Privacy Policy

Last updated 9 October 2026

What personal data planpage holds, why, who helps us process it, how long we keep it, and how to exercise your rights.

The short version

  • planpage is run by Bifrost Development Ltd. We are the controller of the personal data described here. Contact us at hello@planpa.ge.
  • You sign in with GitHub, Discord or a link we email you. We keep your name, avatar link, your planpage username, your verified email addresses (the ones GitHub or Discord report, and any you add and verify yourself), and the content you and your agents create.
  • We do not run analytics, advertising or tracking. The only cookies we set are the ones the service needs to work.
  • We do not run AI models. The agents you connect are your own tools. What they send us is stored like anything else you write.
  • Everything is hosted on Cloudflare. We use a small number of other services, listed below, only when you use the feature that needs them.
  • We keep your data while your account exists. A few things are kept for a fixed time, set out below.
  • You can export or delete your account yourself from Your account. You can also ask to see, correct, export or delete your data by emailing hello@planpa.ge, and you can complain to the Information Commissioner's Office.

Who we are

planpage (https://planpa.ge, with the app at https://app.planpa.ge) is a trading name of Bifrost Development Ltd, a company registered in England and Wales. Bifrost Development Ltd is the controller of the personal data described in this policy, under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

You can reach us about anything in this policy at hello@planpa.ge.

What this policy covers

This policy covers:

  • the planpage website and app;
  • the planpage MCP server and API, which AI agents use on your behalf;
  • public share pages on share.planpa.ge and on custom domains people connect;
  • emails and browser notifications we send.

It does not cover the AI agents or MCP clients you connect (such as Claude Code, Claude, Cursor or ChatGPT), GitHub, Discord, or any other service you use alongside planpage. Each of those has its own privacy policy.

What we collect

Your account

When you sign in with GitHub or Discord, we receive and keep:

  • your display name (your GitHub name or login, or your Discord display name or username);
  • a link to your avatar image on GitHub or Discord;
  • the email addresses the provider reports, with whether each is verified. From GitHub we fetch the full list of addresses on your account. From Discord we receive the one address on your account. One verified address is your primary address;
  • your user ID at the provider, and the access and refresh tokens the provider issues to us, so we can keep your email addresses up to date. We encrypt these tokens (AES-GCM) before storing them;
  • which providers are linked to your account, and when.

You also choose a username, shown with a four-digit tag (for example priya#0427). It starts filled in from your GitHub login or Discord username. Other planpage users see your name, avatar and username: people find you by it to invite you or share documents with you. Your email address is shown only to people in a workspace with you. Anyone who types your exact username can find your name and avatar.

You can also sign in with an email link: you give us your address, we email it a link that works once, for 15 minutes, and keep a hash of the link until it's used or runs out. If no account has that address yet, using the link creates one, and we ask for your name and a username. We keep a record of each sign-in email we send (address, time, whether it was delivered) to stop the form being used to flood someone's inbox.

You can add passkeys to sign in with your device's fingerprint, face or PIN check. For each one we keep its public key and credential ID (never anything that could sign in by itself), an identifier for the kind of authenticator that made it (for example iCloud Keychain or 1Password), whether it syncs between devices, a signature counter, and when you added it. The private key stays on your device or in your password manager. Removing a passkey deletes our copy.

You can add an email address that didn't come from a provider. We send it a six-digit code and a confirm link, keep hashes of both for up to 15 minutes, and add the address once you enter the code or use the link while signed in. Once verified, signing in with a GitHub or Discord account that has that verified address signs into your account. When you make a different address primary, we tell the old one.

We also store your interface theme (system, light or dark), your platform role (almost everyone is a "user"), and whether your account has been suspended, with the reason and end date.

Sign-in sessions

Each time you sign in we create a session record holding the IP address and browser user agent you signed in from, the session's start and expiry times, and the workspace you have open. If a member of staff is viewing your account for support (see "Staff access"), the session records that too.

Workspaces and membership

For each organisation workspace: its name, short name (slug), colour, and its members with their roles (owner, admin, reviewer, member or viewer). For invitations: who was invited (their account, or for older invitations their email address), the role offered, who sent it, whether it was accepted or declined, and when it expires (seven days). For invite links: the role, who created the link, its expiry, how many times it may be used and has been used.

What you and your agents create

This is the main thing planpage holds:

  • projects, with an optional linked repository URL;
  • documents (plans, reports, reviews, decision records and briefs), every saved version of each, and who or which agent session wrote each version;
  • comments and replies, reviews (approve, request changes or comment, with any note), answers to questions and picks on decisions;
  • steps and their status, notes and claims;
  • links to commits, pull requests, branches and other URLs;
  • an activity timeline of who did what to each document;
  • your inbox of notifications, which documents you have stopped following, and which documents you have been asked to review.

Anything you or your agents put into a document is stored as written. Please don't put personal data about other people, or secrets such as passwords and keys, into documents unless you need to.

Agent connections

When you connect an AI agent we record:

  • the connection's name, whether it uses OAuth or an API token, which workspaces it may reach and at what access level (read, publish, or write), when it was created and last seen, and whether it has been revoked;
  • for API tokens: a SHA-256 hash of the token (never the token itself), its first few characters so you can recognise it, and its expiry;
  • for each agent session: a label, and, if the agent supplies them, the model name, client name, repository and branch it is working on.

OAuth grants for agents are held by the OAuth service that runs on Cloudflare (see "Security").

Notifications

  • Email notifications are off until you turn them on. We store your choice (off, as they happen, or a daily digest) and which kinds of notification you want.
  • Browser push notifications are off until you allow them in your browser. We store the push address your browser gives us, the encryption keys for it, your browser's user agent, and when a notification last reached it.
  • Emails sent: for every email we send (invitations, share notices, notifications, digests, email address codes, account notices, and test emails sent by staff) we log the recipient address, subject, type, whether it was sent, and any error.

Sharing

  • Public share links: the document, an optional password (stored only as a salted hash), an optional expiry, an optional pinned version, who created the link, and a count of views. We do not record who viewed the page.
  • Abuse reports on share pages: the reason and any details the reporter types. We do not store the reporter's IP address. We store a keyed hash of the IP address combined with the date, which lets us spot repeat reports from the same place on the same day without knowing who sent them.
  • Sharing with people: who a document is shared with (their account, or for older shares an email address), what they can do (view, comment, review or edit), who shared it, and when.
  • Custom domains: the hostname and its verification status.

Integrations and imports

  • GitHub App: if you install the planpage GitHub App, we store the installation's account name and type, and details of the pull requests you link to plans (repository, number, commit, title, state and check status). We also keep a list of the repositories the app is installed on (name, URL, whether it is private or archived, and when it was last pushed to) so that members of the workspace who can create projects can pick one. That includes the names of private repositories.
  • Zipline import: the address of the Zipline server you import from. The Zipline API token you give us is held only while the import runs and is deleted when it finishes or fails.

Billing

Paid plans are switched off during early access, so we do not collect payment information. If we introduce paid plans, we will store the plan, number of seats, subscription status, renewal date, and the customer and subscription IDs from Polar. Polar handles payment details; we never see card numbers.

Security and audit records

We keep an audit log of actions that change accounts and workspaces: for example signing in with a new provider, changing your primary email, creating or deleting a workspace, inviting or removing members, changing roles, and staff actions such as suspensions and account views. Each entry records who acted, any member of staff acting on their behalf, the workspace, what was done, and to what. Some entries include an email address (for example, the address invited to a workspace).

You can see the entries that concern your own account under Your account, then Security log.

Performance measurements

To keep the service fast we record how long pages take to load. Each measurement holds only the kind of page (for example "/d/:id", with identifiers removed), the time taken, and a breakdown by stage. Measurements from browsers are only accepted from signed-in browsers but are not linked to you, your session, your IP address or your browser.

Operational logs

Cloudflare, which runs planpage, keeps short-lived operational logs of requests and errors, which can include IP addresses and request details. We use them only to keep the service running and to investigate faults and attacks.

How we use it, and our lawful bases

What we do Data used Lawful basis
Create and run your account, sign you in, and keep your email addresses up to date Account, sessions Contract: we need it to provide the service you signed up for
Store, show and sync your workspaces, documents, comments and reviews, including live editing Workspaces, content Contract
Let agents you connect read and write on your behalf Agent connections, content Contract
Send invitations and share notices to people a workspace owner, admin or editor picks Their account and email address Legitimate interests: letting people bring colleagues into a workspace or a document
Send email notifications and digests Email address, notification preferences, inbox Consent: you turn these on, and can turn them off at any time, including with the one-click unsubscribe link in each email
Send browser push notifications Push subscription Consent: you allow them in your browser and can withdraw at any time
Publish public share pages and handle abuse reports Share links, abuse reports Contract (for the person sharing); legitimate interests (keeping the service free of abuse)
Post plan status to GitHub pull requests GitHub App data, plan title, status and step titles Contract: you install the app and link the pull request
Suggest repositories when creating a project GitHub App repository list, project repository URLs Contract: you install the app on those repositories
Keep the service secure, prevent abuse, and enforce our terms Sessions, audit log, suspensions, operational logs Legitimate interests: protecting you, other users and the service
Provide support, including viewing your account when needed Account, content, audit log Legitimate interests: resolving problems you or your workspace report
Measure and improve performance Performance measurements Legitimate interests: a fast, reliable service. These measurements are not linked to you
Take payment, if paid plans are introduced Billing records Contract, and legal obligation (tax and accounting records)
Respond to legal requests and defend legal claims Any relevant data Legal obligation; legitimate interests

Where we rely on legitimate interests, we have weighed them against your rights. You can object (see "Your rights").

We do not sell personal data, use it for advertising, profile you, or make decisions about you by automated means that have legal or similarly significant effects.

AI agents you connect

planpage does not run AI models itself and does not send your content to any AI provider.

The agents you connect (such as Claude Code, Claude, Cursor, ChatGPT or another MCP client) are third-party tools that you choose and control. When you connect one, you choose which workspaces it can reach and its access level in each:

  • read: read projects and documents;
  • publish: read, and publish and update documents;
  • write: everything above, plus claim and update steps as it carries out an approved plan.

An agent can never do more than you can in a workspace. What the agent reads from planpage is passed to that agent and its provider under their terms, not ours. What it sends us is stored like any other content. You can see and revoke your connections under Your account, then Agent connections.

Content in organisation workspaces

When you work in an organisation workspace, the owners and admins of that workspace decide who can see its content, can export it, and can delete the workspace. Other members see your name, avatar, comments, reviews and the documents you write there, according to their role. If you leave a workspace or delete your account, what you contributed to an organisation workspace stays part of that workspace's record. After your account is deleted, those contributions are shown as written by "Deleted user".

A public share link makes a document readable by anyone who has the link, without signing in. Share pages ask search engines not to index them and run no scripts. You can add a password or an expiry date, pin a version, and revoke a link at any time. If a shared document includes images hosted elsewhere, the visitor's browser fetches those images from wherever they are hosted.

People can also share one document with you by your username. You see only that document, with the access they gave you, and you get notices about it.

Who we share it with

We use the following service providers. Each processes data only to provide its service to us.

Provider What for When
Cloudflare, Inc. Hosting, database (D1), key-value storage, real-time collaboration (Durable Objects), content delivery, custom domains, network security and operational logs Always
GitHub, Inc. Signing in with GitHub; the GitHub App, if you install it When you use GitHub sign-in or install the app
Discord Inc. Signing in with Discord When you use Discord sign-in
Our email provider Delivering invitations, notifications and digests by email When an email is sent to you
Browser push services (for example Google, Mozilla or Apple, depending on your browser) Delivering push notifications. The notification is encrypted so that only your browser can read it When you allow push notifications
Polar Software, Inc. Payments, as merchant of record. Polar is responsible for the payment data it collects Only if paid plans are introduced and you buy one

Your avatar is loaded by your browser from GitHub's or Discord's image servers.

Documents can include images hosted on other websites. When you read such a document, in the app or on a share page, your browser fetches each image directly from the site that hosts it, which can see your IP address and browser details. We don't proxy these images.

If you link a pull request to a plan and the GitHub App is installed on that repository, planpage posts a comment on the pull request showing the plan's number, title, status and step titles, and sets a "planpage/approved" status on the commit. Anyone who can see that pull request can see that comment.

We may also disclose data where the law requires it, to protect people's safety, or as part of a sale or reorganisation of our business (in which case this policy will continue to apply to your data).

International transfers

Cloudflare runs planpage on its global network, so requests are handled in the data centre nearest to you or to our database. Our main database is located in western Europe, but copies and processing can occur in other countries, including the United States. GitHub, Discord, Polar and the browser push services are based in or operate from the United States. Your email provider may also process data outside the UK.

Where personal data leaves the UK, we rely on UK adequacy regulations where they apply (including the UK Extension to the EU-US Data Privacy Framework for certified US companies), or on the UK International Data Transfer Addendum to the EU standard contractual clauses. You can ask us for details.

How long we keep it

Data How long
Account, linked providers, email addresses While your account exists. When you delete your account, 14 days after you ask
Workspace content, versions, comments, reviews and activity While the workspace exists, or until the document or project is deleted. Deleting the workspace deletes all of it at once. If paid plans are introduced, free workspaces may keep only 30 days of older versions and activity; current and approved versions are always kept. We will tell you before this starts
Documents and projects in Trash 30 days, hidden from everyone, then deleted with their versions, comments, reviews and activity. Owners and admins can restore them before then, or delete them sooner
Sign-in sessions Until you sign out or the session expires. A session expires after seven days without use. Staff support sessions last at most one hour. Expired session records are deleted a day after they expire
Agent OAuth access Access tokens last one hour; refresh tokens last up to 90 days, or 30 days unused
API tokens and agent connections Until they expire or you revoke them. Revoked or expired ones are deleted 90 days later
Invitations Valid for seven days. The record is deleted 30 days after the invitation is accepted, cancelled or expires
Push subscriptions Until you turn push off, or your browser's push service tells us the address no longer works
Notification preferences While your account exists
Inbox items While your account exists. Items you mark done are deleted 180 days later
Zipline import token Only until the import finishes or fails
GitHub repository list While the app is installed. A repository is removed when you take it out of the installation on GitHub, and the whole list when the app is uninstalled or disconnected
Performance measurements 14 days
Email log 90 days
Audit log 2 years, because it is our record of security events and staff actions. In the record that an account was deleted, the name and email address are removed after 90 days
Abuse reports 1 year after the report is resolved or the share link is revoked
Billing records, if paid plans are introduced As long as tax and accounting law requires, normally six years
Database backups Deleted data can remain in Cloudflare's point-in-time recovery for up to 30 days

Deleting your account

You can delete your account yourself under Your account, then Profile, then Delete your account. We ask you to sign in again if your last sign-in was more than 15 minutes ago, and to type your primary email address. You can also email hello@planpa.ge from an address on your account and we will do it for you.

Your access ends as soon as you ask: we sign you out everywhere, revoke your agent connections, API tokens and the OAuth grants you gave agents, and remove your browser push subscriptions. The account itself is deleted 14 days later. Until then you can sign in and keep it, which protects you if someone else got into your account or you change your mind. We email your primary address when you ask and when the deletion is done.

If you are the only owner of an organisation workspace that other people use, you need to transfer ownership to another member or delete that workspace first. Workspaces where you are the only member are deleted with your account.

When we delete an account we remove your profile, linked providers, email addresses, sessions, personal workspace (its projects, documents, versions, comments, share links and any custom domain), the workspaces where you were the only member, workspace memberships, agent connections, tokens and OAuth grants, notification settings, inbox, push subscriptions and import history, guest access and pending invitations sent to your addresses, and the live-editing copies of deleted documents held by Cloudflare Durable Objects.

What you contributed to organisation workspaces that other people use (documents, versions, comments, reviews and activity) stays with those workspaces, shown as written by "Deleted user". Share links you created there keep working until someone in the workspace revokes them. The audit log keeps a record that the account was deleted, including the name and email address it had for 90 days (so we can spot an account coming back to evade a suspension), then without them. Earlier entries about the account follow the audit log's two-year period.

Deleted data can remain in Cloudflare's point-in-time recovery for up to 30 days after deletion.

Owners of an organisation workspace can delete it themselves from Workspace settings. That happens at once, without a Trash period, and removes its projects, documents, versions, comments, activity, share links, custom domain and the live-editing copies of its documents.

Cookies

We use only cookies that are strictly necessary for the service to work, so we don't ask for consent to them. We use no analytics, advertising or tracking cookies, and no third-party cookies.

Cookie What it does How long
Better Auth session cookie (better-auth.session_token) Keeps you signed in; your session also remembers which workspace you have open Until you sign out or the session expires
Short-lived sign-in cookies set by Better Auth Protect the GitHub or Discord sign-in flow against forgery, and support staff account views Minutes, or the length of the sign-in or support session
pp-theme Remembers whether you chose the light or dark theme, so pages don't flash the wrong one One year (removed if you choose "system")
pp-css Records which version of our stylesheet your browser already has, so we only include it in the page on your first visit 30 days
pp_unlock_… On a password-protected share page, remembers that you entered the right password 12 hours

Security

We protect your data with measures that include:

  • encryption in transit (HTTPS) for every page, API call and email connection we make;
  • data stored with Cloudflare, which encrypts its storage at rest;
  • API tokens stored only as SHA-256 hashes, and share-link passwords stored only as salted PBKDF2 hashes;
  • service credentials that staff configure (such as email and sign-in keys), and the GitHub and Discord tokens issued when you sign in, encrypted with AES-GCM before they are stored, each kind under its own key;
  • agent OAuth grant data encrypted by the OAuth service, which stores tokens only as hashes;
  • signed unsubscribe links, and share pages served with no scripts under a strict content security policy;
  • access limits by workspace role and by agent access level, with staff access logged.

No system is perfectly secure. If a breach affects your personal data in a way that is likely to put you at high risk, we will tell you without undue delay.

Staff access

A small number of staff can use planpage's admin tools. Support staff can view admin pages and, to resolve a problem, sign in as a user for up to one hour. Staff accounts cannot be viewed this way. Each time, the member of staff must give a reason. The start, the end and the reason are logged and shown in that person's Security log, and changes made during the visit are recorded against the member of staff as well as the account. Senior staff can also suspend accounts, sign accounts out, change roles, archive projects, remove members, delete workspaces and accounts, and take down share links; these actions are logged too.

Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • correct data that is wrong or incomplete;
  • delete your data;
  • restrict how we use it;
  • object to processing we carry out on the basis of legitimate interests;
  • data portability: receive the data you gave us in a machine-readable format;
  • withdraw consent at any time, where we rely on it (for example email and push notifications). This doesn't affect what we did before you withdrew it.

Some of this you can do yourself. You can export your account from Your account, then Your data: a zip with everything we hold about you (your profile, email addresses, linked logins, sessions, memberships, invitations, agent connections, inbox, notification and push settings, share links and guest access, imports, the audit entries about you and the emails we sent you), what you wrote in organisation workspaces you can't export yourself, and your personal workspace. It never includes tokens or password hashes. You can also export a workspace (a zip with every document as markdown, plus every version, comment, review, step, link and activity entry as JSON) from Your account, then Your data; for organisation workspaces this needs an owner or admin. You can change notification settings, unlink sign-in providers, change your primary email, revoke agent connections, and delete your account from Your account.

For anything else, email hello@planpa.ge. We may need to confirm it is you. We will reply within one month, or tell you if we need longer for a complex request. There is normally no charge.

If you are unhappy with how we handle your data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator: https://ico.org.uk/make-a-complaint/ or 0303 123 1113.

Children

planpage is a tool for software professionals and is not meant for children. You must be at least 16 to use it. If we learn that we hold data about someone under 16, we will delete it.

Changes to this policy

We will update this policy when what we do with data changes. The date at the top shows when it last changed. If a change materially affects how we use your data, we will tell you by email or in the app before it takes effect.

Contact

Bifrost Development Ltd, trading as planpage Email: hello@planpa.ge