out removes it.
On Android, a home screen widget keeps its own small copy of what it draws, which is the habits on your week and today's entries. It is separate from everything above and it is there because a widget has to draw before the app has opened. It holds nothing else, nothing reads it back into your planner, and signing out empties it.
Clearing your browsing data clears all five. That signs you out and empties the local copy. It does not touch the server copy, which comes back the next time you sign in. In the apps the same is done by signing out, which empties the widget's copy with it, or by removing the app.
How long it is kept
Your planner is kept for as long as your account exists. We do not expire old weeks, thin out last year, or delete a journal page because it is large.
One thing here is worth being straight about. Deleting something in Planye does not erase the row at once: it marks the row deleted and keeps the marker. That is what carries the deletion to your other devices, and it is what makes the five-second undo possible. The content is no longer shown anywhere and no longer counts toward anything, but the marker sits in the database until the account is closed.
Close your account (the button is at the bottom of your account panel) and the whole of it goes, on this timetable.
| What | Gone within |
|---|---|
| Your planner, including deletion markers and every file in the media bucket | At once, when you close the account |
| Your sign-in record with Supabase, and your profile picture if you set one | At once, in the same act |
| Encrypted backups holding any of it | 90 days, as they roll off |
| Request logs | 30 days, on a rolling basis |
| The access record (which account, which IP address, which hour) | Six months, as the Marco Civil da Internet requires, then deleted. It is handed over only on a court order, and it outlives a closed account for that reason and no other |
| Usage measurement | 14 months for the page counting, which is the shortest retention Google Analytics offers, and a year for the moments counted inside the app. Neither holds planner content to begin with |
| Payment and invoice records | Kept as long as Brazilian tax law requires, currently five years, and for nothing else. They outlive a closed account for that reason and no other |
What you can ask us for
Under LGPD article 18 you may ask us to confirm whether we hold data about you, to show you it, to correct it, to anonymise, block or delete it, to hand it to you in a portable form, to tell you who we have shared it with, and to withdraw a consent you gave.
Under the GDPR and UK GDPR you additionally have the rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to a purely automated decision. Planye makes no automated decisions about anyone.
Deletion you can do yourself, at the bottom of your account panel, and it takes effect as you press it. Everything else on those two lists goes to contact@planye.com from the address on the account, and we answer LGPD requests within 15 days and GDPR requests within 30. It costs nothing, unless a request is repeated so often that it stops being a request.
If California law reaches you: we do not sell or share personal information as the CCPA defines those words, we have never done so, and there is nothing here to opt out of.
If you think we have got this wrong, you can complain to the ANPD in Brazil, or to your own supervisory authority in the EEA or the UK. We would rather you wrote to us first, but you do not have to.
How it is protected
Everything travels over TLS. Every request to our server carries a token that is verified before a single row is read, and every table is keyed on your account id, so one account cannot address another's rows. Journal media is filed under your account id too, which means cross-account reach is not so much blocked as impossible to express. Your password never touches our server.
What we will not tell you is that this is perfect. No service can promise that, and Planye is a beta run by a small team. If a breach ever puts your data at risk we will tell you and the ANPD within three working days of learning of it, as Brazilian law requires, and any other authority we owe a report to within its own deadline, which under the GDPR is 72 hours.
Age
Planye is not built for children and is not offered to anyone under 13, or under 16 where local law sets that age for using a service like this one without a parent. If you believe a child has an account with us, write to contact@planye.com and we will remove it.
If this document changes
We will publish a new version, dated, with a note saying what changed. If a change materially affects what we hold or what we do with it, you get an email and a notice in the app at least 30 days before it takes effect, and for anything that needs your consent we will ask rather than assume.
The company behind Planye
Planye is made and run by Riquetti Studio, CNPJ 41.011.161/0001-68, Rua Rodriguês do Prado, 150, Ermelinda, Belo Horizonte, MG, Brazil. Planye is the product; that company is the legal person these documents bind.