Plannie Privacy Policy
Version 2.0 — 2026-07-22
Plannie is built for your family's everyday life, which means you trust us with personal information about your household. This policy explains what personal data we process, for which purposes, on what legal basis, for how long, and what your rights are.
1. Scope of this policy
This policy applies to the personal data Ytterberg Holding AB, org. no. 559515-1845, Valhallavägen 46, 114 22 Stockholm, Sweden ("Plannie", "we"), processes as data controller when you use the Plannie apps and website (plannie.io) or contact us.
It does not apply to third-party services you choose to connect to Plannie (such as Google Calendar, Outlook, Google Photos, or Alexa) as regards the processing those services carry out on their own side. Those services are governed by their own privacy policies, and we are not responsible for their practices. Section 11 describes what Plannie itself does with data received from Google.
Questions about this policy: [email protected].
2. The information we collect
We collect only the categories of personal data described in this section.
2.1 Information you provide to us
- Account information. Email address, name, and password (stored only as a secure hash) — or, if you sign in with Google or Apple, the identifier that service gives us — and whether your email address is verified.
- Family member profiles. The information you choose to enter about the members of your household: names, initials, profile colours, member role, and optionally birth dates, avatar photos, and dietary preferences or allergies. Members other than account holders have profiles but no login.
- Household content. What your household puts into Plannie: calendar events (including any location you type into an event), tasks, chores, routines, check-ins, lists, recipes and meal plans, rewards and balances.
- Photos. Photos you explicitly pick (for example via the Google Photos picker) for your screensaver, re-encoded and stored on our own storage. We cannot access your photo library — only the photos you pick (see section 11).
- Family Inbox email. If you use your household's Plannie email address, the emails sent to it. Email from senders you have not approved is quarantined and deleted after 30 days unless you approve it.
- Approximate location. If you set a location for weather: a city-level place name and coarse coordinates for your household. We do not collect street addresses and we do not track your device's location.
- Communication information. What you send us when you contact support, give feedback, or answer an optional survey (for example when cancelling a subscription).
2.2 Information collected automatically
When you use Plannie we may automatically collect:
- Device and connection data. Push-notification tokens, device platform and app version, and connection metadata (such as IP address) processed transiently to deliver the service and keep it secure.
- Usage data. Product analytics events: which features are used, platform, and a household identifier. AI-feature usage is metered per household to apply the fair-use allowance.
- Diagnostic data. Error and crash reports with technical device context, used to keep Plannie working.
We do not use third-party advertising or tracking SDKs in the app.
2.3 Information from third parties
- Payment status. Purchases run through Apple, Google Play, or our web-billing providers. We receive subscription status and entitlements — never your full card details.
- Connected services. If you connect a calendar or other integration, we receive the data needed for that integration (for example calendar events), and only that.
3. Household member profiles
Plannie accounts are for adults (18+). Other members of your household appear in Plannie only as profiles created and managed by an account holder — they have no account and no login of their own, and cannot use the service directly.
As the account holder, you decide what information about your household members to add. We process it solely to provide the family features you see in the app. We do not use household members' data for advertising or profiling, and it is never visible to anyone outside your household.
4. How we use your personal data
We process personal data only for the purposes in the table below, on the legal basis stated there (GDPR art. 6.1). Where the basis is legitimate interest, we have assessed that our interest is necessary for the stated purpose and is not overridden by your interests and rights; you can object at any time (section 8).
| Purpose | Data | Legal basis | Kept |
|---|---|---|---|
| Providing Plannie: your account, household, calendar, lists, photos, inbox, notifications and other features | Account, profiles, household content, photos, inbox email, device data | Performance of contract (art. 6.1(b)) | Until you delete it or delete your account |
| Service email (verification, invitations, receipts, important notices) | Account information | Performance of contract | Account lifetime |
| AI features you actively use (section 5) | The content you submit to them | Performance of contract | The result is stored as part of your household content; see section 5 |
| Weather on your dashboard | Approximate location | Performance of contract | Until you change or remove it |
| Security: verifying access, preventing fraud and abuse, enforcing our terms | Account, device, usage and diagnostic data | Legitimate interest (art. 6.1(f)): running a safe service | As long as needed for the purpose |
| Improving Plannie: understanding how features are used, fixing errors | Usage and diagnostic data (pseudonymised; aggregated where possible) | Legitimate interest: improving the product | In identifiable form only as long as needed, then deleted or aggregated |
| Newsletters or product news, if we send any | Your email address | Consent (art. 6.1(a)) | Until you unsubscribe or withdraw consent |
| Bookkeeping and tax | Purchase records | Legal obligation (art. 6.1(c)) | As long as bookkeeping and tax law require |
| Customer records after account deletion: handling disputes and refunds, preventing fraud, recognising returning customers | Name, email, subscription history | Legitimate interest | As long as needed for those purposes |
| Establishing, exercising or defending legal claims; corporate transactions (section 6) | What is necessary in the situation | Legitimate interest | Until the matter is resolved |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not build advertising profiles.
5. AI features
When you use the Plannie Assistant, Magic Import (photos, PDFs, links), or when the Family Inbox extracts events from incoming email, the content involved is sent to our AI provider to generate the result — and for no other purpose. Your content is not used to train AI models. Items created by AI or via the API are marked with an attribution badge in the app. Our AI provider is listed in the service provider list.
6. Who we share personal data with
We share personal data only in the situations listed below, and we never sell it or share it with advertisers.
- Service providers. The companies that host and power Plannie (servers, email, AI, analytics, payments) process personal data on our behalf, under contract, only on our instructions, and only as needed to perform their function. The current list, including each provider's location and transfer safeguard, is published at Service providers & sub-processors.
- Services you connect. If you connect an integration (section 1), data flows to and from that service as needed for the connection you chose.
- Legal requirements. Where we are legally obliged to disclose data — for example a court order or a binding authority request — or where disclosure is necessary to establish, exercise or defend legal claims, prevent fraud, or protect the safety of our users or the public.
- Corporate transactions. If we are involved in a merger, acquisition, restructuring or sale of assets, personal data may be disclosed to the parties involved (under confidentiality) and transferred as part of the transaction, under protections no weaker than this policy; we would inform you.
- With your consent — anyone else, only if you ask us to or agree.
7. Where data is processed and international transfers
Our own servers, database and file storage are in the EU. Analytics and error diagnostics are processed in the EU.
Some service providers process personal data outside the EU/EEA. Where that happens, we ensure an essentially equivalent level of protection by relying on one of the following safeguards:
- an adequacy decision of the European Commission for the recipient country or framework — including the EU–U.S. Data Privacy Framework for certified U.S. providers;
- the Commission's Standard Contractual Clauses, together with supplementary measures where our transfer assessment shows they are needed;
- in limited cases, a derogation under GDPR art. 49 (for example a transfer necessary for legal claims).
Which safeguard applies to which provider is stated in the service provider list.
8. Your rights
Under the GDPR you have the right to:
- Access your personal data and receive a copy of it.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten") — largely self-service via account deletion in the app (section 10). We may retain data where a legal obligation requires it or where it is necessary for the purposes in section 4 that survive deletion, in which case we tell you so in our reply.
- Restrict processing while a rectification request or objection is being assessed.
- Object to any processing based on legitimate interest, on grounds relating to your particular situation — we then stop unless we demonstrate compelling legitimate grounds. For direct marketing the objection is absolute: we always stop.
- Data portability — receive data you provided under contract or consent in a machine-readable format.
- Withdraw consent at any time, for anything based on consent, without affecting processing already carried out.
To exercise a right, contact [email protected]. We respond within one month. We may need to verify your identity before acting on a request, and we act on requests to the extent applicable law requires; if we cannot verify that a request comes from the account holder, we will not disclose or delete data on the basis of it. You will never be disadvantaged in your use of Plannie for exercising a right.
If you believe we have processed your data unlawfully, you can lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, imy.se) or with the supervisory authority where you live.
9. How we protect your data
We apply technical and organisational measures appropriate to the risk — including encryption in transit and at rest, access controls, and monitoring — to protect personal data against loss, misuse, unauthorised access, disclosure, alteration and destruction. Payment card details are handled by our payment providers and never touch our servers.
10. How long we keep your data
We keep personal data only as long as necessary for the purposes in section 4 (the "Kept" column there), or longer only where a legal obligation requires it. In addition:
- Account deletion is available directly in the app: Settings → Delete account & data. Deletion takes effect immediately and cannot be undone: it removes the entire household from our active systems, and residual copies in backups are removed within 30 days. A subscription billed through our web billing is cancelled together with the deletion; a subscription billed through the App Store or Google Play must be cancelled there first.
- Quarantined Family Inbox email (unapproved senders) is deleted after 30 days.
- When a premium subscription ends, there is a 30-day grace period; then the family email address and its stored email are released, while your calendar and lists continue on the free plan.
- Where data cannot be deleted immediately for technical reasons (for example backup archives), it is isolated from further processing until deletion completes within the window above.
11. Google user data — Limited Use disclosure
Plannie's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google Calendar data only to provide the two-way calendar sync you set up, and Google Photos data only to display photos you explicitly pick.
- We do not use Google user data for advertising, and we do not sell it.
- We do not allow humans to read your Google user data, except with your explicit permission (e.g. a support request), where required for security, or to comply with law.
- We only transfer Google user data to others where necessary to provide the features above, for security, or to comply with law.
12. Our website and cookies
Our website (plannie.io) uses cookieless analytics by default: page views are measured so that nothing is stored on your device — no cookies and no local storage. The analytics service receives the pages you view, coarse technical context (browser, device type, country), and a random per-session identifier that is discarded when you leave.
If you visit from a country where analytics cookies require consent (the EU/EEA, the UK or Switzerland), we ask first: an analytics cookie — used to tell returning visitors apart — is set only if you choose "Allow" in the cookie banner, and the site works exactly the same if you decline. Outside those countries we may set the same analytics cookie without asking. Your consent choice itself is stored on your device (strictly necessary, no consent needed). To change your mind, clear the site's data in your browser and choose again.
We set no advertising or third-party marketing cookies anywhere.
13. Changes to this policy
We may update this policy. The current version, with its version number and date, is always available where this policy is published. If a change significantly affects how we process your personal data, we will notify you in the app or by email before it takes effect, so you can object or delete your account first. Minor changes (clarifications, provider changes already covered by section 6) take effect when the updated version is published.
14. Contact us
Ytterberg Holding AB, org. no. 559515-1845 Valhallavägen 46, 114 22 Stockholm, Sweden [email protected]
We are the data controller for the processing described in this policy.