Privacy Policy
Last updated: March 8, 2026
Planzy (“we”, “our”, or “the app”) is a travel itinerary management application. This Privacy Policy explains how we collect, use, and protect your information.
1. Information We Collect
Account information: When you create an account, we collect your email address and a password (or passkey). A unique forwarding email address is generated for your account.
Travel emails: When you forward travel confirmation emails to your Planzy address, or when you connect your Gmail account, we receive and process those emails. We extract travel-related information such as flight details, hotel reservations, and activity bookings. Only travel-related emails are stored; all other emails are discarded and never stored.
Gmail access (optional): If you choose to connect your Gmail account, we request read-only access (gmail.readonly scope) to scan your inbox for travel-related emails. We only read emails that match travel-related patterns (booking confirmations from known travel providers, itineraries, etc.). Non-travel emails are never read, stored, or processed. You can disconnect Gmail access at any time from the app settings.
Device information: We collect your device’s push notification token to send you notifications about new travel events. We do not collect device identifiers, location data, or usage analytics.
2. How We Use Your Information
- Itinerary creation: Travel emails are parsed by AI to extract event details (dates, times, locations, confirmation numbers) and organize them into trips.
- Notifications: We send push notifications when new travel events are processed or if processing fails.
- Trip sharing: If you share a trip with another user, they can view (and optionally edit) the trip’s events.
- Sync: Your trip and event data is synced between your device and our cloud database so it’s available across sessions and after reinstallation.
3. Data Storage and Security
- Local-first architecture: Your travel data is stored locally on your device using SQLite. An encrypted copy is synced to a cloud database for cross-device access.
- Per-user databases: Each user’s travel data (trips, events, emails) is stored in a dedicated, isolated database. No other user can access your data unless you explicitly share a trip.
- Email attachments: PDF attachments from travel emails are stored in encrypted cloud storage (Cloudflare R2). Text is extracted from PDFs for itinerary parsing.
- Authentication: Passwords are hashed. Session tokens are used for API authentication. OAuth tokens for Gmail are stored encrypted in the central database.
- Encryption in transit: All communication between the app and our servers uses HTTPS/TLS.
4. AI Processing
We use AI to parse travel emails into structured event data. Email content is sent to the AI model for processing and is not stored by the AI provider beyond the duration of the request. The AI does not learn from or retain your personal data.
5. Google API Services — Limited Use Disclosure
Planzy’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Gmail data to provide the travel itinerary feature described in this policy.
- We do not transfer Gmail data to third parties, except as necessary to provide the service (infrastructure providers), for security purposes, or to comply with applicable law.
- We do not use Gmail data for advertising, market research, or email campaign purposes.
- No human reads your Gmail data unless you provide explicit consent, it is necessary for security purposes, or it is required by law.
6. Data Sharing
We do not sell, rent, or share your personal information with third parties, except:
- Infrastructure providers: We use Cloudflare (hosting, email processing, AI, storage) to operate the service. These providers process data on our behalf under their respective data processing agreements.
- Trip sharing: When you share a trip, the recipient can see the trip’s events (names, dates, locations, confirmation numbers). You control who has access and can revoke it at any time.
- Legal requirements: We may disclose information if required by law or to protect our rights.
7. Your Rights
- Access and export: All your data is visible in the app. You can view all trips, events, and processed emails.
- Deletion: You can delete individual trips and events. You can delete your entire account and all associated data with a single action from the app settings — this permanently removes your dedicated database, email attachments, Gmail OAuth tokens, and all records from the central database.
- Gmail disconnect: You can disconnect Gmail access at any time. We revoke the OAuth token and stop scanning your inbox.
- Data portability: Your data is stored locally in a standard SQLite format on your device.
- GDPR compliance: If you are in the EU/EEA, you have the right to access, rectify, delete, and port your personal data. To exercise these rights, contact us or use the in-app account deletion feature.
8. Data Retention
Your data is retained as long as your account is active. When you delete your account, all data is permanently removed: your per-user database is deleted, email attachments are removed from storage, and your records are purged from the central database.
9. Children’s Privacy
Planzy is not directed at children under 13. We do not knowingly collect information from children under 13.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes through the app or via email.
11. Contact
For privacy-related questions, contact us at privacy@planzy.com.