Privacy Policy
How Pleana handles your information, in plain language.
Last updated: 15 September 2026
Pleana is a calm personal organiser that helps you keep track of your tasks, notes, people, projects and calendar in one private place. This policy explains what information we collect, why we collect it, how it is used and stored, and the choices and rights you have. We have written it to describe how the product actually works today — not aspirational practices. Where a capability is planned but not yet active, we say so.
1. Account information
When you create an account you provide an email address, and — if you sign up with an email and password — a password, which is stored only as a securely hashed value (we never store your plain-text password). You may optionally provide your name and set preferences such as your time zone, working days, and start/end of day. If you sign in with Google, Microsoft or Apple, we receive basic profile information (such as your name and email address) from that provider to create and identify your account.
2. Your content: tasks, notes, people, projects and contexts
The heart of Pleana is the content you create: tasks, notes, reminders, people you want to keep in mind, projects, life areas and contexts. This information is stored in your account so the app can show it back to you, organise it, and help you stay on top of it. It is tied to your identity because it is your personal data, and it is only accessible to you when you are signed in.
3. Calendar data (Google and Microsoft)
Connecting a calendar is entirely optional and completely separate from signing in. Pleana never requires calendar access to use your account. If you choose to connect a calendar, you grant read-only access:
- Google Calendar — we request the read-only calendar scope (
calendar.readonly). We can read your events to display them alongside your tasks; we cannot create, edit or delete anything in your Google Calendar. - Microsoft / Outlook Calendar — we request the read-only calendar permission (
Calendars.Read). The same limitation applies: read-only, no changes are ever written back.
To keep your calendar in sync we store access and refresh tokens from the provider. These tokens are encrypted at rest before being saved. We store the calendar events we read (such as titles, times and calendar names) so we can show your schedule. You can disconnect a calendar at any time from within the app, which removes our stored tokens for that connection.
4. Future Apple and device calendar access
We may in future offer the ability to connect an Apple calendar or read calendars directly from your device. This capability is not active today. If and when it is introduced, it will follow the same principles described here — explicit opt-in, the minimum access needed, and read-only unless clearly stated otherwise — and this policy will be updated before the feature is released.
5. Authentication providers
You can sign in with an email and password, or with Google, Microsoft or Apple. When you use one of these providers, they authenticate you and share basic profile details (name and email) so we can identify your account. Signing in with a provider is used only for authentication — it does not grant Pleana access to that provider's calendar, mail or other data. Calendar access is a separate, explicit step described above. Your session is maintained using a signed token; we do not sell or share your authentication details.
6. AI processing
Pleana uses artificial intelligence to help you in two ways: to turn a free-form “brain dump” into structured tasks and notes, and to answer questions about your own information. To do this, the relevant text is sent to an AI processing service (the Abacus.AI language-model API) which returns a structured or written response.
- For the capture feature, the text you write plus your local date and time zone are sent so the response can be scheduled correctly.
- For the “ask” feature, the question you type together with the relevant items from your account (such as your tasks, notes, people, projects, events and reminders) are sent so the assistant can answer based on your data.
- We keep a small record of each AI interaction for reliability and troubleshooting. This record stores only a short summary (roughly the first 200 characters of your input), the type of interaction, the model used, token counts, duration, and whether it succeeded — it does not store the full response.
AI output is assistive and may be imperfect; it is intended to help you organise your own information, not to make decisions on your behalf.
7. Subscriptions and payment processing
Pleana does not currently process payments, offer paid subscriptions, or collect any billing or payment-card information. If paid plans are introduced in the future, payment handling will be provided by an established payment processor, we will not store full card details ourselves, and this policy will be updated to describe exactly what is collected before any such feature goes live.
8. Analytics and crash reporting
Pleana does not currently use third-party analytics, advertising or crash-reporting tools. We do not track your activity across other apps or websites. If we add any analytics or crash reporting in the future, we will update this policy first and, where required, ask for your consent.
9. Transactional email
We send a small number of service emails that are necessary to operate your account — for example, to verify your email address when you sign up, and to help you reset your password. We do not send marketing email.
10. How your information is stored and secured
Your data is stored in a managed database on the infrastructure that hosts Pleana. Calendar access and refresh tokens are encrypted at rest. Passwords are stored only as secure hashes. Access to your content requires you to be signed in, and each request is checked against your session. No method of storage or transmission is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.
11. Data retention
We keep your information for as long as your account exists, so the app can show it back to you. We do not currently apply fixed expiry periods to your content. When you delete your account, your data is removed as described in the next section. Because Pleana does not process payments today, there are no billing or accounting records that would need to be retained after deletion.
12. Deleting your account and data
You can delete your account at any time from Settings → Delete account inside the app. Deletion is permanent and removes your profile, preferences, tasks, notes, reminders, people, projects, life areas, contexts, captured items, saved calendar connections and synced calendar events, and your AI interaction records. Where practical, we also attempt to revoke the calendar tokens we hold at the point of deletion. For a full explanation of what is removed, see our account deletion page. You may also request deletion by emailing [email protected].
13. International processing
Pleana is operated using cloud infrastructure that may process and store data in locations outside your country of residence. Wherever your data is processed, it is handled in accordance with this policy.
14. Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal information, and to object to or restrict certain processing. You can access and update much of your information directly in the app, and delete your account as described above. To make any other request, contact us at [email protected].
15. Changes to this policy
We may update this policy as Pleana evolves. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you in the app.
Contact
For privacy questions or requests, email [email protected]. For general help, email [email protected] or visit our support page.