← Planrotfish

Privacy Policy

Last updated: August 14, 2026

This policy explains what Planrotfish stores, why, and what control you have over it. The short version: we store what the product needs to work, in the EU, we don’t sell it, and you can have it exported or deleted at any time.

Who is responsible

The data controller for planrotfish.com is the operator of Planrotfish. For anything in this policy — questions, requests, complaints — contact support@planrotfish.com.

What we store

  • Account data — email address, display name, avatar, and authentication records (managed through Supabase Auth).
  • Your content — workspaces, projects, tasks, comments, time entries, calendar events you create, and images you attach.
  • Integration data — when you connect Google Calendar, Outlook, a git provider or Slack: the events and issues we sync for you, plus OAuth tokens stored encrypted (AES-256-GCM). We request the minimum scopes the feature needs.
  • Billing data — your subscription status, mirrored from Stripe. Card details never touch our servers; under Stripe Managed Payments, Link is the merchant of record. Stripe sends receipts, invoices and refund notices to you directly.
  • Operational data — short-lived server logs (IP address, request metadata) for security and debugging, and rate-limiting counters keyed by user, token or IP address. Neither contains your content.

Why we process it

  • To provide the Service (performance of our contract with you) — accounts, your content, syncing, subscription status.
  • To keep the Service secure and working (legitimate interest) — logs, rate limiting, abuse prevention.
  • Integrations you choose to connect (consent) — withdraw at any time by disconnecting them in Settings, which also deletes the stored tokens.
  • Invoicing and tax records (legal obligation) — handled by Stripe as merchant of record, including sales tax/VAT/GST in the countries Managed Payments covers.

We don’t use your data for profiling or automated decisions that have legal effects.

Where it lives

Application data is hosted in the European Union: our database and file storage run on Supabase (eu-central-1, Frankfurt) and the application on Vercel (fra1, Frankfurt).

Sub-processors

  • Supabase — database, authentication, file storage
  • Vercel — application hosting, request logs
  • Stripe / Link — payments, tax and payment support (merchant of record)
  • Upstash — rate-limiting counters (no content data)
  • Google / Microsoft / GitHub / GitLab / Slack — only for the integrations you connect

Some of these providers are established outside the EU/EEA. Where personal data leaves the EU/EEA, the transfer is protected by an adequacy decision (including the EU-U.S. Data Privacy Framework, where the provider is certified) or by EU Standard Contractual Clauses. We keep this list current on this page.

Google user data

Planrotfish’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data — from Google and Microsoft alike — is used only to show and sync your calendar inside the product: never for advertising, never for training AI models, and never sold.

What we don’t do

  • No selling or renting of personal data.
  • No advertising built on your content.
  • No third-party analytics scripts inside the app.

How long we keep it

  • Your content stays until you delete it or your account is deleted.
  • Account deletion permanently removes your personal data and content from our live systems; encrypted backups age out on a short rolling window afterwards.
  • Server logs are short-lived and deleted automatically.
  • Invoicing records are retained by Stripe for as long as tax law requires.

Your rights

You can ask for access to your data, a machine-readable export, correction, restriction of processing, or deletion of your account and everything in it. Email support@planrotfish.com and we’ll respond within one month. If you’re in the EU/EEA, you have all the rights the GDPR describes — including objection and data portability — and the right to lodge a complaint with your local supervisory authority.

Cookies

We use only the cookies required to keep you signed in (Supabase auth session). No tracking or advertising cookies — which is why there’s no cookie banner.

Security

All traffic is encrypted in transit (TLS) and data is encrypted at rest. OAuth tokens for connected integrations are additionally encrypted at the application level (AES-256-GCM), file attachments are served through expiring signed URLs, and workspace content is protected by per-workspace access controls. If you create a calendar feed link (ICS), anyone who has that link can read the events in that feed — treat feed links like passwords.

Children

The Service is not directed at children and requires users to be at least 16 years old.

Changes

If this policy changes materially, we’ll announce it in the app or by email before the change takes effect.

Contact

Privacy questions and requests: support@planrotfish.com.