Privacy Policy
In effect from Sep 2026
This policy explains what PlanRill collects when you use the service at planrill.com, why we hold it, who else processes it, and what you can ask us to do with it. It is written to be read, not to be survived.
1. Who controls your data
PlanRill is operated by WynLara ("PlanRill", "we"), a company registered in California, United States. For the account and billing information described below, we are the data controller. For the work content your team puts into a workspace, your organization is the controller and we act as a processor on its instructions.
Questions, requests, or complaints: contact us here.
2. What we collect
Account information
Your name, email address, and a password stored only as a salted hash — we never hold the password itself. If you sign in with Google, we receive your name, email address, and Google account identifier; we do not receive your Google password, and we do not read your Gmail, Drive, or contacts.
Workspace content
Whatever your team creates in PlanRill: organizations, spaces, projects, activities and tasks, schedules and dependencies, notes, feed posts and comments, meetings and calendar events, links, uploaded documents, and your private notebook. We also record who did what and when, as an activity history your organization can audit.
Planrill AI
If your organization uses Planrill AI, the questions you type into it and the workspace content it reads on your behalf — only what you yourself are allowed to see, including the text of PDF, Word and plain-text files uploaded to your projects — are sent to our AI processor to produce the answer. Conversations are stored so you can return to them and are private to you.
Nothing the assistant proposes changes your workspace until a person applies it; every applied change is recorded in the project's history with who requested and who approved it, and can be undone while the item is untouched. A person may also approve a standing rule or a short plan: those run under that person's own permissions, every run is recorded the same way, and a rule pauses if it fails or its approver loses access. The assistant remembers something across conversations only when you ask it to, and forgets on request. Each night we also check your projects for a milestone at risk or work gone stale and notify the people concerned; those checks run on our own servers and send nothing to the AI processor.
Imported calendars
If you connect an external calendar, we store the feed address you give us and a cached copy of the events it returns, so your agenda can show them alongside project work. That address is a credential: it is never displayed back to you in full, never shown to anyone else in your organization, and never shared with a third party. Imported events are visible only to you. You can remove a feed at any time in Settings, which deletes the address and the cached copy.
Billing information
Your plan, the members it covers, and an identifier issued by our payment processor. We never see or store your card number — card details are entered directly with Stripe and never reach our servers.
Technical information
A session cookie that keeps you signed in, a cookie remembering which space you last viewed, and ordinary server logs (IP address, browser, timestamps) kept for security and troubleshooting. We do not use advertising cookies, we do not run third-party trackers, and we do not sell or share personal data for advertising.
3. Why we use it, and on what basis
- To provide the service — performing our contract with you: rendering your projects, sending notifications you asked for, and keeping your session alive.
- To bill you — performing our contract, and complying with tax and accounting law.
- To keep the service secure and working — our legitimate interest in preventing abuse, diagnosing faults, and protecting accounts.
- To email you about your account — verification codes, password resets, invitations, and the notification digests you control in Settings. We do not send marketing email to your users.
4. Where your data lives
PlanRill runs in Frankfurt, Germany. Both the application and the database are hosted in the European Union, and your workspace content stays there.
We are a California company, so our own staff may access that data from the United States in order to operate and support the service. Where a transfer out of the European Economic Area is involved, it is covered by the European Commission's Standard Contractual Clauses.
5. Who else processes it
We keep the list short on purpose. Each of these is bound by a data processing agreement and may use your data only to provide their service to us:
| Processor | What for | Where |
|---|---|---|
| Vercel | Application hosting | EU (Frankfurt) |
| Neon | Database hosting | EU (Frankfurt) |
| Stripe | Payments and invoices | US / EU |
| Resend | Transactional email | US / EU |
| Sign-in, if you choose it | US / EU | |
| Google (Gemini API) | Planrill AI answers, if your organization uses it | US / EU |
Where a processor operates outside the European Economic Area, transfers are likewise covered by the Standard Contractual Clauses.
6. Who can see your content
This one matters more than people expect in a team tool. PlanRill is a shared workspace, not private storage.Anyone granted access to a project can see the work in it, and organization owners and administrators can reach every project in the organization. Your activity — what you changed and when — is visible in that project's history.
The exceptions are deliberate: your private notebook and your imported calendar events are yours alone, and are never shown to other members.
We do not sell your data, we do not share it with advertisers, and we do not train machine-learning models on your workspace content. Our AI processor may use the content it receives from us only to produce the answer, not to train its models. We disclose data outside the processors above only where the law compels it.
7. How long we keep it
Deleted items go to a restorable state first, so an accident is recoverable, and are then removed. When an account is closed we delete its workspace content; billing records are retained where tax and accounting law requires it, reduced to what those rules demand and stripped of anything they do not.
8. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, or stop a particular use of it. Use the contact page and we will respond within 30 days. Depending on where you are, those rights come from the EU General Data Protection Regulation, the California Consumer Privacy Act as amended by the CPRA, or the Saudi Personal Data Protection Law — we apply them to everyone rather than sorting people by passport.
For California residents specifically: we do not sell your personal information, and we do not share it for cross-context behavioural advertising — so there is nothing to opt out of. We will never discriminate against you for exercising a privacy right.
If your data belongs to a workspace your employer controls, we may need to pass your request to them — we will tell you if that happens. You also have the right to complain to your national data protection authority: in the EU that is your member state's supervisory authority, in Saudi Arabia the Saudi Data & AI Authority, and in California the Attorney General.
9. How we protect it
Everything travels over HTTPS. Passwords are hashed, never stored or logged in the clear. Each organization's data is isolated at the database level as well as in the application, and every request is checked against your permissions before it returns anything. Sign-in requires a verified email address, and resetting a password ends every other session.
No service can promise perfect security. If a breach affects your personal data we will notify you and the relevant authority as the law requires.
10. Children
PlanRill is a workplace tool and is not intended for anyone under 16. We do not knowingly collect data from children.
11. Changes
If we change this policy in a way that materially affects you, we will email the address on your account before it takes effect. The date at the top always reflects the current version.