Privacy Policy
Last updated: April 12, 2026
1. Introduction
Planorbi, provided by LemSof Oy (3606893-9) ("we", "our", or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our planning and productivity platform, including our Planner, Boards, and Strategy tools.
2. Information We Collect
Account Information
When you create an account, we collect your email address and password. You may also provide additional profile information such as your name.
Your Content
We store the content you create within our service, including planners (rings, activities, and tags), boards (columns, cards, labels, and assignees), and strategies (objectives, targets, priorities, and correlation data). This includes titles, descriptions, dates, and any other data you enter.
Lumi Assistant
When you use Lumi, your messages and relevant workspace content are sent through OpenRouter to the configured AI model provider to produce answers and proposed edits. Lumi can automatically search the public web when useful; search queries are sent to Brave Search. Avoid sharing passwords, access tokens or other secrets in chat. Workspace edits require your approval.
Google Calendar Integration
If you choose to connect your Google Calendar account, we securely store encrypted OAuth tokens (access and refresh tokens) that allow us to sync your calendar events. We only request the minimum permissions necessary: calendar read and write access. We do not access any other Google services or data beyond your calendar.
Payment Information
Payment processing is handled by Stripe. We do not store your full credit card details. We only retain your Stripe customer ID and subscription status.
3. How We Use Your Information
- To provide and maintain our service
- To process your subscription and payments
- To send you important service updates
- To respond to your support requests
- To improve our service based on usage patterns
- To sync calendar events between Planorbi and your Google Calendar (only if you choose to connect)
Google Calendar Integration: When you connect your Google Calendar, we use your calendar access to synchronize events bidirectionally. We only access calendars you explicitly link to a planner. We do not read, modify, or delete any calendar data beyond what is necessary for synchronization. All calendar operations are performed using encrypted OAuth tokens that you can revoke at any time through Google's account settings or by disconnecting in Planorbi.
4. Data Sharing
We do not sell your personal data. We may share data with:
- Stripe: For payment processing
- Supabase: For authentication and database hosting
- Vercel: For application hosting
- OpenRouter and the configured AI model provider: To answer requests made through Lumi.
- Brave Search: To process search queries when Lumi uses external web search.
- Google: Only when you explicitly connect your Google Calendar account. We use Google's OAuth 2.0 protocol to securely access your calendar data for synchronization purposes only.
5. Data Retention
Lumi conversations are saved separately for your account and each workspace. You can clear a conversation in the assistant. Inactive conversations and action records are scheduled for deletion after 30 days. Action records include proposed edits, relevant workspace state and execution results, retained to prevent duplicate changes and investigate incomplete operations. Provider processing is also subject to the provider's terms.
We retain your data as long as your account is active. When you delete your account, we permanently delete all your content — including planners, boards, strategies, and personal information — within 30 days.
For Google Calendar integrations: When you disconnect your Google Calendar, we immediately revoke all OAuth tokens at Google's servers and delete all stored tokens from our database. Calendar sync links and event mappings are also removed. You can disconnect at any time from your planner settings.
6. Your Rights
Under GDPR and similar regulations, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data
- Object to certain processing
To exercise these rights, visit your account settings or contact us at joona@planorbi.com.
7. Security
We implement comprehensive security measures to protect your data. However, no method of transmission over the Internet is 100% secure.
Data Encryption
- Encryption in transit: All data transmitted between your device and our servers uses TLS 1.2 or higher
- Encryption at rest: Sensitive data, including OAuth tokens, is encrypted using authenticated encryption (AEAD) with keys stored separately from the data
- Token encryption: Google Calendar OAuth tokens are encrypted using Supabase Vault before storage, with decryption restricted to server-side operations only
Access Controls
- Row-level security: Database policies ensure you can only access your own data. Each user's data is isolated at the database level
- Service role restrictions: Sensitive operations (like token decryption) are restricted to server-side code and cannot be accessed from client applications
- Password security: Passwords are hashed using industry-standard algorithms and never stored in plain text
OAuth & Third-Party Integrations
- OAuth state validation: We use cryptographically secure state tokens to prevent cross-site request forgery (CSRF) attacks
- Return URL validation: OAuth redirect URLs are strictly validated to prevent open redirect attacks
- Scope validation: We verify that Google grants only the minimum required permissions (calendar access only)
- Token revocation: When you disconnect your Google Calendar, we immediately revoke all tokens at Google's servers
- Metadata validation: Calendar event metadata is validated to ensure it belongs to your account before processing
Webhook Security
- Secret validation: Webhook endpoints require cryptographic secrets in production to prevent unauthorized access
- Channel verification: Webhook requests are verified against registered calendar channels before processing
Operational Security
- No token logging: OAuth tokens and sensitive credentials are never logged, even in error messages
- Secure defaults: Production environments require explicit security configuration and reject insecure fallbacks
- Regular security audits: We conduct security assessments and implement improvements based on best practices
8. Cookies
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through our service.
10. Contact Us
If you have questions about this Privacy Policy, please contact us at joona@planorbi.com.