Core principles
PlanMini is a Windows desktop application and browser-based web service for managing schedules and notes and synchronizing them with the Google Calendar and Google Drive accounts you choose to connect. We process only the Google user data needed to provide these features, and we never collect or store your Google password.
Information we process
- Basic account information: Google account identifier, email address, display name, and profile image URL
- Authentication information: OAuth tokens on desktop, the encrypted refresh token and session identifier held by the web authentication service, and the short-lived access token in the current browser tab's memory
- Calendar data: calendar lists, event details, times, recurrence settings, and synchronization identifiers
- Drive data: identifiers for folders and files used by the app, notes, templates, and attachments
- Local data: schedules, tasks, notes, attachments, settings, and synchronization status
- Web usage information: pages visited, access time, browser and device information, referral source, and identifiers used to distinguish sessions and browsers
- Feedback information: the submitted message, optional reply email and public nickname, nickname publication consent, platform, and page where it was sent
Google permissions and their purposes
openid, email, profile: identify you and display your accountcalendar.events: read, create, update, delete, and synchronize events in selected calendarscalendar.app.created: create and manage a supporting calendar dedicated to PlanMinicalendar.calendarlist.readonly: display the calendars available for connectiondrive.file: synchronize notes and attachments used in PlanMinidrive.appdata: manage app settings and synchronization information
Purposes of processing
We use this information to connect your account, configure your workspace, synchronize schedules, notes, and attachments, prevent conflicts, recover from errors, carry out deletion requests, analyze use of the web service, and improve quality. We do not use Google user data for advertising, user profiling, credit assessment, or any purpose unrelated to app functionality.
We do not send Google account identifiers, email addresses, schedules, notes, attachments, or Google authentication tokens to Google Analytics.
We use feedback information to reply, review suggestions and bugs, and credit only nicknames whose publication was separately approved. Email addresses are never published.
Storage and retention
- Desktop data is stored in a local database on your device. Web data is stored in your browser's IndexedDB.
- Desktop OAuth tokens use the operating system's secure storage. Web refresh tokens and basic account information are encrypted at the application level and stored in Cloudflare D1, while plaintext session identifiers are never stored. Web access tokens remain only in the current tab's memory.
- Web authentication information is deleted when you disconnect Google or when the last login session expires. Login sessions are valid for no more than 30 days, and expired information is cleaned up daily.
- When synchronization is enabled, schedules are stored in Google Calendar, while notes and attachments are stored in your Google Drive.
- The web service may use Google Analytics cookies to distinguish browsers and sessions. Analytics data is retained for the period configured in the relevant Google Analytics property.
- Local information may remain until you delete it or remove the app's data.
Third-party sharing
PlanMini does not sell personal information or Google user data. Calendar and Drive content is exchanged directly between your browser and Google APIs. Google authorization-code exchange and token refresh use Cloudflare Workers and D1; schedules, notes, and attachment content neither pass through nor are stored by that authentication service.
We use Google Analytics to process web-service usage statistics, which may send web usage information to Google. Advertising personalization and Google Signals are disabled.
Use of information received from Google APIs is governed by the Google API Services User Data Policy.
For details about Google's data practices, see the Google Privacy Policy.
Your choices and deletion
- Disconnecting Google in the app settings deletes local authentication information and the refresh token and sessions held by the web authentication service, and requests revocation of the Google token.
- You can revoke access directly from Google Account connections.
- You can delete data remaining in Google Drive or Google Calendar directly from those services.
- You can limit Google Analytics browser identification by deleting or blocking cookies in your browser settings.
- For help with deletion, email support@planmini.com.
Security
We use reasonable safeguards including OAuth 2.0 PKCE and state validation on desktop; the OAuth 2.0 authorization-code flow on the web; strict origin and CSRF validation; HttpOnly, Secure session cookies; AES-256-GCM encryption of refresh tokens and account information; one-way hashing of session identifiers; and HTTPS communications. However, no internet transmission or electronic storage method can be guaranteed to be completely secure.
Children's privacy
PlanMini is not directed to children under 14, and the operator does not knowingly collect personal information from children under 14.
Changes and contact
We may update this Policy when features or legal requirements change. For questions about privacy or our handling of Google user data, email support@planmini.com.