PlanaPlana

Privacy policy

What Plana does with personal information, in plain words.

Last updated 5 October 2026

Who we are

Plana is run by Plana Pty Ltd ("Plana", "we", "us"), in Australia. This policy explains what personal information Plana handles, why, who it goes to, how long we keep it, and what you can do about it. We follow the Australian Privacy Principles in the Privacy Act 1988.

Questions or requests: privacy@plana.fyi.

Whose information this covers

Plana is used by businesses ("workspaces") to run their jobs. Two kinds of people are involved:

  • People who sign in to Plana: the business's owners and staff.
  • People the business deals with: its customers, contacts and suppliers, whose details the business keeps in Plana or who email the business, and customers who open a proof link the business sends them.

For the second group, the business decides what it records and why, and Plana handles that information on the business's behalf. If you are a customer or supplier of a business that uses Plana, you can also ask that business directly.

What we collect

  • Account details: your name, email address and sign-in details, and which workspaces you belong to and in what role.
  • Workspace content: jobs, quotes, invoices, purchase orders, deliverables, customers, contacts, suppliers, prices, notes, files and artwork, and the history of who changed what.
  • Email and calendar: when a business connects a Microsoft 365 or Google mailbox, Plana reads the messages, attachments, contacts and calendar events in that mailbox so it can file them against jobs and customers. Only mailboxes the business connects are read.
  • Files from services a business connects, such as Dropbox or Google Drive, and text messages sent to or from Plana's number.
  • Proof portal activity: when a customer opens a proof link, their comments, approvals, and the name or email they give.
  • Usage and error information: pages viewed, buttons pressed, the browser and device used, and error reports, so we can see what is hard to use and fix what breaks.

How we use it

  • To run Plana for the business: storing its records, filing email against the right job, showing the right people the right information, and sending the emails and texts the business asks it to.
  • For Plana's AI features: reading and sorting email, suggesting jobs and deliverables, drafting replies and quotes, and answering questions about the workspace. These features send the content they need to an AI model to get an answer. Emails a model drafts wait for a person to approve them before they are sent.
  • To support you, keep Plana secure, and fix and improve it.

We do not sell personal information, we do not use it for advertising, and we do not use a workspace's content to train AI models.

Claude, ChatGPT and other assistants

You can connect Plana to an AI assistant such as Claude or ChatGPT. The connection acts as you, with your permissions: it sees what you can see in Plana and no more, and anything that would email a customer still waits in Plana for a person to approve.

When you use a connected assistant, the information it reads from Plana is sent to that assistant's provider, and their privacy policy covers what they do with it. Plana keeps only a fingerprint of the connection's sign-in token, never the token itself. You can disconnect it at any time from Plana's settings, and it stops working at once.

Who we share it with

We use these service providers to run Plana. Each handles personal information only to provide its service to us:

  • Vercel — hosts Plana, in Sydney; its AI Gateway passes requests to the AI model providers below.
  • Neon — Plana's database, in Sydney.
  • Cloudflare — stores files and artwork.
  • WorkOS — sign-in.
  • Microsoft and Google — the mailboxes, calendars and drives a business connects.
  • Dropbox — files, if a business connects it.
  • Twilio — text messages.
  • Resend — sending the emails Plana sends.
  • Anthropic, OpenAI and Google — the AI models behind Plana's AI features.
  • PostHog — usage analytics and error reports, in the United States.

Some of these providers process information outside Australia, including in the United States. We may also disclose information when the law requires it, or to protect people or Plana from harm.

How long we keep it

We keep a workspace's information for as long as the workspace uses Plana. Deleting a record in Plana archives it, so it can be brought back; ask us if something needs to be removed for good.

When a business stops using Plana, we delete its workspace within 90 days of its request, or of the account closing, unless the law requires us to keep something longer. Copies in backups are overwritten in the normal course after that. Usage and error information is kept for up to two years.

Keeping it safe

Information is encrypted on its way to and from Plana. Only members of a workspace can sign in to it, and what each person can see follows their role — prices and margins, for example, only to the roles allowed. Removing someone from a workspace cuts off their access, including any assistant they connected, immediately.

Your choices

  • See and correct your information in Plana, or ask us for a copy of it.
  • Ask us to delete your information, or a business to delete what it holds about you.
  • Disconnect a mailbox, file service or AI assistant at any time from Plana's settings.

Write to privacy@plana.fyi and we will answer within 30 days. If you are unhappy with our answer, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

Changes

If we change this policy in a way that matters, we will tell workspace owners before it takes effect. The date at the top says when it last changed.