Privacy policy
Planic is a planning tool: a canvas and a board for a team's projects. This page says what we store about you, why, where, and how to get it removed. The short version: we keep what the product needs to work, we don't sell or share it, there are no ads, no tracking cookies and no analytics.
Who is responsible
[[Legal name and address of the controller]], contact [[privacy@your-domain]].
What we store
| What | Why | How long |
|---|---|---|
| Your name, email address and a hash of your password (never the password itself) | To sign you in and show who did what | Until you delete your account |
| What you put in Planic: teams, products, projects, tasks, comments, drawings | That is the product | Until you or your team deletes it, or you delete your account (see below) |
| A history of changes on each board (who changed what, when) | The activity feed, and so a team can see what an AI assistant changed | As long as the project exists |
| Access tokens you create for AI assistants, and sign-in sessions, stored as hashes | So those tools and devices can act as you, and so you can revoke them | Until they expire or you revoke them |
| Feedback you send from the app, with the page you sent it from | To fix what you report | Kept after account deletion, without the link to you |
| Crash reports from the app: the error message, where in the code it happened, the page you were on and the app version | To fix errors you may not have noticed or reported | 30 days after the error was last seen |
| Your email, if you joined the waitlist | To tell you when Planic opens up | Until you ask us to remove it |
| Server request logs: time, method, address path and response code | To find and fix errors | [[N]] days |
Your IP address is used, in memory only, to limit sign-in attempts. It is not written to our database or our request logs.
Where it is stored
On a server run by [[hosting provider]] in [[EU location]]. Encrypted nightly backups are kept with [[backup provider]] in [[EU location]] for 30 days. We use no other services that receive your data.
Cookies and tracking
None. The app keeps your sign-in in your browser's local storage so you stay signed in. This site loads no third-party scripts or fonts.
AI assistants
If you connect an AI assistant to Planic with an access token, it reads and changes your boards on your behalf, and what it reads is sent to that assistant's provider under their terms, not ours. Changes it makes are marked as made by an agent. Read-only tokens can't change anything.
Your rights
- Delete your account yourself under Profile → Delete account. Teams where you are the only member are deleted with everything in them. In teams you share, your tasks become unassigned and your comments stay, shown as "Deleted user", because they are part of your teammates' work.
- Get a copy of your data yourself under Profile → Download my data: your account and everything in your teams, as one JSON file.
- Have your data corrected, or object to how we use it: email us and we'll answer within a month.
- You can complain to your data protection authority.
Changes
During the alpha we'll tell testers by email before any change that affects them.