Effective Date: September 4, 2026
Last Updated: September 6, 2026
Planobot ("Planobot," "we," "our," or "us") provides tools for collecting, organizing, analyzing, and managing communications, documents, tasks, contacts, counterparties, properties, payments, and related operational information. Planobot is the public operator name for the Service during U.S. Early Access.
This Privacy Policy explains how Planobot collects, uses, stores, shares, retains, exports, and deletes information when you use our website, web application, macOS desktop application, integrations, APIs, and related services (the "Service"). Our Data Practices page provides a plain-language summary of the same product behavior.
1. Information We Collect
1.1 Account and information you provide
We collect information you submit, including your name, email address, account and workspace settings, support, security, or privacy requests, notes, records, uploaded files, and content you choose to import or sync. Customer sign-in uses Google OAuth; Planobot does not collect your Google password.
Planobot Early Access is currently free. We do not collect payment-card details and do not use a payment processor for customer subscription charges.
1.2 Connected and imported communications
Depending on the source and your choices, Planobot may process:
- Email, iMessage, WhatsApp, manual notes, and selected Google Takeout or MBOX archives;
- Sender and recipient names, email addresses, phone numbers, subjects, message bodies, timestamps, provider and thread identifiers, and labels used for the selected import scope;
- Attachments, file names, MIME types, extracted text, and file metadata; and
- Personal, property, tenant, counterparty, invoice, payment, account, and other information present in those communications.
You are responsible for having the rights and permissions needed to provide communications that contain information about other people.
1.3 Derived records and AI traces
Planobot uses rules and AI-assisted processing to create classifications, summaries, suggested tasks, contacts, counterparties, properties, payments, Work Threads, links, and other structured records. We also store bounded analysis traces, job state, model identifiers, provider response identifiers, token counts, durations, and redacted failure metadata so the Service can support human review, retries, and diagnostics.
1.4 Technical and diagnostic information
We process IP address, browser and device type, operating system, requested pages, session and security events, request identifiers, access logs, and redacted error diagnostics. Sentry default PII collection, performance tracing, and session replay are disabled. We do not intentionally send message bodies, prompts, email addresses, credentials, cookies, or attachment paths to Sentry.
1.5 Support, security, and privacy requests
The public contact form collects your name, email, request category, and message. If you submit while signed in, the request may also be linked to your authenticated Planobot user ID for verification. We store lifecycle status, acknowledgment and completion times, the handling administrator, verification method, and a non-sensitive resolution code.
2. How We Use Information
We use information to:
- Authenticate users and protect accounts;
- Import, display, search, classify, and organize communications and attachments;
- Create and link operational records and visible AI-assisted suggestions;
- Operate Space membership, routing, settings, exports, deletion, and other requested workflows;
- Provide support and fulfill privacy requests;
- Detect, prevent, investigate, and respond to security incidents, abuse, fraud, failures, and misuse;
- Maintain redacted diagnostics and service reliability; and
- Comply with law and enforce our Terms of Service.
We do not sell personal information. We do not use private message content or Google user data for advertising.
3. Gmail and Google Data
Planobot requests the Google scopes openid, email, profile, and https://www.googleapis.com/auth/gmail.readonly. The Gmail scope is read-only: Planobot cannot send, edit, or delete your Gmail.
When you choose an import range or ongoing Inbox monitoring, Planobot may read selected or recent Inbox headers, sender and recipient addresses, subject, body, timestamps, thread and provider identifiers, labels used for the selected Inbox scope, and attachments. Planobot stores imported copies and derived operational records in Supabase-hosted database and private Storage services.
For visible analysis features, Planobot sends message text, sender and recipient details, subject, relevant extracted attachment content or supported attachment files, candidate Work Threads, and bounded workspace record matches to OpenAI. We do not sell Google data, use it for advertising, or use it to train general-purpose models.
Disconnecting Gmail asks Google to revoke the refresh credential before Planobot deletes the local encrypted credential and stops future imports. Imported messages, attachments, derived records, and terminal analysis history remain until administrator-fulfilled deletion or service termination. If a legacy connection has no stored credential, Planobot removes the local connection and asks you to review Google Account permissions.
Planobot's use and transfer of information received from Google APIs adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
4. AI Processing
4.1 OpenAI
Planobot uses OpenAI for message analysis and supported attachment-text extraction. The categories sent are described in Section 3 and on the AI data-practices page. Planobot sets store:false on every OpenAI Responses request, so optional provider response storage is disabled. OpenAI may retain content in abuse-monitoring logs for up to 30 days unless Planobot later receives Zero Data Retention approval.
OpenAI API content is not used to train general-purpose models unless Planobot separately opts in; Planobot does not opt in during Early Access. Planobot stores resulting classifications, suggestions, and its own analysis traces until administrator-fulfilled deletion or service termination.
4.2 Desktop Claude Chat
Claude Chat is a user-invoked desktop feature. When you send a prompt, the desktop application sends that prompt and summaries of chats you selected through your separately installed and authenticated Claude CLI. That provider processing is governed by your Anthropic account. Planobot stores the transcript and Claude session ID only in local Planobot app storage on that Mac until you run Clear local Planobot data.
4.3 Human review
AI and rules-based outputs can be inaccurate, incomplete, or outdated. Review important suggestions before relying on them, especially for financial, legal, safety, compliance, or property-management decisions.
5. Service Providers and Disclosures
Planobot uses these providers for the stated purposes:
- Google: Google sign-in, Gmail authorization, and read-only Gmail access;
- Supabase: authentication, PostgreSQL database, and private attachment Storage;
- OpenAI: message analysis and supported attachment-text extraction;
- Sentry: redacted application error diagnostics;
- Vercel: production hosting and delivery of planobot.com; and
- Namecheap: domain services and private support-address email forwarding.
Providers process information under their agreements with Planobot and their applicable policies. We may also disclose information:
- At your direction through an integration or requested support workflow;
- To comply with law, legal process, or a valid government request;
- To protect the rights, safety, and security of Planobot, users, or others; or
- In a merger, financing, reorganization, bankruptcy, acquisition, or sale of assets, subject to applicable law and notice requirements.
We do not disclose Gmail data for advertising or sale. Human access to Google data is limited to your affirmative permission, security or abuse investigation, legal compliance, support you request, or aggregated and anonymized data.
6. Retention
Planobot applies this schedule:
- Active workspace data: imported communications, attachments, derived records, and Planobot AI traces remain until administrator-fulfilled deletion or service termination.
- Gmail refresh credentials: remain encrypted until disconnect or account deletion; Planobot requests provider revocation before local deletion.
- Deleted live account data: sole-member Space and account data is removed when the durable deletion job completes. Shared-Space records remain for other members after membership removal and direct actor anonymization.
- Backups and diagnostics: database backups, private Storage backups, production access logs, and Sentry diagnostics use a maximum rolling retention of 30 days.
- OpenAI: optional response storage is disabled with
store:false; provider abuse-monitoring logs may remain for up to 30 days. - Support, security, and privacy requests: closed requests are deleted 12 months after completion or denial.
- Export working files: administrative export working files are deleted immediately after verified delivery.
- Desktop-local data: Planobot caches, transcripts, archive indexes, and sync cursors remain on each Mac until you run Clear local Planobot data there.
Trash and Archive are reversible organization features and do not permanently delete data. Narrow legal, security, fraud-prevention, dispute, and compliance obligations may require Planobot to preserve specific records longer when law permits. We document any such exception in the request outcome without placing sensitive details in the public request record.
7. Security
Planobot uses safeguards including authentication, Space-scoped authorization, database row-level security, private attachment Storage, encryption in transit, encrypted Gmail refresh credentials, least-privilege service access, redacted diagnostics, and durable deletion stages. No system is perfectly secure, and we cannot guarantee absolute security.
Potential vulnerabilities should be submitted under the Security Reporting policy.
8. Your Choices and Requests
You may request access, a complete export, correction, deletion, or information about Planobot's processing through the contact form. You receive immediate on-screen confirmation. Planobot aims to acknowledge requests within 10 business days and provide a substantive response within 45 calendar days, subject to identity verification, lawful extensions, and exceptions.
When a request is submitted from a current authenticated Google session and its email matches the request, an operator can use that session link for verification. Otherwise, the operator verifies control of the account email before releasing data or initiating deletion.
Active-Space owners and admins can download Tasks, Inbox, and Payments CSVs in Settings as convenience exports for that Space; Members cannot use these CSV export routes. The CSVs are not complete account or privacy exports. Complete exports are administrator fulfilled and exclude refresh tokens, ciphertext, service credentials, internal security controls, and unrelated members' personal account data.
Account deletion is administrator fulfilled during Early Access. A request is complete only after Google credential revocation, database and private Storage cleanup, Auth-account deletion, and quarantine cleanup succeed. Sole-member Spaces are deleted. Shared records remain for remaining members with the departing membership removed and direct actor fields anonymized.
For California residents, applicable law may provide rights to know, access, correct, and delete personal information and to opt out of sale or sharing. Planobot does not sell personal information and does not share it for cross-context behavioral advertising. We do not discriminate for exercising applicable privacy rights.
9. Desktop Data
Clear local Planobot data signs out locally and removes Planobot-managed cached chat summaries and selections, sync cursors, Claude transcripts and session ID, email-archive index data, and extracted archive caches from that Mac. It does not delete original iMessage or WhatsApp databases, user-selected Takeout ZIPs or MBOX sources, or server-side Planobot data. Run the action on every Mac you use.
10. Children's Privacy
Planobot is not intended for children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child provided personal information so we can investigate and take appropriate action.
11. United States Early Access
Public Early Access is intended for users in the United States. Information may be processed in the United States and in locations where the providers listed above operate. EEA and UK launch terms are not included in this release.
12. Changes
We may update this Privacy Policy. If a change is material, we will provide notice required by law and update the effective or last-updated date. A prior policy continues to govern conduct before a new version takes effect.
13. Contact
For privacy questions or requests, use the Planobot contact form. Public support is form-only during Early Access.