Privacy Policy

Last updated: April 30, 2026

1. Who We Are

Plenflow ("we", "our", "us") is a personal productivity application available at plenflow.com. We are the data controller for information collected through the service.

2. Information We Collect

  • Account data — your name, email address, and hashed password when you register.
  • Usage data — planners, tasks, habits, goals, notes, focus sessions, and other content you create inside the app.
  • Preference data — theme, timezone, notification settings, and onboarding choices.
  • Technical data — IP address, browser type, and session tokens for security and authentication.
  • Payment data — subscription status and transaction identifiers. Full payment details (card numbers) are processed exclusively by our payment provider (Gumroad) and are never stored on our servers.

3. How We Use Your Data

  • Provide, maintain, and improve the Plenflow service.
  • Authenticate your account and keep it secure.
  • Send transactional emails (email reminders, support replies, billing receipts) that you have opted into.
  • Respond to support requests.
  • Comply with legal obligations.

4. Legal Basis (GDPR)

For users in the European Economic Area, we process your data under the following legal bases: contract performance (providing the service you signed up for), legitimate interest (security, fraud prevention, service improvements), and consent (optional email reminders).

5. Data Sharing

We do not sell, rent, or trade your personal data. We share data only with the following sub-processors necessary to operate the service:

  • Gumroad — payment processing for Pro subscriptions.
  • Hosting provider — server infrastructure where the application and database run.
  • Email delivery service — transactional email dispatch.

All sub-processors are contractually required to protect your data and use it only for the purposes we specify.

6. Data Retention

We keep your account data for as long as your account is active. If you delete your account, your personal data and all associated content are permanently deleted within 30 days, unless we are required to retain it by law.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your account and data.
  • Export your data in a portable format.
  • Withdraw consent for optional processing (e.g., email reminders) at any time in your profile settings.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us at support@plenflow.com.

8. Cookies

We use a single session cookie to keep you logged in. We do not use advertising cookies or third-party tracking cookies. If that changes, we will update this policy and ask for your consent.

9. Security

We use industry-standard practices to protect your data: encrypted connections (HTTPS/TLS), hashed passwords (bcrypt), and restricted database access. No method of transmission over the internet is 100% secure, but we take reasonable measures to protect your information.

10. Children

Plenflow is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or by a notice in the app at least 14 days before the change takes effect.

12. Contact

Questions about this policy? Email us at support@plenflow.com.

Also see our Terms of Service. Questions? support@plenflow.com