← PlanGentle

Privacy

Short version: PlanGentle stores the data needed to run your account and plan. Your tasks and reflections are never used for advertising, never sold, never sent to AI services, and never read by us. With your consent, XPmetric and Google Analytics 4 measure selected page visits and planning milestones using first-party cookies.

1. Who is responsible

Stefan Rosanitsch, Kriegerdankstr. 14, 96450 Coburg, Germany. Email: stefanrows@gmail.com.

2. What we store and why

DataPurposeLegal basis (GDPR)
Email address; name and profile image if you sign in with GoogleYour account and signing inArt. 6(1)(b) contract
Your tasks, notes, commitments, settings and reflectionsProviding the plannerArt. 6(1)(b) contract
Feedback text, optional day rating and consent choicesReviewing voluntary feedback to improve PlanGentleArt. 6(1)(a) consent
Email address, only when you separately ask for a replyReplying to that feedback by emailArt. 6(1)(a) consent
Selected cancellation category, capture timestamp and suppression flagUnderstanding cancellations, honoring objections and category expiryArt. 6(1)(f) improving the service; you may object
One-way hash of request source or shared fallback key, in server memoryLimiting feedback spam; it expires after one hour and is not saved in the databaseArt. 6(1)(f) preventing abuse
Sessions, with the IP address and browser type they started fromKeeping you signed in; letting sign-out end a session everywhereArt. 6(1)(b) contract; 6(1)(f) security
Short-lived counters keyed by IP address or email addressLimiting sign-in attempts and sign-in emailsArt. 6(1)(f) preventing abuse
Trial dates, Stripe customer and subscription identifiers, subscription status and period endKnowing whether you can edit; your subscriptionArt. 6(1)(b) contract
Which trial emails were sent, and whether you opted outSending each trial email once, and never after you opt outArt. 6(1)(f) informing you about your trial
Page URL and path, referrer, campaign details, browser and device details, approximate location, visitor and session IDs, and planning, time-budget-use, signup, first-save, return-day and checkout-start event namesUnderstanding site traffic and improving PlanGentle, only if you accept analyticsArt. 6(1)(a) consent

We never receive your card details: payment happens on Stripe’s pages. A necessary cookie keeps you signed in, and another remembers your cookie choice. If you accept analytics, XPmetric sets the first-party_xpm_id visitor cookie and Google Analytics 4 sets first-party _ga cookies, each for up to one year. Google receives selected page views and fixed event names, plus browser and device information and your IP address for processing. We send Google page URLs without query parameters or fragments, and do not send account IDs, emails, task or reflection content. We disable enhanced measurement, Google Signals and advertising personalisation. You can change your choice through Cookie settings in the footer; withdrawing analytics consent removes the analytics cookies and reloads the page to stop tracking. A necessary opt-out receipt retries removal of the server identity link after a failed request; it clears when acknowledged. Until the server receives the request, an offline browser cannot remove an existing link. New tracking stays disabled while removal is pending. If you accept analytics and start checkout, we attach XPmetric’s visitor and session IDs to the Stripe checkout and subscription so XPmetric can attribute payments to traffic sources.

Milestone events contain only fixed event names, never task titles, first actions, emails, notes, draft identifiers or sign-in tokens. We keep a first-save timestamp with your account to prevent counting a deleted task as a new activation, plus a signup marker valid for five minutes and the last consented active UTC day to prevent duplicate events. The signup marker clears on the next measured account visit. These markers are removed when your account is deleted. Actions taken before analytics consent are never replayed. Blocked tracking, other browsers and missing consent leave outcomes unknown. A checkout start is not a payment; payments come from verified provider records.

The public daily time-budget worksheet keeps its clock times, labels, estimates and buffer in page memory only. It does not save them to browser storage or send them to our server or an AI service. After you accept analytics, choosing to print may send the fixed pg_time_budget_used event name; worksheet values and labels are not included.

With analytics consent, PlanGentle also temporarily stores XPmetric’s visitor ID and the time our server received your first eligible signed-out landing request so it can link a later account in the same browser. A server export uses XPmetric’s verified first-landing time and a site-specific keyed hash of the account ID. We do not send raw account IDs, email addresses, task or reflection content, diagnoses, authentication tokens or draft identifiers to XPmetric. Withdrawing consent removes the stored visitor-to-account link. A minimal visitor ID and opt-out timestamp prevent delayed requests from restoring it; these and anonymous landing IDs expire after 180 days. The export remains partial because it cannot identify visitors who never create an account or prove every measured arrival was captured.

The optional form at Help sends only the words and choices you submit. It does not attach tasks, reflections, account identity or page content. A reply address is stored only when you separately check the email reply box. Each submission is saved outside your account and shown a reference you can use for a privacy request. The optional day rating describes that day; it is not a health measure. In the Stripe Customer Portal, you may also choose a structured cancellation reason. PlanGentle stores only the selected category from the signed webhook, never a free-text cancellation comment. You can object to our use of that category by contacting us; we will remove it from our billing record and set a minimal suppression flag so later Stripe updates cannot restore it. The category and its capture timestamp are removed from the live database after 90 days; encrypted backups can retain a deleted copy until the relevant snapshot rotates out, for up to 93 days. The suppression flag contains no reason and stays with the billing row until that row is removed after account deletion. Suppression also applies to future cancellation reasons if you renew; this prevents later Portal updates from restoring a reason after you object or it expires.

If you try a task before signing in, its title, first action and time estimate stay in this browser’s local storage so they can survive sign-in. They are sent to your account only when you choose to save the task and sign in. A draft expires after 7 days without changes; we clear expired drafts the next time you open the trial flow. You can clear a draft yourself there at any time, and we remove the local copy after a confirmed save. Drafts do not move between browsers or devices before you save them to your account.

While signed in, unfinished capture, editor and focus text can be stored in encrypted browser storage on this device for recovery. These drafts are separate from your saved account plan and are not sent automatically. The browser holds the encryption key; this does not protect against someone with access to your unlocked browser. Drafts stay until saved, discarded, or cleared through sign-out, account deletion, account switching or the local-draft reset control. If storage or cleanup fails, the app says so. Clearing browser data can also remove drafts. They are not a backup and do not travel between devices.

3. Who processes data for us

RecipientWhat forWhere
Hetzner Online GmbHThe server and database holding your account, plan, separate feedback entries and selected cancellation categoryGermany (Nuremberg)
Resend, Inc.Sending sign-in and trial emails (your address and the email; never plan content)Sent from the EU region (Ireland); US company — SCCs, DPF
Cloudflare, Inc.DNS for plangentle.com, and the network every request passes through on its way to our server (encrypted connections, protection against attacks). Cloudflare sees your IP address and the requests you make, and does not keep your plan.USA / global — SCCs, DPF
Google (Ireland Ltd. / LLC)Sign-in, only if you choose “Sign in with Google”. Separately, our support address is a Gmail mailbox, so Google holds any email you send us and any reply we send if you asked for one. If you accept analytics cookies, Google Analytics 4 also processes selected page views and fixed planning events to help us understand use of the site. See Google’s privacy policy.Ireland / USA — SCCs, DPF
Stripe / LinkCheckout, payments, receipts, VAT and the billing portal. As seller of record under Stripe Managed Payments, Link processes payment data as its own controller under its privacy policy. Stripe also receives any cancellation category you choose in its Customer Portal; PlanGentle receives only the category in the signed subscription webhook.Ireland / USA — SCCs, DPF
XPmetricPage visits, planning milestones and payment attribution analytics, only after you accept analytics cookies; no plan or reflection content is sent. See the XPmetric privacy policy.Germany

Transfers to the USA rely on the EU-US Data Privacy Framework where the provider is certified, otherwise on Standard Contractual Clauses. US authorities may still be able to access such data under US law.

4. How long we keep it

5. Your rights

You have the right to access, rectify, erase and restrict processing of your data, to data portability, and to object to processing based on legitimate interests (Art. 15–21 GDPR). Two of these are built in: export downloads your whole plan as a file, and delete account removes it (both under “Research, privacy & your data” in the app). For anything else, email us; we answer within one month. For a feedback entry, include the reference shown after submission so we can locate it; entries without a reference or reply address may not be linkable to you. Trial emails can be stopped from the link in each one.

You may complain to a data protection authority, in particular in your country of residence. The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

6. No automated decisions

We make no automated decisions about you with legal or similarly significant effect, and no profiling.

See also the terms of use.