Plankast Beta
Capture Plan Your data Agents FAQ
Sign in Request an invite

Legal

Privacy Policy

What Plankast collects, what it never collects, who else ever sees it, how long it is kept, and how to take it all back.

Effective 23 September 2026Last updated 23 September 2026Version 2026-09-23

On this page

  1. Who we are
  2. What we collect
  3. What we never do
  4. How we use it
  5. AI providers and your keys
  6. Agents and MCP
  7. Calendars and contacts
  8. Who else sees it
  9. How long we keep it
  10. Your rights and choices
  11. Security
  12. Where it is stored
  13. Children
  14. Changes
  15. Contact

The short version

  • Your notes, tasks, projects and boards are yours. We do not read them, mine them, sell them, or train anything on them.
  • plankast.com sets no cookies and runs no analytics or advertising trackers. There is no banner because there is nothing to consent to.
  • Plankast has no AI subscription and no server-side model keys. Content only reaches an AI provider when you have connected your own key to that provider, and only for the purpose you assigned it.
  • Your vault is plain Markdown. You can download the whole thing at any time, and delete your account by emailing us.

This summary is here to be read. It is not a substitute for the sections below, which govern.

01Who we are

Plankast is a notes, tasks, calendar and whiteboard application operated by Bryan Saxon LLC, an Alabama limited liability company (“Plankast”, “we”, “us”). This policy covers the Plankast website at plankast.com, the Plankast applications for iOS, iPadOS, Android, macOS, Windows, Linux and the web, and the Plankast API and MCP server at api.plankast.com.

Plankast is in private beta and is invite-only. For the purposes of the UK and EU GDPR, Bryan Saxon LLC is the data controller for the personal information described here.

02What we collect

We collect four kinds of information, and no more than each one needs.

Account information
Your name, your email address, and a one-way hash of your password — we never store the password itself. If you register a passkey we store its public key and an opaque identifier that is deliberately not your email address. We also store the invite code your account was created with, and the fact that you agreed to the Terms of Service and this Privacy Policy, with the date and the version you agreed to.
The content you create
Notes, tasks, projects, tags, saved filters, board and canvas content, handwritten ink pages, audio recordings and their transcripts, files you attach, and the people pages Plankast builds from your calendars and contacts. This is your vault. We store it so we can sync it between your devices, and for no other purpose.
Data from accounts you connect
If you connect Google Calendar or Microsoft 365, we store the access tokens, the calendars and events you have chosen to sync, and — only if you granted that scope separately — your contacts from that account. Contacts are read-only: Plankast never writes to, changes or deletes anything in your Google or Microsoft address book. If you connect an AI provider, we store the API key you supply, encrypted at rest.
Technical and operational data
For each signed-in session we record the IP address and browser or app user-agent it was created from, so that you can see and revoke your own sessions and so we can detect abuse. Our servers keep short-lived operational logs. If you asked for an invite through the form on plankast.com, we keep the email address you gave us, the name if you gave one, and which of the tool categories you ticked.

03What we never do

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have and this is not a policy we intend to change; if it ever did change, we would tell you before it took effect and give you a way out.
  • We do not train AI models on your content. Not ours, not anybody's.
  • We do not read your notes. Staff access to the content of an account is limited to the rare case where you ask us for help with a specific problem and agree to it, or where the law requires it.
  • plankast.com sets no cookies and runs no analytics, advertising or session-replay scripts. The Plankast application stores a sign-in token and a local copy of your own data on your own device, which is what makes it work offline. That is local storage, not tracking, and signing out clears it.

04How we use it

We use the information above to run the service and to do the things you asked it to do:

  • To create and secure your account, sign you in, and let you see and revoke your own sessions.
  • To store your vault and sync it between your devices, including keeping both copies when an offline edit conflicts.
  • To show your calendar, to time-block tasks onto it, and to build one page per person from the calendars and contacts you connected.
  • To carry out AI work you have configured, using the provider keys you supplied — see section 5.
  • To answer you when you contact us, and to send you the small number of service emails the account requires, such as your invite. We do not send marketing email.
  • To keep the service up, diagnose faults, prevent abuse, and meet our legal obligations.

Where the GDPR applies, our legal bases are the performance of our contract with you for everything needed to provide the service, our legitimate interests in keeping the service secure and working, your consent where you connect an outside account or provider, and legal obligation where the law requires it.

05AI providers and your keys

Plankast has no AI subscription of its own and holds no model provider keys on the server other than the ones you give it. Every AI feature has a complete, working state without a model connected.

When you connect a provider — Anthropic, OpenAI, xAI, or any OpenAI-compatible endpoint including one running on your own machine — you assign it to a purpose: chat and summaries, vision and handwriting, embeddings for search, or transcription. From that point, and only for that purpose, the relevant content is sent to that provider under your account with them, and their privacy policy and terms govern what they do with it. We suggest reading them. Disconnecting a provider stops this immediately.

Two consequences worth stating plainly. Embeddings are opt-in because assigning a provider to embeddings re-indexes your existing vault, which means sending it. Transcription can stay on your device — the on-device transcript is captured while you record and nothing has to leave the machine for it to exist.

We store the API key you supply, encrypted at rest, because the service needs it to make the call. We record what each run cost you in tokens so the app can show you your own spend. We do not use your keys for anything you did not assign them to.

06Agents and MCP

Plankast exposes an MCP server at /mcp so AI agents you choose — Claude, Claude Code, or any MCP host — can work with your vault. Access is granted by you, through OAuth 2.1 or a scoped token you create, and on the consent screen you pick which areas of life the agent may see. An agent only ever sees what you granted it.

An agent you authorise acts with your permission and on your behalf. Once information leaves Plankast for an agent or the model behind it, what happens to it is governed by that host and that provider, not by us. You can revoke an agent's access at any time in Settings, and revocation takes effect immediately.

07Calendars and contacts

Connecting Google Calendar or Microsoft 365 is entirely optional and is done through that provider's own OAuth consent screen, which tells you exactly what you are granting. Your events stay in your provider; Plankast caches them so the app works offline, writes your changes back, and lets you time-block tasks onto them.

Contacts are a separate permission, asked for separately, and are strictly read-only. Plankast merges the contacts on the accounts you have connected with everyone you share a calendar with, so that one person is one page however many lists they appear in. It does not read the address book on your phone, and it never writes to your contacts anywhere.

Disconnecting an account in Settings deletes the stored tokens and the cached data that came with it.

Plankast's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

08Who else sees it

We do not sell or rent your information. We share it only with the service providers we need to run Plankast, each under a contract that limits them to processing it on our instructions:

WhoWhat for
RenderApplication hosting and the managed PostgreSQL database that holds your account and vault.
S3-compatible object storageRecordings, ink pages, images and attached files.
Google, MicrosoftOnly where you connected that account, and only for the calendar and contact data you granted.
Your AI providersOnly where you connected a key and assigned it a purpose — see section 5.

We will also disclose information where we are legally required to, and where it is necessary to protect the rights or safety of a person. If Plankast is ever acquired or merged, your information may transfer with it; you will be told before that happens, and this policy will continue to apply to information collected under it until you are given notice of a new one.

09How long we keep it

We keep your account and your vault for as long as your account exists. Beyond that, deletion is not aspirational — a job runs nightly and applies these horizons:

  • Deleted items are recoverable for 90 days, and are then destroyed for good, along with the recordings, ink, boards and attachments belonging to them.
  • Document history keeps the most recent 50 versions of a document, plus everything within the last 90 days.
  • Sign-in sessions are pruned after 90 days without use, and stop working at that point whether or not the sweep has run.
  • AI run records — what a model call cost you — are kept for 90 days.

When you delete your account, your content and connected-account tokens are deleted with it. We may keep a minimal record that an account with that email address existed and was deleted, and anything we are required by law to retain.

10Your rights and choices

Export is not a request you have to make. Every note, task and project is already a plain Markdown file with YAML frontmatter. Download the whole vault as a zip from Settings whenever you like, or point it at a git repository and it will mirror there daily. There is nothing to extract, because nothing was locked in.

Whatever your country, you can ask us to give you a copy of your information, correct it, or delete it. To delete your account, email contact@plankast.com from the address on the account; we will confirm and action it within 30 days. In Settings you can also, at any time and without asking us: disconnect a calendar or contacts account, remove an AI provider key, revoke an agent's access, revoke a session or a passkey, and delete any item in your vault.

If you are in the UK, the EU or Switzerland, you have the rights to access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your local supervisory authority. If you are in California, you have the rights to know, delete, correct and opt out under the CCPA as amended by the CPRA — we do not sell or share personal information as those terms are defined, so there is no opt-out to exercise, and we will never discriminate against you for exercising any right. Other US state privacy laws give comparable rights, and we extend the same handling to everyone rather than sorting people by postcode.

11Security

All traffic between your devices and Plankast is encrypted in transit with TLS. Passwords are stored only as a one-way hash. Provider API keys and connected-account tokens are encrypted at rest. Sessions belong to people and scoped tokens belong to agents — never the same credential — so revoking one does not disturb the other, and an agent's token carries only the scopes you granted it. Passkeys are supported and are the strongest option available to you.

No service can promise perfect security, and we will not pretend otherwise. If a breach affects your personal information we will notify you and the relevant regulators as the law requires and as quickly as we reasonably can.

12Where it is stored

Plankast's servers and database are hosted in the United States. If you use Plankast from outside the United States, your information is transferred to and processed there, in a country whose data protection laws may differ from your own. Where we transfer personal information out of the UK, the EEA or Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum.

13Children

Plankast is not intended for children. You must be at least 16 years old to hold an account. We do not knowingly collect personal information from anyone under 16; if we learn that we have, we will delete the account and its contents.

14Changes

We will update this policy as Plankast changes. The version and date at the top of this page always say which text is in force. For any change that materially affects your rights or how we handle your information, we will give you notice in the app or by email before it takes effect, and where the law requires consent we will ask for it rather than assume it.

15Contact

Questions, requests, or anything in this policy that does not match what you see in the product — write to contact@plankast.com and a person will answer. Postal address available on request.

See also: Terms of Service.

Plankast
CaptureYour dataMCPFAQPrivacyTermsSign in
plankast.com · private beta

Plankast is operated by Bryan Saxon LLC. Google, Google Calendar, Microsoft 365, Anthropic, OpenAI, xAI, Obsidian and Todoist are trademarks of their respective owners. Plankast is not affiliated with or endorsed by any of them.