Legal
Privacy policy
Planner.day ("Planner.day", "we", "us") is a task and project management service operated by LocoBuzz Solutions Pvt. Ltd. This policy explains what personal data we collect, how we use it, who we share it with, and how we protect it. It covers the Planner.day web application, its API, and the optional integrations you can connect to it.
What we collect
- Account data — name, email address and workspace membership.
- Content — tasks, comments, attachments and anything else you create.
- Feedback submissions — if you embed the widget, the reporter's message and, where they provide it, their email address.
- Usage data — request logs and error traces used to operate the service.
- Integration data — where you connect a third-party account, the data described in the relevant section below.
How we use your data
- To provide the service — storing your work, showing it to the people you share a workspace with, and sending the notifications you have enabled.
- To operate and secure the service — diagnosing faults, preventing abuse, and keeping backups.
- To bill you, where you are on a paid plan.
- To reply when you contact us for support.
We do not use your data for advertising, and we do not profile you for any purpose unrelated to running the service.
Google user data
Planner.day offers an optional Google Calendar integration. Nothing below applies unless you choose to connect it.
What we request, and why
When you connect the integration we request three OAuth scopes:
openid and email to identify the Google account being connected,
and https://www.googleapis.com/auth/calendar.readonly to read your calendar.
The calendar scope is read-only; it is the narrowest scope that supports
the feature.
How we use it
We use this access for a single purpose: to display your existing Google Calendar events alongside your tasks in the Planner.day calendar view, so that meetings and work appear in one place. We do not create, modify, or delete anything in your Google Calendar.
- Calendar events are fetched on demand when you open the calendar.
- They are held in a temporary server-side cache for no more than 10 minutes, then discarded.
- They are never written to our database.
- They are visible only to you. No other member of your workspace, and no workspace administrator, can see your Google Calendar data.
Google user data and AI
Google user data is never sent to any artificial intelligence or machine learning provider, and is never used to develop, train, or improve any generalised or foundational AI/ML model. Planner.day's optional AI features are described below and operate on a separate data path that has no access to Google user data.
Disconnecting
You can disconnect the integration at any time from Settings → Integrations in Planner.day, which deletes the stored authorisation tokens. You can also revoke access directly from your Google account permissions page.
Limited Use
Planner.day's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who we share data with
We do not sell, rent or trade personal data. We share it only in the circumstances below, and where we use a service provider they act on our written instructions and may not use the data for their own purposes.
- Within your workspace — content you create is visible to the members of the workspace you created it in. Google Calendar data is the exception: it is never shared with other members.
- Infrastructure providers — Amazon Web Services, which hosts the application, its database and its file storage.
- Operational service providers — transactional email delivery, error and performance monitoring, and payment processing for paid plans.
- Integrations you connect — where you link a third-party account such as Google Calendar, GitHub or Slack, data moves between Planner.day and that service only as needed for the feature you enabled, and subject to that provider's terms.
- Legal and safety — where we are required to by law, or where disclosure is necessary to investigate fraud, enforce our terms, or protect the rights and safety of our users.
- Business transfers — if Planner.day is involved in a merger, acquisition or sale of assets, data may transfer as part of that transaction. We will give notice before it becomes subject to a different privacy policy.
Google user data is not disclosed to any third party other than the infrastructure provider that hosts the service. It is not shared with other users, not sold, not used for advertising, and not transferred to any AI/ML provider.
How we protect your data
- In transit — all traffic to Planner.day is encrypted with TLS 1.2 or higher.
- At rest — data is stored on encrypted infrastructure. OAuth access and refresh tokens for connected accounts, including Google, are additionally encrypted before they are stored and are readable only by the Planner.day service.
- Access control — data is scoped to the workspace it belongs to. Google Calendar data is scoped to the individual who granted it. Internal access by our staff is restricted to personnel who need it to operate or support the service.
- Minimisation — we request the narrowest scopes that support a feature, and we do not persist data we do not need. Google Calendar events are cached briefly and never stored.
- Passwords — stored only as salted hashes; we cannot read them.
AI features
Planner.day offers optional AI features, such as summarising software development activity linked to a task. These run on Amazon Bedrock within our own cloud account. Prompts are built only from the specific content required for the feature you invoked. Amazon Bedrock does not retain those inputs or use them to train models, and we do not use your content to train any model of our own.
As stated above, Google user data is excluded from all AI features.
What we do not do
- We do not sell personal data.
- We do not use your content to train models.
- We do not transfer Google user data to AI/ML providers.
- We do not run third-party advertising trackers on this site.
Retention
Content is retained while your account is active. Deleting a workspace removes its content subject to backup rotation. Authorisation tokens for a connected integration are deleted when you disconnect it. Cached Google Calendar events expire within 10 minutes and are never retained.
Your rights
You can request access, correction, export or deletion of your personal data by emailing
privacy@planner.day. Depending on where you live you may also have the right to
object to or restrict certain processing, and to complain to your local data protection
authority.
Changes to this policy
We may update this policy to reflect changes to the service or to legal requirements. The date at the top of this page shows when it was last revised, and we will give notice of material changes before they take effect.
Contact
Questions about this policy, or about how we handle your data, go to
privacy@planner.day.