Legal document
Privacy Policy
- Version and effective date
- Version 1
1. Who processes your data
This Policy explains how Planuze processes personal data in the desktop application, on the planuze.com website and in the associated services.
Corporate identification: [to be completed: legal name, tax ID and full address of the entity operating Planuze]. This is the single deliberate gap in this document; it must be filled in before the text is enforced against a user.
2. The principle: local-first
Planuze is built to keep your work on your machine. Your projects, the declarative model, the generated code and the AI agent sessions are not sent to our servers.
There is also no usage analytics: we do not track screens visited, clicks, session duration or behaviour inside the application.
What we process is the minimum needed to keep your account, your licence, your billing and the marketplace working — set out item by item below.
3. Data we process
| Category | What it is | What for |
|---|---|---|
| Account | e-mail, username, display name, profile picture, e-mail verification date | creating and maintaining your account |
| Authentication | sessions, access and refresh tokens, authorised devices | keeping you signed in and protecting the account |
| Social login (optional) | identifier, verified e-mail, name and picture from Google or GitHub | letting you sign in without a password, if you choose |
| Licensing | plan, licence state, identification of authorised devices | validating the licence and enforcing the device limit |
| Payment | Stripe customer identifier, plan, invoice history and, if you request tax invoices, company name and tax ID | charging you and issuing tax documents |
| Organisations | membership, role and seat | controlling team access |
| Support | messages and attachments you send us | answering your request |
| Marketplace | publisher profile, published packs, download statistics | operating the marketplace and calculating payouts |
| Diagnostics | error and crash reports | fixing defects |
We do not store your card number. Payment is processed by Stripe, which receives the card data directly.
Error reports go through automatic removal of sensitive data before being sent: e-mails, JWT tokens, API keys and fields named as password, secret or authorisation are replaced by markers.
4. What never leaves your machine
- Projects, declarative model and generated code.
- AI agent sessions, history and attachments.
- Your AI provider API keys, stored in the operating system credential vault — Keychain on macOS, DPAPI on Windows, libsecret on Linux.
5. AI agent
Requests to the model provider go directly from your machine, authenticated with your own key. We are not an intermediary: we do not receive, process or keep your prompts or the responses.
What happens to that content is then governed by the policy of the provider you chose. If you use a local model, nothing leaves your computer.
6. Legal bases
We process personal data under the Brazilian General Data Protection Law (LGPD):
- Performance of a contract (art. 7, V): account, licence, billing, support and marketplace.
- Compliance with a legal obligation (art. 7, II): retention of tax documents.
- Legitimate interests (art. 7, IX): account security, fraud prevention and defect diagnosis, always limited to what is necessary.
- Consent (art. 7, I): optional communications, which you may withdraw at any time.
7. Who we share with
We engage processors that handle data on our behalf, under contractual confidentiality and purpose-limitation obligations:
| Processor | What for |
|---|---|
| Cloudflare | hosting the services and the website, and file storage |
| Stripe | payment processing and billing |
| Resend | transactional e-mail (verification, billing, notices) |
| Sentry | receiving error and crash reports |
| Google and GitHub | only if you choose to sign in with social login |
We do not sell personal data and we do not run behavioural advertising.
We may share data where there is a legal obligation, a court order, or a need to defend rights in proceedings.
8. International transfers
Some of the processors above operate servers outside Brazil. In those cases, the transfer takes place with the safeguards required by article 33 of the LGPD, through contractual protection clauses.
9. How long we keep it
- Account and licence: for as long as the account exists. After deletion, we keep data for up to 30 days to allow reversal, then erase or anonymise it.
- Tax documents: 5 years, by legal obligation.
- Support: 2 years after the request is closed.
- Error reports: 90 days.
10. Your rights
The LGPD (art. 18) grants you: confirmation that processing exists, access, correction of incomplete or outdated data, anonymisation or erasure of unnecessary data, portability, information about sharing, and withdrawal of consent.
To exercise any of them, use the support channels in the application or at planuze.com. We respond within 15 days. We need to confirm your identity before acting on requests involving account data.
11. Security
Traffic encrypted in transit; credentials and keys stored in the operating system vault, never in clear text; cryptographically signed licence tokens; internal access restricted to those who need it.
No system is immune. In the event of a security incident with material risk, we notify the affected data subjects and the Brazilian data protection authority within the statutory deadlines.
12. Cookies and the website
The planuze.com website is static and uses no tracking cookies, pixels or analytics tools. The application stores preferences (language, theme, layout) locally on your computer only.
13. Children and adolescents
Planuze is not directed at people under 18 and we do not knowingly collect children's data. If we identify an account in those circumstances, it will be handled as the law requires.
14. Changes to this Policy
This Policy is versioned like the Terms: each version has a number and an effective date, published versions are never edited, and material changes are announced at least 30 days in advance.
15. Data protection officer and contact
Requests about personal data and communications from the data protection officer may be sent through the support channels in the application and at planuze.com.
[to be completed: name and e-mail of the data protection officer, under article 41 of the LGPD]

