PlanMyGrid
Privacy Policy
Effective August 27, 2026. This policy describes how PlanMyGrid collects, stores, and protects information when you use the planner, AI helpers, sharing features, or billing tools.
Data we process
- Account profile: name, email address, avatar, and the authentication provider identifiers needed to sign you in.
- Workspace content: grids, post metadata, captions, share links, analytics events, and AI results when you choose to sync them.
- Client media and delivery: files you upload to a workspace's media library, collections, delivery links, and files clients send you through upload request pages — including the sender's email address when they choose to provide it.
- Planning content: canvas boards, cross-channel drafts (captions, images, and dates planned for other platforms), and approval feedback from your clients including their name and email when they leave it.
- Client credentials (Vault): logins your clients hand to you through the Vault are encrypted with AES-256-GCM before storage — our database only ever holds ciphertext. We keep an access log of who revealed a credential and when. Hand-back links purge our copy of the secret and retain only the log.
- Billing artefacts: Stripe customer IDs, subscription status, plan selections, invoices, and payment history for Pro users.
Where data lives
- Browser storage: offline grids, AI drafts, and recent media remain on your device until you clear them from Settings → Data controls.
- Our secure database and cloud storage: synced grids, media references, share analytics, actions history, and user profile records.
- Backups: encrypted daily snapshots of our database retained for up to 30 days for disaster recovery.
When we share data
- Stripe receives name, email, Stripe customer ID, and subscription metadata to process PlanMyGrid Pro billing.
- OpenAI receives temporary prompts, color palettes, and publicly reachable image URLs only for AI captioning, hashtag generation, and grid analysis. Assets are never logged or used to train OpenAI models.
- Vault credentials are never shared with any third party, never leave our infrastructure except over TLS to you or to the client you release them to, and are never used for any purpose other than showing them to authorised workspace members.
- We do not sell, broker, or rent any personal data and we do not run ad networks.
How we protect it
- Authentication and storage are handled on hardened infrastructure with row-level security and encryption at rest.
- TLS secures every network request. Sensitive environment keys (database credentials, OpenAI, Stripe) live only on the server.
- Team access is restricted to vetted staff with logging, SSO, and least-privilege permissions.
Your rights & controls
- Export: download a JSON or ZIP of your grids from Settings at any time. Media exports include the watermark visible in-app.
- Delete: remove cached data locally or permanently delete your account (and all synced assets) from Settings → Data controls.
- Access & correction: email hey@planmygrid.com to update billing details, request audit logs, or obtain a full export for compliance reviews.
Quick references
- Data processor: PlanMyGrid, 85 Great Portland Street, London, UK
- Data sub-processors: Stripe (billing), OpenAI (optional AI features)
- Contact: hey@planmygrid.com • Response time: within one business day
More resources
- Request DPA or SOC reports → hey@planmygrid.com
- Security disclosures → security@planmygrid.com
- Data request workflow → planmygrid.com/data-usage
Questions?
Email hey@planmygrid.com. We respond within one business day and are happy to discuss DPAs, residency requirements, or security reviews.