Gmail access
Planobot requests Google profile scopes openid, email, and profile, plus https://www.googleapis.com/auth/gmail.readonly. The Gmail permission is read-only: Planobot cannot send, edit, or delete email.
When you choose a range or enable ongoing Inbox monitoring, Planobot may read message headers, sender and recipient addresses, subject, body, timestamps, thread and provider identifiers, labels used for the selected Inbox scope, and attachments. Planobot stores imported copies and derived operational records in your workspace. Disconnecting revokes the Google refresh credential and stops future imports; it does not erase copies already imported. Those remain until administrator-fulfilled deletion or service termination.
Planobot's use and transfer of Google user data complies with the Google Workspace API User Data and Developer Policy, including its Limited Use requirements. Gmail data is not sold, used for advertising, or used to train general-purpose models.
AI processing
Visible analysis features send message text, sender and recipient details, subject, relevant extracted attachment content or supported attachment files, candidate Work Threads, and a bounded set of workspace record matches to OpenAI. OpenAI responses may create classifications, suggested records, links, and analysis traces that Planobot stores in the workspace. Planobot requests no optional OpenAI response storage (store:false); OpenAI may retain abuse-monitoring logs for up to 30 days unless Zero Data Retention is approved for Planobot later.
The desktop Claude Chat feature runs only when you send a prompt. It passes that prompt and summaries of the chats you selected through your separately installed and authenticated Claude CLI. That processing is governed by your Anthropic account. Planobot keeps the desktop chat transcript and Claude session ID only on that Mac until you clear local Planobot data.
AI output can be inaccurate or incomplete. Review important suggestions before relying on them.
Retention schedule
- Active workspace data, imported communications and attachments, derived records, and Planobot AI traces: until administrator-fulfilled deletion or service termination.
- Gmail refresh credentials: until disconnect or account deletion, with revocation requested from Google before local deletion.
- Database and private Storage backups, production access logs, and Sentry diagnostics: a maximum rolling 30 days.
- OpenAI provider content: optional response storage disabled; abuse-monitoring logs may remain for up to 30 days.
- Closed support, security, and privacy requests: 12 months after completion or denial.
- Administrative export working files: deleted immediately after verified delivery.
- Desktop caches, transcripts, archive indexes, and sync cursors: until you clear local Planobot data on each Mac.
Trash and Archive are reversible organization features, not permanent deletion. Narrow legal, security, fraud-prevention, and dispute-preservation exceptions may require longer retention where law permits.
Export
Active-Space owners and admins can download Tasks, Inbox, and Payments CSVs in Settings as convenience exports for that Space. Members cannot use these CSV export routes. The CSVs are not complete account or privacy exports and may omit message bodies, attachments, account settings, other record types, shared-Space attribution, and request history.
A complete export is administrator fulfilled after identity verification. It includes an account package and, for a Space you own, a complete owned-Space package with a manifest and checksums. Refresh tokens, ciphertext, service credentials, unrelated members' account data, and internal security controls are excluded.
Deletion
Early Access deletion is administrator fulfilled after identity and ownership checks. Completion means Google credential revocation, database and private Storage cleanup, Auth-account deletion, and quarantined object cleanup have all succeeded.
Sole-member Spaces are deleted with their live server data. In shared Spaces, Planobot removes the membership and direct actor identity while preserving shared records for remaining members. Deleted data may remain in rolling backups, diagnostics, or legally preserved records until their applicable period ends.
Desktop-local data
Clear local Planobot data signs out and removes Planobot-managed cached chat summaries and selections, sync cursors, Claude transcripts and session ID, the email-archive index, and extracted archive caches from that Mac. It does not delete original iMessage or WhatsApp databases, selected Takeout ZIPs or MBOX sources, or server data. Run it on every Mac you use.
Requests and response timing
Submit support and security reports through the Planobot contact form. The automated receipt confirms submission but is not a human acknowledgment. Planobot aims to acknowledge support and security requests within five business days.
For access/export, deletion, correction, and other privacy-rights requests, Planobot aims to provide a human acknowledgment within 10 business days and a substantive response within 45 calendar days, subject to identity verification, lawful extensions, and exceptions. An authenticated Google session may verify an account request; otherwise an operator verifies control of the account email before releasing data or initiating deletion.
Service providers
- Google: Google sign-in, Gmail authorization, and read-only Gmail access.
- Supabase: authentication, PostgreSQL database, and private attachment Storage.
- OpenAI: message analysis and supported attachment-text extraction.
- Sentry: redacted application error diagnostics; default PII, tracing, and session replay are disabled.
- Vercel: production hosting and delivery of planobot.com.
- Namecheap: domain services and private support-address email forwarding.
Planobot does not currently use a payment processor and does not charge Early Access users.
This guide supplements the Privacy Policy and Terms of Service.