Privacy Policy

Last updated 4 October 2026

What personal data planpage holds, why, who helps us process it, how long we keep it, and how to exercise your rights.

The short version

  • planpage is run by Bifrost Development Ltd. We are the controller of the personal data described here. Contact us at hello@planpa.ge.
  • You sign in with GitHub or Discord. We keep your name, avatar link, the verified email addresses those services report, and the content you and your agents create.
  • We do not run analytics, advertising or tracking. The only cookies we set are the ones the service needs to work.
  • We do not run AI models. The agents you connect are your own tools. What they send us is stored like anything else you write.
  • Everything is hosted on Cloudflare. We use a small number of other services, listed below, only when you use the feature that needs them.
  • We keep your data while your account exists. A few things are kept for a fixed time, set out below.
  • You can ask to see, correct, export or delete your data by emailing hello@planpa.ge. You can also complain to the Information Commissioner's Office.

Who we are

planpage (https://planpa.ge, with the app at https://app.planpa.ge) is a trading name of Bifrost Development Ltd, a company registered in England and Wales. Bifrost Development Ltd is the controller of the personal data described in this policy, under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

You can reach us about anything in this policy at hello@planpa.ge.

What this policy covers

This policy covers:

  • the planpage website and app;
  • the planpage MCP server and API, which AI agents use on your behalf;
  • public share pages on share.planpa.ge and on custom domains people connect;
  • emails and browser notifications we send.

It does not cover the AI agents or MCP clients you connect (such as Claude Code, Claude, Cursor or ChatGPT), GitHub, Discord, or any other service you use alongside planpage. Each of those has its own privacy policy.

What we collect

Your account

When you sign in with GitHub or Discord, we receive and keep:

  • your display name (your GitHub name or login, or your Discord display name or username);
  • a link to your avatar image on GitHub or Discord;
  • the email addresses the provider reports, with whether each is verified. From GitHub we fetch the full list of addresses on your account. From Discord we receive the one address on your account. One verified address is your primary address;
  • your user ID at the provider, and the access and refresh tokens the provider issues to us, so we can keep your email addresses up to date;
  • which providers are linked to your account, and when.

We also store your interface theme (system, light or dark), your platform role (almost everyone is a "user"), and whether your account has been suspended, with the reason and end date.

Sign-in sessions

Each time you sign in we create a session record holding the IP address and browser user agent you signed in from, the session's start and expiry times, and the workspace you have open. If a member of staff is viewing your account for support (see "Staff access"), the session records that too.

Workspaces and membership

For each organisation workspace: its name, short name (slug), colour, and its members with their roles (owner, admin, reviewer, member or viewer). For invitations: the invited email address, the role offered, who sent it, and when it expires (seven days).

What you and your agents create

This is the main thing planpage holds:

  • projects, with an optional linked repository URL;
  • documents (plans, reports, reviews, decision records and briefs), every saved version of each, and who or which agent session wrote each version;
  • comments and replies, reviews (approve, request changes or comment, with any note), answers to questions and picks on decisions;
  • steps and their status, notes and claims;
  • links to commits, pull requests, branches and other URLs;
  • an activity timeline of who did what to each document;
  • your inbox of notifications, which documents you have stopped following, and which documents you have been asked to review.

Anything you or your agents put into a document is stored as written. Please don't put personal data about other people, or secrets such as passwords and keys, into documents unless you need to.

Agent connections

When you connect an AI agent we record:

  • the connection's name, whether it uses OAuth or an API token, which workspaces it may reach and at what access level (read, publish, or write), when it was created and last seen, and whether it has been revoked;
  • for API tokens: a SHA-256 hash of the token (never the token itself), its first few characters so you can recognise it, and its expiry;
  • for each agent session: a label, and, if the agent supplies them, the model name, client name, repository and branch it is working on.

OAuth grants for agents are held by the OAuth service that runs on Cloudflare (see "Security").

Notifications

  • Email notifications are off until you turn them on. We store your choice (off, as they happen, or a daily digest) and which kinds of notification you want.
  • Browser push notifications are off until you allow them in your browser. We store the push address your browser gives us, the encryption keys for it, your browser's user agent, and when a notification last reached it.
  • Emails sent: for every email we send (invitations, notifications, digests, and test emails sent by staff) we log the recipient address, subject, type, whether it was sent, and any error.

Sharing

  • Public share links: the document, an optional password (stored only as a salted hash), an optional expiry, an optional pinned version, who created the link, and a count of views. We do not record who viewed the page.
  • Abuse reports on share pages: the reason and any details the reporter types. We do not store the reporter's IP address. We store a keyed hash of the IP address combined with the date, which lets us spot repeat reports from the same place on the same day without knowing who sent them.
  • Guest reviewers: the email address a document was shared with, who invited them, whether they can comment, and when they accepted.
  • Custom domains: the hostname and its verification status.

Integrations and imports

  • GitHub App: if you install the planpage GitHub App, we store the installation's account name and type, and details of the pull requests you link to plans (repository, number, commit, title, state and check status).
  • Zipline import: the address of the Zipline server you import from. The Zipline API token you give us is held only while the import runs and is deleted when it finishes or fails.

Billing

Paid plans are switched off during early access, so we do not collect payment information. If we introduce paid plans, we will store the plan, number of seats, subscription status, renewal date, and the customer and subscription IDs from Polar. Polar handles payment details; we never see card numbers.

Security and audit records

We keep an audit log of actions that change accounts and workspaces: for example signing in with a new provider, changing your primary email, creating or deleting a workspace, inviting or removing members, changing roles, and staff actions such as suspensions and account views. Each entry records who acted, any member of staff acting on their behalf, the workspace, what was done, and to what. Some entries include an email address (for example, the address invited to a workspace).

You can see the entries that concern your own account under Your account, then Security log.

Performance measurements

To keep the service fast we record how long pages take to load. Each measurement holds only the kind of page (for example "/d/:id", with identifiers removed), the time taken, and a breakdown by stage. Measurements from browsers are only accepted from signed-in browsers but are not linked to you, your session, your IP address or your browser.

Operational logs

Cloudflare, which runs planpage, keeps short-lived operational logs of requests and errors, which can include IP addresses and request details. We use them only to keep the service running and to investigate faults and attacks.

How we use it, and our lawful bases

What we do Data used Lawful basis
Create and run your account, sign you in, and keep your email addresses up to date Account, sessions Contract: we need it to provide the service you signed up for
Store, show and sync your workspaces, documents, comments and reviews, including live editing Workspaces, content Contract
Let agents you connect read and write on your behalf Agent connections, content Contract
Send invitations to people a workspace owner or admin invites Invited email address Legitimate interests: letting workspace owners invite their colleagues
Send email notifications and digests Email address, notification preferences, inbox Consent: you turn these on, and can turn them off at any time, including with the one-click unsubscribe link in each email
Send browser push notifications Push subscription Consent: you allow them in your browser and can withdraw at any time
Publish public share pages and handle abuse reports Share links, abuse reports Contract (for the person sharing); legitimate interests (keeping the service free of abuse)
Post plan status to GitHub pull requests GitHub App data, plan title, status and step titles Contract: you install the app and link the pull request
Keep the service secure, prevent abuse, and enforce our terms Sessions, audit log, suspensions, operational logs Legitimate interests: protecting you, other users and the service
Provide support, including viewing your account when needed Account, content, audit log Legitimate interests: resolving problems you or your workspace report
Measure and improve performance Performance measurements Legitimate interests: a fast, reliable service. These measurements are not linked to you
Take payment, if paid plans are introduced Billing records Contract, and legal obligation (tax and accounting records)
Respond to legal requests and defend legal claims Any relevant data Legal obligation; legitimate interests

Where we rely on legitimate interests, we have weighed them against your rights. You can object (see "Your rights").

We do not sell personal data, use it for advertising, profile you, or make decisions about you by automated means that have legal or similarly significant effects.

AI agents you connect

planpage does not run AI models itself and does not send your content to any AI provider.

The agents you connect (such as Claude Code, Claude, Cursor, ChatGPT or another MCP client) are third-party tools that you choose and control. When you connect one, you choose which workspaces it can reach and its access level in each:

  • read: read projects and documents;
  • publish: read, and publish and update documents;
  • write: everything above, plus claim and update steps as it carries out an approved plan.

An agent can never do more than you can in a workspace. What the agent reads from planpage is passed to that agent and its provider under their terms, not ours. What it sends us is stored like any other content. You can see and revoke your connections under Your account, then Agent connections.

Content in organisation workspaces

When you work in an organisation workspace, the owners and admins of that workspace decide who can see its content, can export it, and can delete the workspace. Other members see your name, avatar, comments, reviews and the documents you write there, according to their role. If you leave a workspace or delete your account, what you contributed to an organisation workspace stays part of that workspace's record.

A public share link makes a document readable by anyone who has the link, without signing in. Share pages ask search engines not to index them and run no scripts. You can add a password or an expiry date, pin a version, and revoke a link at any time. If a shared document includes images hosted elsewhere, the visitor's browser fetches those images from wherever they are hosted.

A guest is someone a document has been shared with by email. They see the document once they sign in with a verified address that matches.

Who we share it with

We use the following service providers. Each processes data only to provide its service to us.

Provider What for When
Cloudflare, Inc. Hosting, database (D1), storage, key-value storage, real-time collaboration (Durable Objects), content delivery, custom domains, network security and operational logs Always
GitHub, Inc. Signing in with GitHub; the GitHub App, if you install it When you use GitHub sign-in or install the app
Discord Inc. Signing in with Discord When you use Discord sign-in
Our email provider Delivering invitations, notifications and digests by email When an email is sent to you
Browser push services (for example Google, Mozilla or Apple, depending on your browser) Delivering push notifications. The notification is encrypted so that only your browser can read it When you allow push notifications
Polar Software, Inc. Payments, as merchant of record. Polar is responsible for the payment data it collects Only if paid plans are introduced and you buy one

Your avatar is loaded by your browser from GitHub's or Discord's image servers.

If you link a pull request to a plan and the GitHub App is installed on that repository, planpage posts a comment on the pull request showing the plan's number, title, status and step titles, and sets a "planpage/approved" status on the commit. Anyone who can see that pull request can see that comment.

We may also disclose data where the law requires it, to protect people's safety, or as part of a sale or reorganisation of our business (in which case this policy will continue to apply to your data).

International transfers

Cloudflare runs planpage on its global network, so requests are handled in the data centre nearest to you or to our database. Our main database is located in western Europe, but copies and processing can occur in other countries, including the United States. GitHub, Discord, Polar and the browser push services are based in or operate from the United States. Your email provider may also process data outside the UK.

Where personal data leaves the UK, we rely on UK adequacy regulations where they apply (including the UK Extension to the EU-US Data Privacy Framework for certified US companies), or on the UK International Data Transfer Addendum to the EU standard contractual clauses. You can ask us for details.

How long we keep it

Data How long
Account, linked providers, email addresses While your account exists
Workspace content, versions, comments, reviews and activity While the workspace exists. Documents and projects can be archived but not individually deleted; they go when the workspace is deleted. If paid plans are introduced, free workspaces may keep only 30 days of older versions and activity; current and approved versions are always kept. We will tell you before this starts
Sign-in sessions Until you sign out or the session expires. A session expires after seven days without use. Staff support sessions last at most one hour
Agent OAuth access Access tokens last one hour; refresh tokens last up to 90 days, or 30 days unused. API tokens last until they expire or you revoke them
Invitations Seven days, or until accepted or cancelled
Push subscriptions Until you turn push off, or your browser's push service tells us the address no longer works
Notification preferences and inbox While your account exists
Zipline import token Only until the import finishes or fails
Performance measurements 14 days
Email log While the service runs; we will set a fixed period and update this policy
Audit log While the service runs, because it is our record of security events and staff actions; we will set a fixed period and update this policy
Abuse reports While the share link exists
Billing records, if paid plans are introduced As long as tax and accounting law requires, normally six years
Database backups Deleted data can remain in Cloudflare's point-in-time recovery for up to 30 days

Deleting your account

There is no self-service account deletion yet. To delete your account, email hello@planpa.ge from an address on your account. If you are the only owner of an organisation workspace, you will need to hand ownership to someone else or delete that workspace first.

When we delete an account we remove your profile, linked providers, email addresses, sessions, personal workspace (its projects, documents, versions, comments and share links), workspace memberships, agent connections and tokens, notification settings, push subscriptions and import history. What you contributed to organisation workspaces stays with those workspaces. The audit log keeps a record that the account was deleted, including the name and email address it had, and earlier entries about the account.

Owners of an organisation workspace can delete it themselves from Workspace settings, which removes its projects and documents.

Cookies

We use only cookies that are strictly necessary for the service to work, so we don't ask for consent to them. We use no analytics, advertising or tracking cookies, and no third-party cookies.

Cookie What it does How long
Better Auth session cookie (better-auth.session_token) Keeps you signed in; your session also remembers which workspace you have open Until you sign out or the session expires
Short-lived sign-in cookies set by Better Auth Protect the GitHub or Discord sign-in flow against forgery, and support staff account views Minutes, or the length of the sign-in or support session
pp-theme Remembers whether you chose the light or dark theme, so pages don't flash the wrong one One year (removed if you choose "system")
pp-css Records which version of our stylesheet your browser already has, so we only include it in the page on your first visit 30 days
pp_unlock_… On a password-protected share page, remembers that you entered the right password 12 hours

Security

We protect your data with measures that include:

  • encryption in transit (HTTPS) for every page, API call and email connection we make;
  • data stored with Cloudflare, which encrypts its storage at rest;
  • API tokens stored only as SHA-256 hashes, and share-link passwords stored only as salted PBKDF2 hashes;
  • service credentials that staff configure (such as email and sign-in keys) encrypted with AES-GCM before they are stored;
  • agent OAuth grant data encrypted by the OAuth service, which stores tokens only as hashes;
  • signed unsubscribe links, and share pages served with no scripts under a strict content security policy;
  • access limits by workspace role and by agent access level, with staff access logged.

No system is perfectly secure. If a breach affects your personal data in a way that is likely to put you at high risk, we will tell you without undue delay.

Staff access

A small number of staff can use planpage's admin tools. Support staff can view admin pages and, to resolve a problem, sign in as a user for up to one hour. Staff accounts cannot be viewed this way. Each time, the member of staff must give a reason. The start, the end and the reason are logged and shown in that person's Security log, and changes made during the visit are recorded against the member of staff as well as the account. Senior staff can also suspend accounts, sign accounts out, change roles, archive projects, remove members, delete workspaces and accounts, and take down share links; these actions are logged too.

Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • correct data that is wrong or incomplete;
  • delete your data;
  • restrict how we use it;
  • object to processing we carry out on the basis of legitimate interests;
  • data portability: receive the data you gave us in a machine-readable format;
  • withdraw consent at any time, where we rely on it (for example email and push notifications). This doesn't affect what we did before you withdrew it.

Some of this you can do yourself. You can export a workspace (a zip with every document as markdown, plus every version, comment, review, step, link and activity entry as JSON) from Your account, then Your data; for organisation workspaces this needs an owner or admin. You can change notification settings, unlink sign-in providers, change your primary email, and revoke agent connections from Your account.

For anything else, email hello@planpa.ge. We may need to confirm it is you. We will reply within one month, or tell you if we need longer for a complex request. There is normally no charge.

If you are unhappy with how we handle your data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator: https://ico.org.uk/make-a-complaint/ or 0303 123 1113.

Children

planpage is a tool for software professionals and is not meant for children. You must be at least 16 to use it. If we learn that we hold data about someone under 16, we will delete it.

Changes to this policy

We will update this policy when what we do with data changes. The date at the top shows when it last changed. If a change materially affects how we use your data, we will tell you by email or in the app before it takes effect.

Contact

Bifrost Development Ltd, trading as planpage Email: hello@planpa.ge