Privacy
Short version: PlanGentle stores the data needed to run your account and plan. Your tasks and reflections are never used for advertising, never sold, never sent to AI services, and never read by us. With your consent, XPmetric and Google Analytics 4 measure selected page visits and planning milestones using first-party cookies.
1. Who is responsible
Stefan Rosanitsch, Kriegerdankstr. 14, 96450 Coburg, Germany. Email: stefanrows@gmail.com.
2. What we store and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address; name and profile image if you sign in with Google | Your account and signing in | Art. 6(1)(b) contract |
| Your tasks, notes, commitments, settings and reflections | Providing the planner | Art. 6(1)(b) contract |
| Feedback text, optional day rating and consent choices | Reviewing voluntary feedback to improve PlanGentle | Art. 6(1)(a) consent |
| Email address, only when you separately ask for a reply | Replying to that feedback by email | Art. 6(1)(a) consent |
| Selected cancellation category, capture timestamp and suppression flag | Understanding cancellations, honoring objections and category expiry | Art. 6(1)(f) improving the service; you may object |
| One-way hash of request source or shared fallback key, in server memory | Limiting feedback spam; it expires after one hour and is not saved in the database | Art. 6(1)(f) preventing abuse |
| Sessions, with the IP address and browser type they started from | Keeping you signed in; letting sign-out end a session everywhere | Art. 6(1)(b) contract; 6(1)(f) security |
| Short-lived counters keyed by IP address or email address | Limiting sign-in attempts and sign-in emails | Art. 6(1)(f) preventing abuse |
| Trial dates, Stripe customer and subscription identifiers, subscription status and period end | Knowing whether you can edit; your subscription | Art. 6(1)(b) contract |
| Which trial emails were sent, and whether you opted out | Sending each trial email once, and never after you opt out | Art. 6(1)(f) informing you about your trial |
| Page URL and path, referrer, campaign details, browser and device details, approximate location, visitor and session IDs, and planning, time-budget-use, signup, first-save, return-day and checkout-start event names | Understanding site traffic and improving PlanGentle, only if you accept analytics | Art. 6(1)(a) consent |
We never receive your card details: payment happens on Stripe’s pages. A necessary cookie keeps you signed in, and another remembers your cookie choice. If you accept analytics, XPmetric sets the first-party_xpm_id visitor cookie and Google Analytics 4 sets first-party _ga cookies, each for up to one year. Google receives selected page views and fixed event names, plus browser and device information and your IP address for processing. We send Google page URLs without query parameters or fragments, and do not send account IDs, emails, task or reflection content. We disable enhanced measurement, Google Signals and advertising personalisation. You can change your choice through Cookie settings in the footer; withdrawing analytics consent removes the analytics cookies and reloads the page to stop tracking. A necessary opt-out receipt retries removal of the server identity link after a failed request; it clears when acknowledged. Until the server receives the request, an offline browser cannot remove an existing link. New tracking stays disabled while removal is pending. If you accept analytics and start checkout, we attach XPmetric’s visitor and session IDs to the Stripe checkout and subscription so XPmetric can attribute payments to traffic sources.
Milestone events contain only fixed event names, never task titles, first actions, emails, notes, draft identifiers or sign-in tokens. We keep a first-save timestamp with your account to prevent counting a deleted task as a new activation, plus a signup marker valid for five minutes and the last consented active UTC day to prevent duplicate events. The signup marker clears on the next measured account visit. These markers are removed when your account is deleted. Actions taken before analytics consent are never replayed. Blocked tracking, other browsers and missing consent leave outcomes unknown. A checkout start is not a payment; payments come from verified provider records.
The public daily time-budget worksheet keeps its clock times, labels, estimates and buffer in page memory only. It does not save them to browser storage or send them to our server or an AI service. After you accept analytics, choosing to print may send the fixed pg_time_budget_used event name; worksheet values and labels are not included.
With analytics consent, PlanGentle also temporarily stores XPmetric’s visitor ID and the time our server received your first eligible signed-out landing request so it can link a later account in the same browser. A server export uses XPmetric’s verified first-landing time and a site-specific keyed hash of the account ID. We do not send raw account IDs, email addresses, task or reflection content, diagnoses, authentication tokens or draft identifiers to XPmetric. Withdrawing consent removes the stored visitor-to-account link. A minimal visitor ID and opt-out timestamp prevent delayed requests from restoring it; these and anonymous landing IDs expire after 180 days. The export remains partial because it cannot identify visitors who never create an account or prove every measured arrival was captured.
The optional form at Help sends only the words and choices you submit. It does not attach tasks, reflections, account identity or page content. A reply address is stored only when you separately check the email reply box. Each submission is saved outside your account and shown a reference you can use for a privacy request. The optional day rating describes that day; it is not a health measure. In the Stripe Customer Portal, you may also choose a structured cancellation reason. PlanGentle stores only the selected category from the signed webhook, never a free-text cancellation comment. You can object to our use of that category by contacting us; we will remove it from our billing record and set a minimal suppression flag so later Stripe updates cannot restore it. The category and its capture timestamp are removed from the live database after 90 days; encrypted backups can retain a deleted copy until the relevant snapshot rotates out, for up to 93 days. The suppression flag contains no reason and stays with the billing row until that row is removed after account deletion. Suppression also applies to future cancellation reasons if you renew; this prevents later Portal updates from restoring a reason after you object or it expires.
If you try a task before signing in, its title, first action and time estimate stay in this browser’s local storage so they can survive sign-in. They are sent to your account only when you choose to save the task and sign in. A draft expires after 7 days without changes; we clear expired drafts the next time you open the trial flow. You can clear a draft yourself there at any time, and we remove the local copy after a confirmed save. Drafts do not move between browsers or devices before you save them to your account.
While signed in, unfinished capture, editor and focus text can be stored in encrypted browser storage on this device for recovery. These drafts are separate from your saved account plan and are not sent automatically. The browser holds the encryption key; this does not protect against someone with access to your unlocked browser. Drafts stay until saved, discarded, or cleared through sign-out, account deletion, account switching or the local-draft reset control. If storage or cleanup fails, the app says so. Clearing browser data can also remove drafts. They are not a backup and do not travel between devices.
3. Who processes data for us
| Recipient | What for | Where |
|---|---|---|
| Hetzner Online GmbH | The server and database holding your account, plan, separate feedback entries and selected cancellation category | Germany (Nuremberg) |
| Resend, Inc. | Sending sign-in and trial emails (your address and the email; never plan content) | Sent from the EU region (Ireland); US company — SCCs, DPF |
| Cloudflare, Inc. | DNS for plangentle.com, and the network every request passes through on its way to our server (encrypted connections, protection against attacks). Cloudflare sees your IP address and the requests you make, and does not keep your plan. | USA / global — SCCs, DPF |
| Google (Ireland Ltd. / LLC) | Sign-in, only if you choose “Sign in with Google”. Separately, our support address is a Gmail mailbox, so Google holds any email you send us and any reply we send if you asked for one. If you accept analytics cookies, Google Analytics 4 also processes selected page views and fixed planning events to help us understand use of the site. See Google’s privacy policy. | Ireland / USA — SCCs, DPF |
| Stripe / Link | Checkout, payments, receipts, VAT and the billing portal. As seller of record under Stripe Managed Payments, Link processes payment data as its own controller under its privacy policy. Stripe also receives any cancellation category you choose in its Customer Portal; PlanGentle receives only the category in the signed subscription webhook. | Ireland / USA — SCCs, DPF |
| XPmetric | Page visits, planning milestones and payment attribution analytics, only after you accept analytics cookies; no plan or reflection content is sent. See the XPmetric privacy policy. | Germany |
Transfers to the USA rely on the EU-US Data Privacy Framework where the provider is certified, otherwise on Standard Contractual Clauses. US authorities may still be able to access such data under US law.
4. How long we keep it
- Your plan and account: for as long as your account exists — including after a trial or subscription ends, so you can always export it.
- After you delete your account: 30 days, during which signing in again cancels the deletion; then your plan, account, sessions and billing record are removed.
- Import undo snapshot: 7 days.
- Sessions: 30 days after last use, or until you sign out.
- Unused sign-in links: 15 minutes.
- Feedback text and any reply address: 90 days in the live database, then removed by the scheduled retention sweep. Encrypted backups use 7 daily snapshots, Sunday snapshots for 28 days and first-of-month snapshots for 93 days; a deleted entry can remain in a snapshot until that copy rotates out. The feedback table has no account link; use the reference shown after submission to ask for earlier access or deletion.
- A selected cancellation category and capture timestamp: for up to 90 days in the live database, then removed by the scheduled retention sweep. Encrypted backups can retain a deleted copy until the snapshot rotates out, for up to 93 days. A selected category is also cleared if you reverse a scheduled cancellation. A minimal suppression flag remains in the billing row after an objection or expiry to prevent a later Stripe update from restoring the category; it contains no reason and is removed with the billing row after the 30-day account deletion grace period. Suppression remains in effect if you renew, so a later cancellation category is not collected for that billing row.
- XPmetric visitor cookie: one year unless you withdraw analytics consent sooner. XPmetric retains analytics events for two years.
- Google Analytics cookies: up to one year unless you withdraw analytics consent sooner. We set GA4 user and event-level retention to two months, without resetting user retention on new activity. Google’s standard aggregate reports are not covered by that setting.
- Stripe keeps payment records as long as tax and commercial law require; that is outside our control.
5. Your rights
You have the right to access, rectify, erase and restrict processing of your data, to data portability, and to object to processing based on legitimate interests (Art. 15–21 GDPR). Two of these are built in: export downloads your whole plan as a file, and delete account removes it (both under “Research, privacy & your data” in the app). For anything else, email us; we answer within one month. For a feedback entry, include the reference shown after submission so we can locate it; entries without a reference or reply address may not be linkable to you. Trial emails can be stopped from the link in each one.
You may complain to a data protection authority, in particular in your country of residence. The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
6. No automated decisions
We make no automated decisions about you with legal or similarly significant effect, and no profiling.
See also the terms of use.