1. Introduction
Your privacy matters to us. This policy explains what data we collect when you use Planora (the “Service”), how we use it, who we share it with, and how we protect it. This policy forms an integral part of our Terms of Service.
2. Data Controller
The operator of the Service and responsible party for your data is:
PLANORA
Email: support@planora.co.il
3. Data We Collect
- Account information — name, email address, and login credentials (including Google OAuth login).
- Content you enter — client records, projects, tasks, suppliers, documents, and financial data you store in the system.
- Technical information — basic usage data, browser type, and IP address, for security and service improvement.
- Gmail data (optional) — if you choose to connect your Gmail account, Planora reads data from your mailbox as described in Section 8 below.
- Google Calendar data (optional) — if you choose to connect Google Calendar, Planora reads and writes calendar events as described in Section 8 below.
When you sign in with Google, we receive only the account details required for user identification (such as name and email address), according to the permissions you grant. We never receive your Google account password.
4. How We Use Your Data
- To provide, operate, and maintain the Service;
- To authenticate identity, secure accounts, and prevent misuse;
- To provide support, respond to inquiries, and improve user experience;
- To send operational notifications relating to your account and the Service.
5. Data Ownership
The business data you upload to the system remains yours. We do not use it for commercial purposes and do not process it beyond what is required to deliver the Service.
6. Third-Party Sharing and Providers
We do not sell your data. We may rely on external service providers to operate the system, including:
- Supabase — for database storage and user authentication.
- Vercel — for hosting and running the application.
- Google — for Google account login (OAuth), Gmail synchronization (
gmail.readonly, see Section 8), and calendar integration (calendar.events, see Section 8). No additional data beyond what is required to operate these integrations is shared with Google. - Resend — for sending operational email notifications.
These providers receive access to data only to the extent required to deliver the Service and are required to protect it. We may also disclose data if required to do so by law or court order.
7. Storage, Security, and Backups
Data is stored on secured servers operated by our infrastructure provider (Supabase) located in the European Union (Frankfurt, Germany). We apply industry-standard technical, physical, and organisational security measures, including encryption in transit, access controls, and monitoring. However, no storage or transmission method is 100% secure.
For security and disaster-recovery purposes, data may also be retained in secure backups for a limited period.
We aim to comply with the principles of the European General Data Protection Regulation (GDPR) to the extent applicable to the Service.
8. Google Services Integration — Gmail and Google Calendar
A. Gmail Integration (Optional)
Planora offers an optional Gmail connection. If you choose to connect, Planora requests the gmail.readonly permission from Google.
Planora is read-only with respect to Gmail
Planora does not send, reply to, forward, modify, or delete email messages, and does not manage your Gmail mailbox in any way. All sending and replying continues to happen directly through Gmail.
Purpose of access
Planora reads Gmail data solely to identify business communication that involves client contacts registered in Planora, and to associate relevant communication with Planora projects.
Historical and ongoing access
On first connection, Planora may scan messages from the previous 12 months (excluding drafts, spam, trash, and chats). After that, synchronization is incremental and tracks only changes since the last sync.
Categories of Gmail data accessed
- Message subject
- Snippet / preview text
- Address fields: From, To, Cc, Bcc, Reply-To
- Message body
- Timestamps
- Message and thread identifiers
- Attachment presence indicator (whether attachments exist — not their contents)
Data minimisation
Messages may be read by Planora's servers to determine relevance. However, only threads in which a known Planora client contact participates are stored in Planora's Gmail synchronisation storage. Communication that does not match a known client contact is not permanently retained by the synchronisation system.
Private synchronisation data
Gmail data associated with your connected mailbox is stored in dedicated tables in Planora's infrastructure, for the purpose of delivering the project communication feature. This synchronisation data is private and scoped to your connection.
Shared project communication
When a Gmail thread is associated with a Planora project, it may become part of that project's shared communication history. This shared history is visible to studio members who are authorised to access that project (the studio owner and team members with project access). Gmail communication is not exposed to clients through the Client Portal.
Disconnecting Gmail
Disconnecting Gmail does the following:
- Revokes Planora's OAuth authorisation in your Google account;
- Deletes the Gmail connection and the private synchronisation cache associated with it (threads and message details stored for that connection).
Important:Communication that was already associated with a Planora project before disconnection may remain as part of that project's shared communication history. This history forms part of the studio's project data and is not automatically deleted upon disconnection.
OAuth token security
Gmail OAuth tokens (access token and refresh token) are encrypted server-side before storage. They are not exposed to the browser or client, and there is no intentional logging of token material in application logs.
Note: this encryption applies to OAuth tokens only. Gmail message content (such as subjects and message bodies) is stored in Supabase's secured infrastructure, subject to the security measures described in Section 7.
Human access to Google user data
Human access by Planora personnel to Google user data is restricted. Such access occurs only where permitted under the Google API Services User Data Policy, including:
- With your explicit consent, for the purpose of providing support involving specific data;
- Where necessary to maintain or improve the Service, or to address security or abuse issues;
- Where required by applicable law.
Google Limited Use disclosure
Planora's use of information received from Google APIs — including Gmail data obtained via gmail.readonly— is limited to providing and improving Planora's features. Planora:
- Does not sell Google user data to third parties;
- Does not use Google user data for advertising purposes;
- Does not build advertising profiles from Google user data;
- Does not use Google user data to train general-purpose artificial intelligence or machine learning models.
Planora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
B. Google Calendar Integration (Optional)
Planora offers an optional Google Calendar connection. If you choose to connect, Planora requests the calendar.events permission. This allows Planora to read your primary calendar events and write events to it, for the purpose of integrating project scheduling with your calendar. Planora does not delete or alter existing calendar events without an explicit action on your part.
9. Cookies
We use essential cookies to manage login sessions and operate the Service. These cookies are required for the system to function correctly and are not used for advertising. You may block cookies in your browser settings, but doing so may impair your ability to use the Service.
10. Your Rights
You may view, correct, update, or request deletion of your data, as well as request deletion of your account. Some actions are available directly within the system; for others, please contact us. We may be required to retain certain data for a limited period to comply with legal obligations.
To revoke Gmail or Google Calendar access, you may disconnect the integration in Planora's settings, or revoke access directly through your Google Account.
11. Data Retention
We retain data for as long as your account is active or as required to deliver the Service. Upon account deletion, personal data will be deleted or anonymised, except for data we are required to retain by law.
Gmail's private synchronisation cache is deleted when you disconnect your Gmail connection. Communication that was associated with a project before disconnection may remain as part of project data, as described in Section 8.
12. Policy Changes
We may update this policy from time to time. In the event of a material change, we will publish a notice on the site or within the system and update the date at the top of this document.
13. Contact
For any questions or requests regarding privacy and your data, please contact us at support@planora.co.il.