Draft — last matched to the code 2026-07-31
Privacy
This describes what Planser actually does with your information today, in plain language. It is a draft, not a finished legal document — see the note in this page’s source for what still needs a lawyer’s review before Planser is public.
The short version
Planser builds your day from what you tell it — text you type, or a photo of a schedule. To do that, what you send is read by Anthropic’s AI models (the company behind Claude, which is what Planser runs on). Once you sign in, your calendar and tasks are stored in an account database that only your signed-in account can read. We don’t sell your data, we don’t run ads, and Settings has a real, immediate “delete everything” button — it means what it says.
What Planser collects, and why
What you type or say.When you tell Planser something (“I have school 8–3 every day,” “bio test Friday”), that text is sent to Anthropic’s AI models, which read it and turn it into structured events and tasks. That’s the entire reason it’s collected — to build and update your day.
Screenshots.A photo of a class schedule or similar is sent to Anthropic to be read, the same way. Planser itself does not keep the photo afterward — only the events and tasks it extracts from it are saved. The image isn’t written to your device’s storage or to your account.
What’s stored on this device.Planser keeps a working copy in your browser’s local storage: your events, tasks, the day it built, and a few preferences (what matters most right now, your notification choice). Goals you set under Programs are, for now, stored only on this device — they don’t sync to your account yet.
What’s stored in your account.Once you sign in, that same data — your events, tasks, the days Planser has built, and your preferences — is mirrored into an account database, so it follows you across devices. Each account can only read and write its own rows; nobody else’s data is reachable from yours.
Your identity.Signing in uses Google, through Clerk (a separate sign-in service). Clerk holds your name, email address, and profile photo as Google provides them, plus the session token that proves it’s you. Planser doesn’t separately store your Google password — it never sees it.
What Planser does not collect.No GPA, no school-name form, no permission blast at signup. No advertising trackers or analytics vendor of any kind are wired into this app today — that’s not a promise about the future, it’s a fact you could verify by reading the code, and true as of this writing.
IP addresses, briefly.Planser’s public “build a day” endpoint (the one that works before you even sign in) keeps a short-lived counter, in server memory only, to stop it from being hammered by scripts. It’s not written to a database and doesn’t persist across a server restart.
Who it’s shared with
Planser doesn’t sell data or share it for advertising. The services below are the real ones this app is built on — each does one job, and none of them see more of your information than that job requires.
- Clerk — handles sign-in and holds your account identity (name, email, profile photo, session).
- Supabase— the database that stores your account’s events, tasks, days, and preferences once you’re signed in, locked so only your own account can reach your rows.
- Anthropic— the AI models that read what you type or photograph and decide how your day fits together; they also power the “tell Planser about this block” editor, and, if you use Programs, help draft a program toward a goal you set.
- Vercel — hosts the app and its servers.
- Voyage AI— a detail worth naming precisely: Voyage only ever processes Planser’s shared research library (published academic studies used to ground scheduling guidance). It never sees your schedule, your captures, or anything personal to your account.
That’s the complete list of outside services this app is built on today. We don’t use email-sending services, advertising networks, or analytics/tracking vendors — none of that is wired into the product right now. If that changes, this page changes with it.
How long it’s kept, and deleting it
Local data stays on your device until you clear your browser storage or use delete below. Account data stays in the database until it’s deleted — signing out doesn’t delete anything, it just ends your session.
Delete everything(Settings → Account & privacy) is real: it immediately clears every Planser key on your device, and if you’re signed in, it clears the matching rows in your account — your events, tasks, days, and preferences all go. There’s no soft-delete, no 30-day grace window, and no backup kept on our side to restore from. This normally happens the moment you tap it; account deletion completes once your device has synced with your account, which is ordinarily near-instant. Because Programs aren’t backed up to your account yet, deleting on a device also permanently removes any goals/programs you built there.
Kids and families
Planser is built for students, including people under 18. Right now, honestly: signing in only requires a Google account — Planser does not itself verify a user’s age or require a parent or guardian’s consent before an account is created. If you’re a parent or guardian, we’d rather say that plainly than claim a safeguard that doesn’t exist yet.
What we can say concretely: there are no ads and no data sales regardless of age; the delete button above applies equally to every account; and a parent can review or remove everything on a shared device the same way any user would, through Settings.
This is one of the areas most in need of a lawyer’s review before Planser is public — see the note at the top of this page’s source.
Security
Planser is young software and hasn’t had an independent security audit or any compliance certification. Your account’s database rows are restricted so only your own signed-in session can read or write them. Beyond that, treat this the way you’d treat any early-stage product: real effort, no guarantees.
Changes to this page
If what Planser actually collects or does with it changes, this page is updated in the same change — it’s meant to describe the real, current app, not a policy frozen in time.
Contact
[TODO: a real contact address/email, and the legal entity operating Planser, go here before launch.]