← Back to Plan Court
Privacy Policy
Plan Court (sole proprietorship of [Your Name]) · Last updated: September 2026
This policy explains what we collect, why, and the choices you have. We keep it short on purpose: we collect only what the service needs to work.
1. Data we collect
- Account data: your email address (used to sign you in with a one-time link) and your workspace membership role.
- Plan content: the implementation plans you submit, the critiques and verdicts the models produce, and the resulting reports — stored in your workspace.
- Provider configuration: if you bring your own model API keys, those keys are stored encrypted at rest (AES-256-GCM) and are never shown back to you in full after you save them.
- Billing data: your plan, credit balance, and purchase history. Payment card details are collected by Paddle (our payment processor), not by us; we never see or store your card number.
- Usage logs: minimal server logs (IP address, request path, timestamps) used for security and abuse prevention.
2. How we use it
To operate the service: sign you in, run the roundtable on your plans, store and show your reports, enforce your plan and credits, and support you. We do not sell your data and do not use it for advertising.
3. Plans are never used for AI training
Your plans, critiques, and reports are never used to train AI models — by us or by anyone else. We transmit plan text to model providers only to fulfill your specific run. When you use your own keys, that transmission is between you and your provider under your own agreement. For our managed mixes, we configure providers so inputs are not used for training.
4. Third-party subprocessors
- Paddle — payment processing and merchant of record (tax/invoicing).
- Resend — sends your sign-in and notification emails.
- Hetzner — hosts our servers (EU data centers).
- Model providers — when you run a session, the models you select (e.g. OpenAI, Anthropic, Google, DeepSeek, OpenRouter, and others) receive the plan text needed to produce critiques and verdicts.
These providers process data only as needed to provide their part of the service.
5. Retention
Your plan reports and run history are stored in your workspace and shown according to your plan's history window (7 days on Free, 90 days on Pro and Team). You can delete your account and all of its data at any time (see below).
6. Cookies & local storage
We use one essential cookie: a signed, HttpOnly session cookie that keeps you signed in for 30 days. The marketing site stores your chosen color theme in your browser's local storage. We use no tracking or advertising cookies.
7. Your rights
- Access and export: your plans and reports are available in the app; you can copy or download them at any time.
- Deletion: you may delete your account and workspace from within the app, which removes your plan content, reports, configuration, and billing records. Email [email protected] to request deletion or to exercise any other data right.
- Correction: you can update your provider configuration and workspace settings at any time.
8. Security
We store data with restrictive file permissions, encrypt provider API keys at rest, and require authentication for your workspace. No security is perfect; please report issues to [email protected].
9. Changes
We may update this policy. Material changes will be posted on this page with a new date. Continued use after a change means you accept it.
10. Contact
Privacy questions or requests: [email protected].