Legal

Privacy Policy

Here we explain what data we collect, what we use it for, how long we keep it, and how you can exercise your rights. No small print, no runaround.

Last updated: 2 August 2026

1. Data controller

The data controller for the personal data collected through the Planera mobile app (iOS and Android) and the website planera.es is Alejandro Fraile (hereinafter, "Planera", "we" or "the controller").

This Privacy Policy clearly explains what data we process, for what purpose, for how long, and with whom we share it, in compliance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

For any questions about privacy, you can write to us at any time at: privacidad@planera.es

2. What data we collect (and what we don't)

We apply the principle of data minimisation: we only collect the data that is strictly necessary for Planera to work. Below we detail each category.

a) Identity and account data

  • Email address (required) and username, needed to create your account and sign in.
  • Password, which is always stored encrypted using hash functions; never in plain text or visible to us.
  • Optional profile data that you choose to provide: name, gender, date of birth, profile type (student, professional, personal…) and avatar photo. You can leave these blank and edit or delete them whenever you like.
  • Sign in with Apple: if you use "Sign in with Apple", we receive the identifier Apple provides us and an email address (which Apple lets you hide behind a private relay address). We also store, encrypted, an Apple session token whose sole purpose is to let us revoke your Sign in with Apple access when you delete your account.

b) Content you create (usage data)

  • Tasks and subtasks, subjects, grades and marks, calendar events, exams, habits, streaks, shopping lists, training routines and workout sessions (including, if you choose to log it, your body weight linked to each session), focus sessions (duration, linked task and alert preferences), academic programmes, flashcard decks and cards, recipes (ingredients, steps, timings and servings), your weekly menu and your app preferences.
  • This data is yours. You enter it, you control it, and you can modify or delete it at any time.

c) Photos and images

  • Your avatar photo and the custom photos for your task icons, if you choose to add them from the camera or your photo library.
  • Camera and photo library permissions are only requested when you choose to use these features, and you can revoke them in your device settings. We do not access your photo library without your explicit action.

d) Your garage and vehicle data

  • Vehicle data that you enter: nickname, make, model, year, number plate, chassis number (VIN), fuel and body type, transmission, current and estimated mileage, MOT and insurance dates, and notes.
  • Maintenance and history: maintenance, repair, inspection and upgrade records, with their date, mileage, cost, parts and warranties, as well as the maintenance plans and reminders you set up.
  • Garages you save: name, speciality, phone number, address, coordinates, rating and notes. You provide this data for your own record-keeping.

e) Location (Garage feature, optional)

  • If you use the nearby-garages radar or start a trip to a garage, we ask for permission to access your location "while using the app". We use it to centre the map near you and calculate the distance and estimated arrival time at the garage.
  • We do not track your location in the background or keep a history of your movements. Your position is used in the moment and is not stored on our servers as location data.
  • To display the maps and calculate the route, your coordinates and the garage's are sent to map and routing providers (OpenFreeMap and OSRM). You can deny or revoke the location permission in your device settings; the rest of the Garage will keep working, just without distance or route.

f) Subscription and payment data

  • The purchase and renewal of the Pro subscription are processed by the Apple App Store / Google Play and RevenueCat. We store a subscription identifier, its status (active, cancelled, expired) and its source.
  • Planera does not store or have access to your card details or your payment method. That information is handled directly by the app store.

g) Technical and device data

  • Device type, operating system, browser identifier (user agent) and push notification token (if you enable notifications), needed to deliver alerts to you.
  • The IP address of your last sign-in and security logs (access audit trail), which we use exclusively to protect your account and detect unauthorised access.
  • Crash reports and performance metrics (via Sentry) to keep the app stable. This data is technical and is not used for advertising purposes.

h) Google Calendar (Pro feature, optional)

  • If you connect your Google Calendar, we store, encrypted, the access tokens and the Google account email solely to sync your events. You can disconnect it at any time from settings.

i) Focus mode, alarms and Live Activities (optional)

  • If you use focus mode, we store on your account and/or device the session duration, the linked task (if you choose one) and your alert preferences (alert on finish and persistent alarm).
  • On iPhone with iOS 26 or later, if you turn on alerts or an alarm, we'll ask for permission for Planera to schedule alarms and timers via Apple's native framework (AlarmKit). The timer and the alert are managed on the device; we do not send the alarm's content to our servers.
  • The countdown may be shown on the Lock Screen and in the Dynamic Island via Live Activities linked to AlarmKit. On other iOS versions or on Android, we use local notifications instead.
  • We also use Live Activities for the workout rest timer and for the trip to the garage in the Garage feature, when you turn them on.
  • You can revoke the alarms permission in iPhone Settings (Planera → Alarms & Timers) and the notifications permission in your system settings at any time.

j) Friends and your profile visible to others

  • Planera has an optional friends layer: if you don't add anyone, nothing in this section applies to you.
  • When someone adds you, they see your name, your username and your profile photo. Nothing else: not your email, not your date of birth, not your activity.
  • To find you, someone needs your exact username. There is no fuzzy search or directory of people, precisely so no one can sweep through the list of users.
  • You can stop being discoverable by username from settings, and block someone at any time. Blocking or ending a friendship instantly revokes anything you had shared with each other.
  • We store the status of the relationship (pending request, accepted or blocked) and its date, which is what's needed for the feature to work.

k) Messages

  • If you use the chat, we store on our servers the messages you send and receive, with their date, and the photos you send through that channel.
  • Messages are not end-to-end encrypted. They travel encrypted in transit (HTTPS) and are stored on a server that only the Planera team accesses for technical purposes, but we are technically able to read them. We're telling you this clearly so you can decide what you write there.
  • On your device, the local copy of your conversations is stored encrypted.
  • For the chat to work we also process ephemeral data: whether you're online, whether you're typing, and how far you've read in the conversation. "Online" and "typing" status isn't stored in the database: it's calculated on the fly and disappears when you close the app.
  • You can delete a message; it's removed for both parties. Deleting your account deletes all your conversations.

l) What you share with a friend

  • You can share a shopping list, a task list or a vehicle with a specific person. While the share stays active, that person can view and edit that content in real time.
  • A note on cars: sharing a vehicle means the other person sees everything you've saved about it, including the number plate, the chassis number (VIN), the MOT and insurance dates, and the maintenance history. Only share it with someone you really trust.
  • Recipes and training routines work differently: they travel as a copy. The recipient keeps their own version, and any later changes you make don't reach them. The dish photo is not sent.
  • You can stop sharing whenever you like, and the other person can leave too. In both cases access is cut off instantly: it's checked on every read, not just when opening.

m) Sharing outside Planera

  • You can generate a story-format image of a recipe. The image is created on your device: it doesn't pass through our servers.
  • From there, you choose which app to send it to (Instagram, WhatsApp, whichever) via the system's share menu. From that point on, that app's privacy policy applies, not ours. Planera does not post anything on your behalf and has no access to your social media accounts.

n) Data we do NOT collect

  • Your phone number: Planera does not request or store your personal phone number. (A garage's phone number that you add is business contact data you enter voluntarily.)
  • Continuous location tracking: we don't track your position in the background or keep a history of your movements. We only access your location at specific moments and with your permission, for the Garage feature (see section "e").
  • Advertising behavioural data: we don't profile your activity for advertising, and we don't sell your data.
  • A public social network: Planera has no walls, no followers, and no content visible to strangers. What you share goes to a specific person you choose.
  • Your contacts list: we don't read it and we don't ask for permission to. To add someone you need their username.

3. Purpose and legal basis for processing

We process your data for the following purposes, each backed by a legal basis under Article 6 of the GDPR:
  • Providing the service: creating and managing your account, storing your content and syncing it across devices, and offering you the app's features. Legal basis: performance of a contract (Art. 6.1.b).
  • Managing the Pro subscription: activating paid features and verifying your subscription status. Legal basis: performance of a contract (Art. 6.1.b).
  • Security and fraud prevention: access, IP and audit logs to protect your account. Legal basis: legitimate interest (Art. 6.1.f) and legal obligation (Art. 6.1.c).
  • Improvement and stability: error diagnostics and technical performance metrics. Legal basis: legitimate interest (Art. 6.1.f).
  • Managing the garage: storing your vehicles, their maintenance, garages and reminders to help you keep them up to date. Legal basis: performance of a contract (Art. 6.1.b).
  • Focus mode and alarms: scheduling timers and alerting you when the session ends, including native alarms on iPhone when you authorise them. Legal basis: performance of a contract (Art. 6.1.b) and, for AlarmKit, notifications and Live Activities, consent (Art. 6.1.a).
  • Push notifications, alarms (AlarmKit), camera, photo library, location and Google Calendar: features that only activate with your permission. Legal basis: consent (Art. 6.1.a), revocable at any time.
  • Friends, chat and shared content: letting you add a person, talk to them and share a list or a vehicle with them, which involves showing them your name, username and photo. Legal basis: performance of a contract (Art. 6.1.b); this is an optional feature that only activates when you use it.
  • Moderation and community standards: handling blocks and reports between users and preventing abusive use of the chat. Legal basis: legitimate interest (Art. 6.1.f).
  • Service communications: notices about your account, email verification or important changes. Legal basis: performance of a contract.

4. Retention periods

We keep each piece of data only for as long as necessary for the purpose that justifies it:
  • Account and content data: for as long as you keep an active account. When you delete your account, your content is immediately deleted from the database and your personal data is irreversibly anonymised; backups rotate and are gone within a maximum of 30 days.
  • Technical and error logs: up to 90 days for diagnostic purposes, anonymised where possible.
  • Security and audit logs: for as long as necessary to ensure security and handle any claims.
  • Billing data: retained by Apple, Google and RevenueCat according to their own retention periods and applicable tax obligations.
  • Chat messages and photos: until you or the other person delete them, or until one of the two accounts is deleted. Deleting a message removes it for both parties.
  • Shared content: the permission lasts as long as the share and the friendship do. When you stop sharing, block someone, or end a friendship, access is revoked immediately.
  • Friendship: for as long as it exists. Ending it also deletes the record, except for a block, which is kept so it keeps having effect.

Where the law requires us to retain certain information for a specific period (for example, tax or security obligations), we will keep it blocked until that obligation lapses.

5. Third parties and international transfers

To provide the service we rely on providers acting as data processors. They only access the data they need, and do so under contract in accordance with Art. 28 of the GDPR:
  • Apple App Store / Google Play — app distribution, push notifications and subscription payment processing.
  • RevenueCat — management and validation of in-app subscriptions.
  • Sentry — error and technical performance monitoring.
  • Google — only if you enable Google Calendar sync.
  • OpenFreeMap — maps for the Garage feature. Receives the requests needed to display the maps (including the area you're viewing).
  • OSRM (routing service) — calculating the route to the garage. Receives your coordinates and the garage's only when you start a trip.
  • Infrastructure and notifications provider — secure database hosting and push notification delivery (Expo).
  • Other Planera users: the natural recipient of a message or a shared list is the person you choose. This isn't a disclosure to a third party in the classic sense — you decide it, case by case — but it's worth bearing in mind: whatever you send them, they have.
  • The app you share a story to: if you generate a recipe image and choose to send it to Instagram, WhatsApp or another app, that image leaves Planera and becomes subject to that app's policy. We play no part in that transfer and don't know where it ends up.

Some providers may process data outside the European Economic Area. In those cases we guarantee an adequate level of protection through the European Commission's Standard Contractual Clauses or other valid GDPR mechanisms.

We do not sell your data or disclose it to third parties for advertising or commercial purposes unrelated to the service.

6. Your rights

As the data subject, you can exercise the following rights at any time:
  • Access: find out whether we process your data and obtain a copy.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): delete your data when it's no longer necessary. You can delete your account directly from the app (Profile → "Danger zone" → "Delete account"): all your content (tasks, events, subjects, workouts, vehicles, photos…) is deleted immediately, your personal data is irreversibly anonymised, your Sign in with Apple access is revoked if you used it, and the account is deactivated instantly.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection and restriction: object to certain processing or ask us to restrict it.
  • Withdraw consent: for processing based on it (camera, photo library, notifications, focus mode alarms, Google Calendar), without affecting the lawfulness of processing carried out before the withdrawal.

To exercise these rights, write to us at privacidad@planera.es. We will respond within a maximum of one month. You can also lodge a complaint with the Spanish Data Protection Agency (AEPD).

7. Data security

We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration:
  • Encrypted connections (HTTPS/TLS) across all communications.
  • Passwords stored using hashing, plus an optional two-factor verification (2FA).
  • Secure storage of credentials and tokens on the device, restricted access to production data, and regular backups.
  • Access is checked on every read, not just when opening: if someone loses permission to a list or a car, they stop seeing it instantly, even if they had the screen open.
  • When you request something that isn't yours, the answer is always "not found", never "you don't have permission". This is deliberate: a "you don't have permission" response would confirm that the content exists.
  • Local copies of your conversations on your device are stored encrypted.

No system is 100% foolproof. If a security breach were to occur that affects your rights, we will notify you without undue delay in accordance with Articles 33 and 34 of the GDPR.

8. Minors

Planera is not aimed at children under 14, and we do not knowingly collect their data. If you are under 14, you need the consent of your parent or legal guardian to use the service. If we detect, or are informed, that a minor has provided data without that authorisation, we will delete it without delay.

9. Cookies and similar technologies

The website planera.es only uses strictly necessary technical cookies for it to function. We do not use tracking cookies or third-party advertising cookies.

The mobile app does not use cookies. Session data is stored securely on the device (the system's secure storage).

10. Changes to this policy

We may update this policy to reflect changes in the service or in applicable law. When we do, we will update the "Last updated" date at the top. If the changes are significant, we will let you know by email or via a notice in the app.

We recommend you review this page periodically. Also see our Terms and Conditions and our Data & Compliance page.

Got questions?

We're here to help.

If you have any questions about this policy or want to exercise your rights, write to us. We respond within a maximum of 72 hours.