Legal
Privacy Policy
Effective and last updated: 7 September 2026
This policy explains how PlayablePlan handles personal data when you visit the website, join the newsletter or use the service.
1. Data controller
PlayablePlan is responsible for the personal data processing described in this policy. For privacy requests or questions, email [email protected].
2. Data we process
- Account data: name, email address, password hash, studio membership and role. If you choose social sign-in, we also store the provider and its stable account identifier.
- Workspace data: projects, tasks, milestones, comments, notifications, files, build or demo links and activity history supplied by users.
- Security data: session, CSRF, invitation, password-reset and MCP access-token records. Secret tokens are stored as cryptographic hashes where supported by the feature.
- Newsletter data: email address, consent time, the version of this notice shown at sign-up, and eligibility and redemption of the launch Studio offer.
- Billing data: Studio billing contact, Stripe customer and subscription identifiers, selected price, subscription status, billing period, confirmed payment and refund amounts and currencies, and payment-success or payment-failure status. Card and payment-method details are collected and stored by Stripe, not PlayablePlan.
- Technical and aggregate usage data: ordinary server and security logs generated when the service is requested, plus daily page-view totals by public page. The aggregate counter does not store an IP address, user agent or visitor identifier.
- Service activity: we record completed product actions and daily workspace access with timestamps and account, studio and project identifiers to provide support and understand activation, feature use and returning studios. These records contain action types and limited status information, not task text, comments or file contents.
- Optional website measurement: if you consent, PlayablePlan records public page paths, broad traffic-source categories, campaign labels and signup steps using a random browser identifier. A successful registration may be linked to this consented journey. We do not record sessions, form contents, full referring URLs or advertising profiles, and do not send these events to an external analytics provider.
3. Why we use data and legal bases
- To create and operate accounts, studios and collaborative workspaces, and to provide support: performance of the service agreement or steps requested before entering it.
- To secure the service, prevent abuse, keep backups, measure service adoption and returning usage, improve the product and establish or defend legal claims: our legitimate interests in operating a safe, useful and reliable service.
- To comply with tax, accounting, regulatory or lawful authority requests: compliance with legal obligations.
- To send launch news or other newsletter messages, and to collect optional website measurement: consent. You may withdraw it at any time without affecting earlier processing.
Data required to provide an account or a requested feature is necessary for that purpose. If it is not supplied, we cannot provide the relevant service.
4. Service providers and disclosures
We use suppliers where needed to run the service, including IONOS for infrastructure and hosting, Brevo for transactional email delivery, Google or GitHub when you choose their sign-in service, Stripe for payment collection, subscription management and billing support. Stripe receives payment and billing information under its own legal responsibilities; see the Stripe Privacy Policy. Data may also be disclosed to professional advisers, authorities or other parties where required by law or necessary to protect legal rights. Workspace data is visible to the members of the studio selected by the user according to their role.
5. International transfers
If a supplier processes personal data outside the European Economic Area, we use an applicable adequacy decision or appropriate safeguards under Chapter V GDPR. You may contact us for information about the safeguards relevant to your data.
6. Retention
Account and workspace data is kept while the account or studio is active and afterwards only as needed for deletion requests, legal obligations, disputes, security and limited backup cycles. Newsletter data is kept until consent is withdrawn. Optional website events and routine product-usage events are removed after 180 days by daily maintenance. Registration, verification, first activation and subscription milestones remain with the relevant service records; confirmed payment and refund records follow accounting retention requirements. The optional browser identifier expires after 90 days and is removed when consent is withdrawn. Source and campaign context lasts for the browser tab session. Authentication sessions expire after 12 hours, or after 30 days when Remember me is selected; password-reset links expire after one hour and are single-use. Some security and transaction records may be retained longer where necessary to protect the service or comply with law.
7. Your rights
Subject to the conditions in applicable law, you may request access, correction, deletion, restriction, portability or object to processing. Where processing is based on consent, you may withdraw it at any time. Send requests to [email protected]. You may also lodge a complaint with the data-protection supervisory authority responsible for your country.
8. Children
The service is not directed to children. Account holders must be at least 18 years old.
9. Changes
We may update this notice when the service or its data practices change. Material changes will be highlighted in the service or communicated by email where appropriate.
