Skip to main content
planin30

Privacy Policy

Last updated 2026-07-20.

planin30 does not collect personal information without consent.

Cookies

We use a small number of strictly necessary cookies to operate the site: a session cookie to keep you signed in, and a functional cookie that prevents spam in our feedback form. These are set only when you use those features and can’t be turned off without breaking them. Our analytics is cookieless (see below), and we use no advertising or cross-site tracking cookies — so there is nothing non-essential to consent to, and we don’t show a cookie-consent banner.

Third-party analytics

We use privacy-friendly analytics (Vercel Web Analytics) to count page views and referral sources. Vercel Web Analytics stores no cookies and does not collect your IP address. To opt out, set Do Not Track in your browser.

First-party product data

We also record limited first-party product events — for example, when an unsigned visitor tries to save calculator work or begins signup. These records may include the event name, the calculator’s identifier, the page path, a timestamp, a short-lived random “flow” identifier stored alongside your in-progress save, and a salted hash of your IP address used solely for abuse prevention and rate-limiting. We do not store the calculator inputs you enter as an anonymous (signed-out) visitor, your raw IP address, or use this data for cross-site advertising, and we do not sell or share it with third parties. Anonymous event records are retained for up to 12 months; IP hashes for up to 30 days; both are then deleted.

When you use the homepage search box, we log the search text you submit (not individual keystrokes), which tool it matched, and which result you opened, along with the same salted IP hash used for rate-limiting. We use these searches to understand what people want to plan and to build tools we don’t have yet. Please don’t include personal details in searches; search records are retained for up to 12 months and are never sold or shared with third parties.

Tool-specific data

When you sign in and use the product apps, the content you provide — including scenarios you save and documents you upload — is stored against your account. We use it to operate, secure, and improve our services, including fixing problems, internal analytics, and product development. Some features use AI to help — for example, reading an uploaded document to pre-fill a plan — and our AI providers do not train their models on your data. We never sell your financial data or share it for advertising, and you can delete your data at any time. The marketing site itself never reads or writes that data.

Google Contacts data

If you choose Import from Google, planin30 requests read-only access to your Google Contacts. We use Google’s People API to retrieve contact names, email addresses, phone numbers, postal addresses, and contact notes. We do not create, edit, or delete anything in your Google account.

The browser uses a short-lived Google provider token to retrieve the contacts directly for your preview. We use that token only for this import and do not store it in our application database. Retrieved contacts are not stored in your planin30 account unless you review the preview and choose to import them. When you import, the recognized contact fields are stored in your private contact book and may be used by you for guest lists and invitations.

Google Contacts data received through this connection is used only to provide those user-facing features. It is not sold, used for advertising, shared with data brokers, sent to our AI providers, or used to develop or train AI or machine-learning models. We do not create aggregated or anonymized datasets from Google Contacts data. Imported records are stored with Supabase, our database and authentication provider. Vercel hosts the application and processes the requests needed to operate it. If you direct us to email an invitation, Resend receives the recipient address and message content needed to deliver that invitation. These providers process the data only to deliver their services to us.

Imported contacts remain until you remove an individual contact, clear your contact book, or delete your account. Revoking planin30’s Google permission prevents future access but does not by itself remove contacts you previously chose to import. Traffic is encrypted in transit using HTTPS, and account-scoped access controls restrict stored contacts to their owner.

planin30’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Guest lists and invitations

Some planners (weddings, parties, fundraisers, memorial services) let you keep a guest list and send each party a private RSVP link. Names, email addresses, and details like seat counts or dietary notes on a guest list are information about other people that you choose to provide. We store them to run your plan and your invitations, and for nothing else:

  • Never marketing. Guest names and addresses are never used to market planin30 (or anything else) to your guests, never added to any mailing list, and never sold or shared for advertising.
  • What a guest sees. Each RSVP link shows only what you chose to publish: the event details you wrote, that party’s own name and seat count, and their own reply. A guest never sees your budget, your notes, your contact book, or the rest of the guest list.
  • What we record from guests. When a guest replies through their link we store their reply (attendance, dietary notes, an optional message to you) and basic delivery signals (that the page was opened, that an invitation was sent). A guest can also choose to add the names of the people in their party (for example, for seating and place cards) — those names are optional, stored as part of the RSVP, shown to you as the host, and deleted with the invitation. We do not use tracking pixels, and RSVP pages carry no third-party analytics.
  • Comments on the event page. Some event pages include a comment wall (a guestbook, for weddings). Anything a guest posts there — including the display name they choose — is visible to the other guests of that event, and the composer says so before they post. Guests can delete their own comments from their invitation link; as the host you can hide or delete any comment and turn the wall off entirely. Every event page carries a report link (support@planin30.com) for unwanted or abusive content, and comments are deleted with the event.
  • Invitation email. If you ask us to send invitations for you, each email is sent at your request, identifies you as the host, says it was sent via planin30, and includes a way to report abuse. If a guest’s address bounces or a guest marks an invitation as unwanted, we stop sending to that address (a suppression list keyed to the address) — including for future events, until the guest opts back in.
  • Deletion. Removing a guest from your list withdraws their invitation link. Deleting a plan (or your account) deletes its invitation records with it, automatically.

Email and communications

When you sign in, we send transactional emails you requested — your magic-link sign-in link and account-related notifications. We do not send marketing email. If we add product updates or a newsletter in the future, they will be strictly opt-in and every such message will include a one-click unsubscribe link.

Service providers

We rely on a few trusted providers to run GuideNext, Inc., each processing data only to deliver their service to us: Vercel (hosting, content delivery, and the cookieless analytics above), Supabase (database and authentication), Resend (delivery of the transactional emails above), and Google Workspace (our staff email). When paid plans are active, Stripe processes payments — we never receive or store your full card details.

Your choices and rights

You can request a copy of, or deletion of, your account data at any time — contact us and we’ll respond within 30 days. Deleting your account removes your saved scenarios and profile. Depending on where you live (for example, the EU/UK under GDPR or California under the CCPA), you may have additional rights to access, correct, port, object to, or delete your personal data. We do not sell your personal information.

Data security

Traffic is encrypted in transit (HTTPS), authentication is handled by Supabase, and access to stored data is restricted. No system is perfectly secure, but we work to protect your information and will notify affected users of any material breach as required by law. To report a security concern, use our contact page.

Contact

Questions about this policy or GuideNext, Inc.: see the contact page.