Controller
For the closed beta, Planny is the controller for account, product, and usage data on plannyapp.eu. Privacy requests can be sent to privacy@planny.ai. Beta participants receive formal company and contract details in their invitation or beta agreement.
What data Planny processes
Planny processes account data, provider identity, mailbox data, selected email content, drafts, send status, contact data for recipient selection, calendar information, settings, audit logs, and operational safety data. Which mailbox, contact, and calendar content is available depends on the permission level selected during provider connection.
Why we use that data
Data is used to classify inboxes, create draft replies, suggest meetings, find recipients for new emails, create or update Gmail drafts, send confirmed emails, support approval flows, keep provider connections active, investigate security incidents, and store account settings.
The main legal bases are performance of the beta agreement, legitimate interest for security and product reliability, consent for provider scopes where required, and legal obligations where applicable.
Provider access
Users connect Planny through Google or Microsoft. Depending on the selected permission level, Planny may read mailbox and calendar content, use contacts to search recipients, prepare or save drafts, adjust mailbox labels or message status, and send confirmed emails within configured approval and safety rules.
Protection of sensitive data
Planny protects sensitive mailbox, contact, calendar, account, and OAuth data with technical and organizational measures. Traffic between users, Planny, and connected providers uses encrypted HTTPS connections. OAuth tokens are stored server-side, encrypted before database storage, and not placed in browser cookies or client sessions.
Access to user data is limited to authenticated server routes, user-bound database controls, and authorized employees or processors who need access for support, security, or operations. Planny uses logging, audit rules, approval flows for sensitive actions, data minimization, periodic deletion or anonymization, and separated production configurations to reduce misuse, unauthorized access, and unnecessary retention.
Google Workspace data and AI processing
Google Workspace data, such as Gmail, contact, and calendar data, is used only to deliver requested Planny functionality: reading, summarizing, finding recipients, preparing reply text, managing Gmail drafts, performing mailbox actions, supporting meetings, and sending confirmed messages. Planny does not use Google Workspace API data to train, improve, or develop general AI or machine-learning models.
When AI processing is needed for a user request, only the required context is shared with the processor being used, and that processing remains limited to performing the requested function. Planny does not sell Google Workspace data or use it for advertising.
Sharing with third parties
Planny does not sell personal data. Data is shared only with subprocessors required to deliver the service, such as hosting, authentication, database, AI processing, payment processing, and provider integrations.
Retention and control
Users can export account data and request account deletion through the application. Provider access can also be revoked through the connected Google or Microsoft account. Audit and security logs are retained only as long as needed for operational security, troubleshooting, and legal obligations.
During the beta, operational logs and audit data are reviewed periodically. Data that is no longer needed for the beta, support, security, or legal obligations is deleted or anonymized.
Data subject rights
Users can request access, correction, deletion, restriction, objection, and data portability through the app or via privacy@planny.ai. Planny handles requests under the GDPR and may ask for verification before account data is shared or deleted.