Skip to main content

Privacy Policy

Last updated: January 2026

1. Introduction

Planra ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered idea-to-execution planning service.

Data Controller: Planra
Contact: privacy@planra.co

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, name (optional), password
  • Project Content: Ideas, concepts, and text you submit for AI processing
  • AI Outputs: Generated plans, specifications, brand kits stored in your account
  • Audio Files: Recordings uploaded for transcription (processed but not stored)
  • Communications: Support requests, feedback, and correspondence

2.2 Information Collected Automatically

  • Usage Data: Features used, project counts, timestamps
  • Technical Data: IP address (for security/rate limiting only), browser type
  • Cookies: Essential authentication cookies (see Section 8)

2.3 Payment Information

Authentication and payment processing are handled by Clerk. We receive only: Clerk user ID, plan tier, and billing status. We never receive or store your credit card numbers.

3. How We Use Your Information

PurposeLegal Basis (GDPR)
Provide and operate the ServiceContract performance
Process AI requests and generate outputsContract performance
Process payments and subscriptionsContract performance
Send transactional emails (receipts, updates)Contract performance
Prevent fraud and ensure securityLegitimate interest
Improve the Service (aggregate analytics)Legitimate interest
Comply with legal obligationsLegal obligation

4. AI Processing Disclosure

When you use our AI features, your content is sent to third-party AI providers for processing:

  • AI Processing Provider: Processes text and audio content to generate project plans, specs, brand kits, and transcriptions

Data Handling by AI Providers:

  • Processing is transient—your data is not stored by these providers after processing
  • Your content is not used to train their AI models (per our API agreements)
  • All data transmission uses encrypted connections (HTTPS/TLS)

5. Data Sharing and Service Providers

We share your information only with service providers necessary to operate the Service:

Clerk (Authentication & Payments)

Purpose: User authentication, subscription billing
Data: Account information, payment information, billing address
Safeguards: SOC 2 Type 2 certified, PCI DSS compliant

Supabase (Database)

Purpose: Application data storage
Data: Projects, tasks, workspaces, usage data
Safeguards: Standard Contractual Clauses, SOC 2 certified

AI Processing (Google Cloud)

Purpose: Generate project plans, content, and audio transcription
Data: Text and audio content submitted for processing
Retention: Transient only (not stored after processing)

Other Disclosures

We may also disclose your information: (a) to comply with legal obligations; (b) to protect our rights or safety; (c) in connection with a merger, acquisition, or sale of assets.

We do not sell or share your personal information for cross-context behavioral advertising.

6. Data Retention

Data TypeRetention Period
Account informationAccount lifetime + 30 days after deletion
Project content and outputsAccount lifetime + 30 days after deletion
Audio filesNot stored (streamed and deleted)
Security logs (IP addresses)24 hours (in-memory only)
Payment records7 years (legal requirement)

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Right to Access

Request a copy of the personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete data via your account settings.

Right to Erasure ("Right to be Forgotten")

Delete your account and all associated data via account settings or by contacting us.

Right to Data Portability

Export your projects and data in a machine-readable format.

Right to Object

Object to processing based on legitimate interests.

To exercise your rights: Contact us at privacy@planra.co or use the account deletion feature in your dashboard settings. We will respond within 30 days.

California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, request deletion, and opt-out of sale. We do not sell personal information.

8. Cookies and Tracking

We use only essential cookies required for the Service to function:

CookiePurposeType
sb-*-auth-tokenAuthentication sessionEssential
sb-*-auth-token-code-verifierPKCE securityEssential

We do not use analytics cookies, marketing cookies, or third-party tracking. If this changes, we will update this policy and implement appropriate consent mechanisms.

9. Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest (database encryption)
  • Secure authentication with session management
  • Rate limiting to prevent abuse
  • Access controls and audit logging
  • Regular security reviews

While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

10. International Data Transfers

Your data may be transferred to and processed in countries other than your own, including the United States. These transfers are protected by Standard Contractual Clauses (SCCs) and the data protection frameworks of our service providers. By using the Service, you consent to these transfers.

11. Children's Privacy

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided us with personal information, we will delete it immediately. If you believe we have collected information from a child under 13, please contact us at privacy@planra.co.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we will also send you an email notification. Your continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

For privacy-related questions, data requests, or concerns, please contact us at:

Privacy Contact: privacy@planra.co

We will respond to all privacy requests within 30 days.