Features How It Works Pricing Blog
← Back to Home

Privacy Policy

How Planairly collects, uses, stores, and protects your personal data.

1. Introduction

Planairly ("we", "us", "our") operates the Planairly.com platform (the "Service"), a collaborative project planning application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable US state and federal privacy laws.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

2. Data Controller

Michał Tarnawski (EU VAT ID: PL8961375834), Address: ul. Ślężna 187/1, 53-110 Wrocław, Poland operating under the brand name Planairly, is the data controller responsible for your personal data. You can reach us at:

For GDPR-specific inquiries or to exercise your data subject rights, you may also contact our Data Protection Officer at [email protected].

3. Information We Collect

3.1 Information You Provide Directly

  • Account information: Name, email address, profile picture, and password when you create an account (managed via Clerk authentication).
  • Workspace and team data: Organization name, team membership, and role assignments.
  • Project content: Tasks, PERT diagrams, task descriptions, estimated durations, due dates, assignee information, dependencies, and other project artifacts you create within the Service.
  • Communication data: Messages, feedback, and support requests you send to us.
  • Payment information: Billing details processed through Paddle, our Merchant of Record for subscription payments and invoicing. We do not store full credit card numbers on our servers.

3.2 Information Collected Automatically

  • Usage data: Pages visited, features used, actions taken, timestamps, and session duration.
  • Device information: Browser type, operating system, device identifiers, screen resolution, and language preferences.
  • Log data: IP addresses, access times, referring URLs, and error logs.
  • Real-time collaboration data: Cursor positions, presence status, and editing operations transmitted via our Hocuspocus/Y.js collaboration layer. This data is ephemeral and not persisted beyond the active session except where it results in saved project content.

3.3 Information from Third-Party Integrations

When you connect third-party services, we receive data necessary to provide the integration:

  • Jira (Atlassian): Project names, issue data (titles, descriptions, statuses, assignees, estimates, due dates, issue links/dependencies), user account IDs, and display names from your Jira instance. Data is exchanged via Atlassian Forge webtriggers with HMAC signature verification.
  • Linear: Organization, team, project, issue, status, assignee, estimate, due date, and dependency data from your Linear workspace.
  • Slack: Workspace, channel, and user identity data needed to deliver project notifications and process interactive task actions.

We only access the minimum data necessary for each integration to function. Integration connections are established per-workspace and require explicit authorization from a workspace administrator.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service: To operate, maintain, and improve Planairly, including real-time collaboration features, PERT diagram editing, and project management.
  • Third-party integrations: To synchronize tasks, assignees, and dependencies with Jira and Linear, and to deliver configured notifications and interactive task actions through Slack.
  • Authentication and security: To verify your identity, manage sessions, and protect against unauthorized access.
  • Communication: To send service-related notices, respond to support requests, and (with your consent) send product updates.
  • Analytics and improvement: To understand usage patterns, diagnose technical issues, and improve the Service.
  • Legal compliance: To comply with legal obligations and enforce our terms.

5. Legal Bases for Processing (GDPR)

Under the GDPR, we process your personal data based on the following legal grounds:

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you've subscribed to, including account management, project data storage, and integration synchronization.
  • Legitimate interests (Art. 6(1)(f)): Analytics, security monitoring, and service improvement, where our interests do not override your fundamental rights.
  • Consent (Art. 6(1)(a)): Marketing communications and optional data processing where we request your explicit consent. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): Where we must process data to comply with applicable laws.

6. Data Sharing and Third-Party Services

We share your data only in the following circumstances:

6.1 Service Providers and Payment Provider

Provider Purpose Data Shared Location
Clerk Authentication and user management Account data, authentication tokens US
Paddle Merchant of Record for subscription billing, payments, and invoicing Billing contact, purchase, and payment details Global
Supabase Database hosting and persistence All project and user data EU / US (configurable)
Hocuspocus Real-time collaboration server Session data, document edits, presence EU
Vercel Application hosting Request logs, server-side rendering data Global CDN (EU primary)

Paddle processes purchase information as our independent Merchant of Record. Paddle's own privacy policy applies to the billing details it receives.

6.2 Third-Party Integrations (User-Initiated)

When you enable integrations with Jira or Linear, data flows bidirectionally between Planairly and the connected service:

  • Outbound: Task titles, descriptions, statuses, estimated durations, due dates, assignee mappings, and dependencies are pushed to the connected service.
  • Inbound: Issue data, assignee information, status changes, and issue links are received from the connected service.

When you enable Slack, Planairly sends configured project notifications to mapped channels or users and receives interactive task actions initiated from Slack.

These integrations are activated only by explicit workspace administrator action. You can disconnect integrations at any time, which stops all data exchange. Data already synchronized to a third-party service is governed by that service's own privacy policy.

6.3 Other Disclosures

We may disclose personal data where required by law, regulation, legal process, or governmental request, or where necessary to protect the rights, property, or safety of Planairly, our users, or others.

7. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence. For transfers from the EU/EEA to countries without an adequacy decision, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • EU-US Data Privacy Framework for transfers to certified US organizations.
  • Additional technical and organizational safeguards including encryption in transit and at rest.

8. Data Retention

  • Account data: Retained for the duration of your account. Upon account deletion, personal data is removed within 30 days, except where retention is required by law.
  • Project data: Retained for the duration of the workspace subscription. Deleted within 30 days of workspace termination.
  • Collaboration session data: Ephemeral real-time data (cursor positions, presence) is not persisted beyond the active session.
  • Sync records: Integration sync logs are retained for 90 days for debugging purposes, then automatically purged.
  • Log data: Server logs are retained for 90 days.
  • Backup data: Database backups follow the same retention schedule as the primary data, with a maximum lag of 30 days.

9. Your Rights

9.1 Rights Under GDPR (EU/EEA Residents)

Under the GDPR, you have the following rights:

  • Right of access (Art. 15): Request a copy of your personal data.
  • Right to rectification (Art. 16): Request correction of inaccurate data.
  • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Right to restriction (Art. 18): Request restriction of processing in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interests, including profiling.
  • Right to withdraw consent (Art. 7(3)): Withdraw consent at any time where processing is based on consent.
  • Right to lodge a complaint: File a complaint with your local data protection supervisory authority.

9.2 Rights Under US State Privacy Laws (CCPA/CPRA)

If you are a California resident (or resident of another US state with applicable privacy legislation), you have the right to:

  • Know what personal information we collect, use, and disclose.
  • Delete your personal information, subject to certain exceptions.
  • Opt-out of the sale or sharing of your personal information. Note: Planairly does not sell your personal information.
  • Non-discrimination: Exercise your privacy rights without discriminatory treatment.
  • Correct inaccurate personal information.
  • Limit use of sensitive personal information to purposes necessary for providing the Service.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA/CPRA) of receiving a verifiable request.

10. Cookies and Tracking

We use the following categories of cookies:

  • Essential cookies: Required for authentication, session management, and security (e.g., Clerk session tokens). These cannot be disabled.
  • Functional cookies: Remember your preferences (theme, sidebar state). You can manage these in your browser settings.
  • Analytics cookies: Help us understand usage patterns. Deployed only with your consent where required by law.

We do not use tracking cookies for advertising purposes. We do not sell your data to advertisers.

11. Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • HMAC signature verification for all integration webhook communications.
  • Role-based access control and workspace-level data isolation.
  • Regular security audits and penetration testing.
  • Secure authentication via Clerk with support for multi-factor authentication.

For more details, see our Security page.

12. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we will provide prominent notice (e.g., email notification or in-app banner).

Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

14. Contact Us

If you have questions about this Privacy Policy, your data, or wish to exercise your rights:

For EU residents, you also have the right to lodge a complaint with your national Data Protection Authority.