1. Scope
This Privacy Policy applies to PlannerDate's website and account-based application at plannerdate.com. It describes the current application, including planning, Life & Money, connected-finance, payroll, account, support, and communication features.
2. Information PlannerDate collects
Account and profile information
We process information you provide to create and maintain an account, such as name, email address, password hash, contact email, phone number, profile text or photo, username, profile visibility choices, account status, and linked sign-in-provider identifiers. PlannerDate stores password hashes rather than plaintext account passwords.
Planning, Life & Money, and payroll information
We process the tasks, events, work records, income entries, manual account and finance records, budgets or goals, notes, payroll profile settings, time entries, estimated earnings and deductions, paycheck records, reminders, and reconciliation links that you choose to add or generate.
Authentication and communications
We process session records, sign-in and multi-factor-verification state, password-reset records, notification preferences, in-app messages, and support/contact messages. Email delivery providers process addresses and transactional messages such as verification codes and password-reset links on our behalf.
Connected financial information
If you connect an institution, PlannerDate may receive and store institution and connection identifiers; account identifiers, names, types and subtypes; masked account numbers; balances, available balances, currencies and connection status; and transaction identifiers, dates, descriptions, merchants, amounts, categories, status and payment channel. PlannerDate also stores a provider access token in protected form so it can request updates until the connection is disconnected.
AI conversations and usage
If an AI feature is enabled for you, PlannerDate processes the messages you submit, assistant responses, conversation ownership and timestamps, provider and model identifiers, token and request counts, tool names, latency, estimated cost, feedback, and safe error categories. Public chatbot sessions are separate from authenticated account histories. PlannerDate does not put bank credentials, Plaid access tokens, full account numbers, session secrets, encryption keys, or unrestricted database content into AI conversations.
3. Plaid's role and your bank credentials
When you choose Plaid, PlannerDate creates a Link token, opens Plaid Link, and receives a short-lived public token after you authorize the connection. PlannerDate's server exchanges that token with Plaid for an access token. PlannerDate then uses Plaid's APIs to retrieve authorized account and transaction information for display, synchronization, categorization, cash-flow views, and optional payroll reconciliation.
Plaid handles information under its own terms and privacy practices. Learn more in Plaid's End User Privacy Policy. Your financial institution may also apply its own privacy terms.
4. AI features and data minimization
PlannerDate's AI features may send your current message, a bounded recent conversation context, approved public product information, and narrowly scoped PlannerDate tool results to a configured AI service provider. For financial questions, PlannerDate prefers server-calculated aggregates and limited factual summaries instead of raw history. The provider does not receive direct database, Plaid, filesystem, shell, credential, or unrestricted network access through PlannerDate.
The public chatbot is limited to approved product, help, pricing, and high-level security information and cannot access private PlannerDate records. Authenticated conversations are account-scoped. You can start a new conversation and delete conversations available in your account. AI outputs may be incomplete or inaccurate and should be verified before important decisions.
5. How information is used
- Provide, personalize, and maintain your planner, Life & Money, payroll, connected-finance, AI, profile, social, inbox, and support features.
- Authenticate you, manage sessions, perform multi-factor verification, and help recover an account.
- Connect authorized financial institutions, synchronize accounts and transactions, preserve manual categories, calculate summaries, and reconcile eligible payroll records.
- Generate requested AI responses, enforce AI limits and budgets, prevent abuse, and measure safe operational usage without putting prompts or financial values into general analytics.
- Send transactional or service communications and respond to support, privacy, or account requests.
- Protect the service, troubleshoot errors, prevent abuse, administer accounts, and improve reliability and usability.
- Comply with applicable legal obligations and enforce PlannerDate's terms.
7. Data security
PlannerDate uses safeguards supported by the current implementation, including HTTPS delivery, authenticated and account-scoped application routes, hashed account passwords, protected session cookies, rate limits on sensitive actions, and application-level protection for selected stored banking fields and provider tokens. No internet service or storage method is completely secure, and we do not guarantee absolute security or claim a certification not stated here.
8. Data retention
PlannerDate generally retains account and application information while your account remains active and as needed to provide the service, maintain security, resolve support issues, or meet legal obligations. Session cookies are configured to expire after up to 14 days, although server records and other records may have different lifecycles. Stored AI conversations are subject to configured size and retention limits and may be deleted by their owner through the available conversation controls. Safe aggregate AI usage and cost records may be retained separately for security, budgeting, and operations. The current system does not promise one fixed retention period for every data category.
Disconnecting a financial institution stops future authorized access after the provider removal succeeds, but intentionally preserves previously imported account and transaction history, manual categories, and related payroll reconciliation records. Deletion from active systems is handled through a verified manual request. Existing backup copies, where applicable, may not be rewritten immediately and are addressed as part of the request review.
9. Disconnecting a financial institution
You can disconnect a linked institution from the connected-finance area. For a successful Plaid disconnection, PlannerDate asks Plaid to remove the Item, clears the stored PlannerDate access token, and marks the connection and its accounts disconnected. This prevents future synchronization through that connection. It does not automatically erase history already imported into PlannerDate.
To request deletion of imported financial history or other account data, follow the data-deletion instructions. You may also remove PlannerDate's access through your institution or Plaid; doing so may not delete information already stored in PlannerDate.
10. Your choices and data rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, or a copy of personal information, or to object to certain processing. PlannerDate currently handles these requests manually after verifying the requester. You can update some profile, privacy, notification, planning, finance, and connection settings in the application.
Submit a request through the PlannerDate contact form using the email associated with your account and clearly describe the request. Do not include a password, verification code, bank credential, or full account number. We may ask for additional information needed to verify identity and will explain any information that cannot be deleted or must be retained.
11. Children's privacy
PlannerDate is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided information to PlannerDate, contact us so the situation can be reviewed and appropriate action taken.
12. Changes to this policy
PlannerDate may update this policy as the service or its practices change. The effective date at the top identifies the current version. Material changes may also be communicated through the website, application, or account communications when appropriate.
13. Contact PlannerDate
For privacy questions or requests, use the public contact form. If you have an account, use its registered email so PlannerDate can begin identity verification. PlannerDate does not publish or invent a physical company address in this policy.