Privacy Policy — Planovik AI

Version dated September 14, 2026 · For the web service and mobile application

1. General provisions and scope

This Policy describes personal data processing when using planovik.pro, the web application at app.planovik.pro, the mobile application, application programming interfaces and Planovik AI cloud synchronization (the “Service”).

2. Purposes and legal grounds

Personal data is processed to:

  • create accounts, authenticate users, synchronize data and provide selected Service features;
  • enable collaboration, manage roles and deliver notifications;
  • provide paid access and record subscription terms, limits and payment-related requests;
  • provide support, diagnose errors, protect accounts and prevent abuse;
  • comply with applicable law and lawful requests from competent authorities.

Legal grounds include entering into and performing an agreement with the user, user consent, compliance with legal obligations and the Controller’s legitimate rights and interests where these do not override user rights.

3. Data we process

  • Account: name, email address, avatar, language and display settings, and an external sign-in provider identifier. For password sign-in, a cryptographic password hash is stored, not the original password.
  • Workspace data: workspaces, tasks, lists, Kanban boards, subtasks, comments, habits, documents, finance records, shopping lists, timers and change history.
  • Collaboration: participants, roles, assignments, watchers and actions in shared workspaces.
  • Files: images, documents, avatars and voice recordings added by the user. Voice recordings are not used for biometric identification.
  • Integrations: connection identifiers, access tokens, encrypted credentials for external calendars and storage, synchronization settings, and data the user asks the Service to send or retrieve.
  • Payments: order identifier, selected plan and resources, amount, payment status, access term and receipt/contact email. Bank card details are handled by the payment aggregator and are not received or stored by the Service.
  • Technical data: IP address, browser, device and application version, timestamps, and sign-in, synchronization and error logs.

The Service is not intended to deliberately collect special categories of personal data. Such information should not be uploaded without necessity and a lawful basis.

4. Local storage and cookies

  • Browser: the browser database and local storage may contain workspace data, settings and a queue of changes not yet sent to the server.
  • Mobile application: data and media may be stored in the device database and file storage for offline operation.
  • Cloud: after successful synchronization, workspace data is held in the server database and files in private object storage. Private files are accessed using time-limited links.
  • Cookies: necessary cookies and local tokens are used for sign-in, security and preferences. Third-party behavioral advertising trackers are not currently used.

Clearing browser or application data before synchronization completes may cause loss of local changes.

5. Integrations and recipients

The Controller does not sell personal data. To the extent required for a selected feature, data may be received by:

  • providers of servers, cloud databases, object storage, email and system notifications;
  • the payment aggregator when arranging and confirming payment;
  • Yandex when using Yandex ID, Yandex Calendar or Yandex Disk, and Yandex Metrica for anonymized web-service visit statistics; task titles, documents, files, chat text, email addresses and other account data are not sent to Metrica;
  • Google when using Google Calendar, Google Drive or Google notification services;
  • Telegram when linking a bot or delivering notifications;
  • KodikRouter and the language model providers it selects, only when an AI feature is used;
  • public authorities, only where required by law.

External providers process data under their own terms and policies. Some may process data outside the Russian Federation. Such transfer occurs only when the relevant feature is used and subject to applicable cross-border transfer requirements.

6. AI features

When an AI feature is used, the Service sends the prompt and the task or workspace context needed for the response or selected action through KodikRouter. Other account data is not automatically included in the request. Before routing a request to a language model provider, KodikRouter applies deterministic personal-data masking: direct identifiers are replaced with pseudonyms.

The language model provider receives pseudonymized text. When a response is returned, KodikRouter restores substituted identifiers where this is necessary to display the response to the user. AI providers may temporarily process a request under their own rules. Users should not submit passwords, payment details, government identifiers, medical information or other data whose disclosure is unnecessary for the requested action.

7. Retention and deletion

  • Account data and workspace content are retained while the account is in use or while needed to provide the Service.
  • A user may delete an account in settings. After confirmation, data is removed from the active database and associated cloud files are scheduled for deletion. Copies may remain temporarily in technical backups until routine rotation.
  • A free account may be deleted after 90 days without a sign-in. A warning is sent approximately 14 days beforehand; signing in cancels inactivity deletion.
  • An irreversible hash of the email address is retained for no more than 90 days to identify that an inactive account was deleted.
  • Without an active paid plan or trial, cloud media other than the avatar may be deleted after a 14-day grace period.
  • Payment and accounting records may be retained for the period required by law.

8. User rights

Users may request information about processing, correction, restriction, deletion or cessation of processing and may withdraw consent where processing is based on consent.

Requests must be sent to support@planovik.pro. The Controller may request identity verification to protect the account. Requests are handled within statutory periods; data required by law is retained until the mandatory period expires.

9. Data protection

Legal, organizational and technical measures appropriate to the processing are used, including account and role access controls, password hashing, encryption of stored integration credentials, protected network connections, private file storage, logging and backups. No storage or transmission method provides absolute protection against every threat.

10. Policy changes

The current version is published on this page. Where purposes or processing methods materially change, users are notified through the website, application or email when required by law.