Privacy

How your data is handled.

What we collect, why we process it, how long we keep it, and how you can exercise your rights.

Last updated: September 10, 2026

Privacy Policy

At Plannk, we respect your privacy and are committed to protecting your personal data. This Privacy Policy describes how we collect, use and protect your information.

1. Personal data we collect

Data provided by you:

  • Account information (name, email, password, phone).
  • Personal identifiers, when necessary: CPF (Brazil) or SSN/ITIN (USA) for individuals.
  • Business identifiers, when applicable: CNPJ (Brazil) or EIN (USA) for legal entities.
  • Content you create (prompts, files, images, documents).
  • Payment information (processed by PCI-DSS certified third parties).
  • Communications with us (support, feedback, complaints).
  • Organization data (for business and government accounts).
  • Connected calendar data (Google Calendar or Microsoft 365), only when you authorize the connection, as described in section 4.

Note on sensitive identifiers: we collect CPF, CNPJ, SSN, EIN or other tax/government identifiers only when strictly necessary for billing, tax compliance or identity verification required by law. This data receives additional protection.

Automatically collected data:

  • Usage and interaction data with the Services (features used, frequency, duration).
  • Device information (model, operating system, unique identifiers).
  • Browser information (type, version, language settings).
  • IP address and approximate location (country, state, city).
  • Cookies and similar technologies (as per specific section).
  • Access and security logs.

2. How we use your data and legal bases

Purposes and legal bases:

  • Service provision: performance of a contract (LGPD Brazil: Art. 7, V).
  • Billing and payments: performance of a contract and legal obligation.
  • Technical support: performance of a contract.
  • Security and fraud prevention: legitimate interest (LGPD Brazil: Art. 7, IX).
  • Service improvements and AI training: legitimate interest with anonymized data (LGPD Brazil: Art. 7, IX and Art. 12).
  • Direct marketing: consent (LGPD Brazil: Art. 7, I) - you can opt out.
  • Legal compliance: legal obligation (LGPD Brazil: Art. 7, II).

For users in the United States (CCPA/CPRA - California and applicable state laws):

  • We do not sell your personal information ("sale" as defined in the CCPA).
  • We do not share your information for cross-context behavioral advertising ("sharing" per CPRA).
  • You can exercise your rights of access, deletion, correction and opt-out according to applicable state legislation.

Important about AI training:

  • Identifiable personal data: not used for training without specific consent.
  • Anonymized data: we may use them to improve our models and Services, as they are not considered personal data by LGPD (Brazil) or "Personal Information" by CCPA/CPRA (USA).
  • Benefits: the use of anonymized data allows us to improve the quality, accuracy and security of our services for all users.
  • Connected services data: information received through Google or Microsoft APIs (such as calendar events) is never used to train, improve or develop generalized artificial intelligence models, not even in anonymized form.

3. Data sharing

Your data may be shared with:

  • Service providers: hosting, payment processing, technical support, data analysis, marketing, security, cloud.
  • Business partners: only as necessary and always in compliance with LGPD (Brazil) and applicable privacy laws.
  • Legal authorities: for compliance with legal obligations, court orders or defense of rights.
  • Corporate transfers: in case of merger, acquisition, sale or restructuring.
  • Third parties indicated by you: only with consent or express instruction.
  • Other users: when you choose to share content publicly.

Important: we do not sell your personal data (as defined by LGPD Brazil and CCPA/CPRA USA). All sharing strictly follows applicable data protection legislation and is limited to the minimum necessary.

4. Connected services: Google Calendar and Microsoft 365

You can connect your Google calendar (Google Calendar) or Microsoft calendar (Outlook/Microsoft 365) to Plannk through an OAuth authorization that you grant. The connection is optional, belongs to your individual account and can be removed at any time.

Data we access:

  • Google Calendar: events from your primary calendar (title, time, organizer, attendees, meeting link, location and description), through the read-only events scope, and the email address of the authorized account.
  • Microsoft 365: events from your calendar, through the read-only calendar scope, and the email address of the authorized account.
  • We do not request permission to create, edit or delete events, nor access to your mailbox, your contacts or your files.

How we use this data:

  • Identify online meetings (Google Meet, Microsoft Teams and Zoom) and, when you enable automatic recording, send an assistant to record and transcribe the meeting.
  • Display synchronized meetings in your meetings area and link recordings, transcripts and summaries to the corresponding event.
  • Identify the connected account by its email and avoid duplicate connections.

Storage, sharing and retention:

  • Access tokens are stored encrypted and are used only by our servers to synchronize the calendar; they are never displayed or shared.
  • We synchronize a window of recent and upcoming events (approximately 7 days back and 60 days ahead) and keep only the fields needed for the purposes above.
  • We share with service providers only what is strictly necessary for the feature, such as the meeting link with the service that operates the recording assistant.
  • Calendar data is not sold, is not used for advertising, is not transferred to data brokers and is not used to train generalized artificial intelligence models.
  • When you disconnect the account, we revoke the authorization with the provider and delete the tokens and the synchronized events. Meetings, recordings and summaries already created from them remain in your account until you delete them.
  • You can also revoke access at any time in the security settings of your Google Account or your Microsoft account.

Plannk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data retention and deletion

Retention periods:

  • Account data: during the relationship and up to 6 months after termination.
  • Tax data: 5 years according to Brazilian tax legislation (CTN) or 7 years according to IRS (USA), whichever applies.
  • Security logs: 30-180 days (extendable if there is an investigation).
  • Conversations/content: until you delete the content or close your account.
  • Support: 3 years after resolution.
  • Anonymized data: indefinite period (may be used for training and improvements).

Deletion: after the deadlines, we perform secure deletion or irreversible anonymization, except for retentions required by law or for defense in proceedings.

6. Your rights as a data subject

Rights guaranteed by LGPD (Brazil):

  • Confirmation and access: verify if we process your data and obtain a copy.
  • Correction: update incomplete or incorrect data.
  • Deletion: delete unnecessary or irregularly processed data.
  • Portability: receive your data in a structured format.
  • Anonymization/blocking: for excessive or irregular data.
  • Information: know with whom we share your data.
  • Revocation: withdraw consent at any time.
  • Objection: contest processing based on legitimate interest.
  • Review: request human review of automated decisions.

Additional rights for California residents (CCPA/CPRA - USA):

  • Right to Know: know what personal information we collect, use and share.
  • Right to Delete: request deletion of your personal information.
  • Right to Correct: correct inaccurate personal information.
  • Right to Opt-Out: refuse the sale or sharing of your information.
  • Right to Limit Use: limit the use of sensitive personal information.
  • Right to Non-Discrimination: not be discriminated against for exercising your rights.

Rights for residents of other US states: if you reside in Colorado, Connecticut, Virginia, Utah or other states with privacy laws, you may have similar rights. Contact us to exercise them.

How to exercise: send a request to [email protected] with identification.

Response time: up to 15 days (extendable by 15 more with justification).

7. Children and adolescents

Our Services are not directed to children under 13 and we do not intentionally collect data from children in this age group.

Minors between 13 and 18 years old need express authorization from parents or legal guardians to use the Services.

If we become aware that we have collected data from a child under 13 without verifiable parental consent, we will take steps to delete that information.

8. Cookies and similar technologies

Types of cookies we use:

  • Essential: necessary for basic operation (authentication, security, session preferences). Do not require consent.
  • Functional: user personalization and preferences (language, theme). Require consent.
  • Analytics: understand how the Services are used for improvements. Require consent.
  • Marketing: relevant advertising and campaign measurement. Require consent.

Management: you can manage your cookie preferences in your profile or browser settings.

9. Security and international transfer

Security measures:

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Secure authentication with bcrypt hash.
  • Principle of least privilege for data access.
  • Continuous security monitoring.
  • Regular backups with geographic redundancy.

International transfer: your data may be processed in countries where our suppliers operate (USA, EU). We use appropriate safeguards, including standard contractual clauses when applicable.

10. Changes to this Policy

We may update this Policy periodically. We will notify you of significant changes 30 days in advance via email and/or in-app banner.

We recommend reviewing this Policy periodically. The update date at the top indicates when the last modification was made.

Final provisions

These Terms of Use and Privacy Policy constitute the entire agreement between the user and Plannk, superseding any prior understandings. If any provision is deemed invalid, the others shall remain in full force and effect.

Responsible vulnerability disclosure: we value security researchers who act in good faith. Report vulnerabilities to [email protected] with detailed description, reproduction steps and potential impact. Do not take actions that could harm our users or systems.

Contact:
For questions, requests or exercise of rights: [email protected]
For security issues: [email protected]
For business opportunities and partnerships: [email protected]

Reach the right team.

Choose the channel that matches your subject so your request arrives with the context it needs.

Contact support