Who we are
M1Planner is a planner for tasks, projects, goals, habits, notes, meetings, reminders, contacts, money, sleep and reading. It works as a website, as a web app you can install, and as an Android app, all using the same account and the same servers.
In this policy, “M1Planner”, “we” and “us” mean the team that runs the service, and “you” means the person using it. We are responsible for the personal data described here. You can reach us at the address at the end of this page.
This policy covers the website, the web app and the Android app. It does not cover other websites you open from inside M1Planner, such as a meeting link or a website saved in a task.
What we collect
We collect only what the service needs to work. Most of it you give us; some of it is created as you use the app.
- Your account
- Your email address, which is how you sign in. Your password, stored only as a one-way hash that nobody can read, not even us. If you use “Continue with Google”: the identifier of your Google account, the email address Google confirms, and your name if your profile does not have one yet (we do not receive your Google photo). The IP address and browser or device you signed up from, and those of your latest sign-in.
- Your profile and settings
- Whatever you choose to fill in: name, display name, photo, birth date, gender, job title, company and a short bio. Your settings: language, calendar, time zone, first day of the week, currency, notification preferences and screen layout.
- What you put in the planner
- Tasks, projects, goals, habits and their check-ins, notes and folders, files you attach, meetings, reminders and important dates, contacts in your address book, wallets, transactions and bills, books and sleep entries. Your address book can contain other people’s names, phone numbers, email addresses and birthdays; it is kept for you and is not used to contact them.
- Your devices and sessions
- Each time you sign in, we keep a session for that device: a random device identifier, a device name (in a browser, its user-agent text; in the Android app, the phone’s make and model), the platform, the app version, the IP address and when it was last used. You can see them in Settings › Devices and sign any of them out.
- Notification channels
- If you allow notifications: the push address your browser gives us, or in the Android app a Firebase Cloud Messaging token. If you connect Telegram: the id of the chat you connected and its name (your username or name, or the group’s title).
- Payments
- For each order: the plan or add-on, the price, any discount code, the dates, the IP address the order was placed from, the wallet address you were asked to pay to, and the blockchain transaction that paid it, with the sending wallet address, the amount and the time.
- Messages to support
- If you write to us by email, WhatsApp or Telegram, we receive what you send and the address or number you send it from.
We do not collect your location, the contacts stored on your phone, or your camera or microphone, and we never see a payment card, because we do not take cards.
Regional hints: on your first visit, the website looks up the country of your IP address in a database stored on our own server (no outside service is asked) to show the site in your language. When you create an account, that country, your device’s time zone and your browser’s languages are used once to choose your starting calendar, week start and currency. We keep the choices, not the hints, and you can change every one of them.
How we use it
We use your data to run M1Planner for you, and for nothing else:
- to create your account, sign you in, keep it secure and keep your devices in step;
- to show your planner to you, and to the people you choose to share with;
- to send the reminders, summaries and notifications you set up, on the channels you chose: in the app, push, email or Telegram;
- to send the emails the service itself needs: sign-in and confirmation codes, security notices such as a changed email address, team invitations you send, and messages about your subscription;
- to take payments and keep records of them;
- to answer you when you contact support;
- to protect the service and the people who use it: limiting repeated attempts, spotting abuse and investigating problems.
We do not use your data to advertise to you, we do not build marketing profiles, we do not send marketing email, and we do not sell or rent personal data to anyone. We do not use your content to train artificial intelligence.
Where the law asks for a legal basis (for example the GDPR in the EU and the UK): we process your account and content to provide the service you signed up for (contract); security, abuse prevention and the records needed to run the service rest on our legitimate interest in keeping it safe; payment records are kept because accounting rules require them (legal obligation); and optional channels such as push notifications and Telegram are used because you turned them on (consent), which you can withdraw at any time in Settings.
Payments on a public blockchain
M1Planner is paid for in USDT on BNB Smart Chain (BEP-20). We never see or store a payment card or a bank account.
A blockchain is public by design. The transaction you send, including the sending wallet address, our receiving address, the amount and the time, can be seen by anyone, permanently, and cannot be changed or deleted by us or by anyone else. We record every transfer that reaches our payment wallets so that we can match it to an order, sort out mistakes and keep our accounts.
If you would rather not connect a wallet you use elsewhere to your account, pay from a wallet you keep for this purpose.
How long we keep it
We keep your data for as long as you have an account. Nothing is deleted because a trial or subscription ended.
- Deleting a single item removes it from every screen, list and export at once, and a deleted file is erased from storage straight away. Other deleted items are kept, hidden, in our database until you delete your account, and are shown to nobody, you included.
- Deleting your account takes effect immediately, with no waiting period: your profile, content, files, sessions, notification channels and your place in other people’s teams and projects are removed.
- After an account is deleted we keep only what accounting and fair use require: a record of each completed payment (the plan, the amount, the date and the blockchain transaction it came from), and a one-way fingerprint of your email address that shows the free trial was used, so it is not given twice.
- Your name can remain where it is part of other people’s data: in their own address books, in a notification in their inbox (inbox items expire after 90 days), or as the person who changed something in a project they own.
- Notifications are kept for 90 days, and sign-in and confirmation codes for 24 hours. The record of a device that has signed out or expired is deleted automatically, within four months at most.
- If you start creating an account and do not finish, the email address you entered and the IP address and browser you used are deleted automatically 30 days later.
- Our servers keep technical logs, which can include IP addresses, to run and protect the service. They are rotated automatically and are not used for anything else.
- Backups of the database and of uploaded files are kept for 14 days and then deleted, so something you deleted can remain in a backup for up to 14 days. Backups are used only to recover from a failure.
Before you delete your account you can download your data: Settings › Export & import exports every section as a spreadsheet, a JSON file or a zip of CSV files. Attached files are not inside the export; download the ones you want to keep from where they are attached.
How we protect it
- Everything between your device and our servers travels encrypted over HTTPS.
- Passwords are stored only as a one-way BCrypt hash. Access tokens are signed, encrypted and expire within an hour; refresh tokens are stored only as hashes.
- Signing up, resetting a password and deleting the account need a code sent by email, and repeated wrong attempts are limited. Changing your sign-in email address or setting a first password also needs your current password or a code sent to your current address.
- Each device has its own session. You can sign any of them out, and changing your password signs out all your other devices.
- Your content is only ever shown to you and to the people you share it with. Pictures you use as a profile photo, a contact photo or a cover are served from unguessable links that do not need a sign-in, so they can be shown in shared places; all other files need a sign-in.
- In the Android app, your sign-in is kept in the phone’s secure storage, the app can be locked with a PIN or your fingerprint, and its data is excluded from device backups.
No system is perfectly secure. If we learn of a breach that affects your data, we will tell you, and the authorities where the law requires it, without undue delay.
Your rights and choices
You are in control of your data, and most of it you can manage yourself:
- See it and take it with you
- Everything you put in is in the app. Settings › Export & import exports every section at once, and most screens download as a spreadsheet too. This works even when you have no active plan.
- Correct it
- Change your profile and settings in Settings, including your sign-in email address.
- Delete it
- Delete any item at any time, or the whole account from Settings › Security. The page “How to delete your account” explains exactly what happens.
- Stop notifications
- Turn any channel off in Settings › Notifications, disconnect Telegram, or withdraw notification permission in your browser or phone.
Depending on where you live (for example in the EU, the UK or California), you may also have the right to know what data we hold about you, to have it corrected or erased, to restrict or object to some processing, and to receive it in a portable format. To use any of these rights, write to us from your account’s email address; we will answer within one month. We may ask you to confirm the request from that address, so that nobody else can make it in your name.
If you think we have handled your data wrongly, please tell us first so we can put it right. You also have the right to complain to the data protection authority where you live.
Where your data is processed
Your account, your content and your files are stored on our servers at our hosting provider. When one of the companies listed above is involved (Google, your browser’s push service or Telegram), the data it handles may be processed in other countries under that company’s own safeguards. Where the law requires it, we rely on appropriate safeguards for such transfers.
Children
M1Planner is not intended for children. You must be at least 13 years old to use it, or at least 16 in the European Economic Area and the United Kingdom, or older if the law where you live sets a higher age. We do not knowingly collect personal data from children below these ages; if you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
When we change this policy, we update the date at the top of this page. If a change matters, for example a new kind of data or a new company that receives it, we will tell you by email or in the app before it takes effect.
Contact
For questions about this policy or your data, or to use any of your rights, write to us at the address below. If the request is about your account, please write from your account’s email address.