Plannorium IDGDPR / NDPA

Privacy Policy

Last updated: 16 August 2026

Plannorium ID is the account system used to sign in to Plannorium products. This policy explains exactly what we store, why we store it, how long we keep it, and the rights you can exercise over it.

1. Data we collect

We collect only what an identity provider needs to operate. Everything below corresponds to a field this service actually stores.

  • Account identity — your full name, email address, and whether that email is verified. Optionally a username, short bio, profile links, and a profile image.
  • Authentication credentials — your password stored only as a bcrypt hash (never in plain text), and, if you enable them, two-factor settings and passkey (WebAuthn) credentials. We never store the private key of a passkey.
  • Recovery details — an optional recovery email address.
  • Session records — a session token, its creation and expiry time, and the account it belongs to.
  • Security events — sign-in and security activity including the IP address and timestamp of the event, shown to you in your security settings.
  • Connected application data — for each application you approve, the client it was granted to and the scopes you consented to.

2. What we do not collect

Stating the boundary plainly is part of the policy.

  • We do not collect payment card details. Plannorium ID does not process payments.
  • We do not read the content held inside connected products; an application receives only the scopes you approve.
  • We do not sell personal data, and we do not share it with advertisers.
  • We do not use your data to build advertising profiles.

4. How long we keep it

We do not keep personal data indefinitely by default.

  • Account data is kept while your account is open, and deleted within 30 days of you deleting the account.
  • Session records expire automatically and are removed once expired.
  • Authorization codes and SDK sign-in sessions are single-use and expire within minutes.
  • Security event history is retained for up to 12 months so you can review suspicious activity.
  • We may retain limited records for longer where the law requires it, and only for that purpose.

5. Your rights

If you are in the UK, EU, or EEA, the GDPR gives you the rights below. We extend the same controls to every user regardless of location. Nigerian users hold equivalent rights under the NDPA.

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct data that is inaccurate or incomplete.
  • Erasure — delete your account and associated personal data.
  • Portability — export your data in a structured, machine-readable format.
  • Restriction — ask us to limit how we process your data.
  • Objection — object to processing carried out on the basis of legitimate interests.
  • Withdraw consent — revoke an application's access, or disable two-factor and passkeys, at any time.
  • Complain — lodge a complaint with your data protection authority.

6. Exercising your rights

Most controls are self-service and take effect immediately: you can export your data, review connected applications, revoke access, and delete your account from your privacy settings. For anything not available there, contact us using the details below. We respond within 30 days.

7. Subprocessors

A current list of the processors we use, together with their purpose and processing region, is available on request — email support@plannorium.com. Every processor is bound by a data processing agreement and may only act on our instructions.

8. International transfers

Some processors above operate outside your country. Where personal data leaves the UK, EU, or EEA, transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard. You may request a copy of the safeguard applying to a specific transfer.

9. Cookies

We use only the cookies needed to sign you in and keep you signed in securely.

  • Session cookie — keeps you signed in. HttpOnly, Secure, and SameSite-protected.
  • CSRF token — protects sign-in and consent forms from cross-site request forgery.
  • Callback URL cookie — returns you to the right place after signing in.
  • We do not set advertising or cross-site tracking cookies.

10. How we protect it

Passwords are hashed with bcrypt and never stored or logged in plain text. Sign-in supports two-factor authentication and passkeys. Sessions use HttpOnly, Secure, SameSite cookies. Applications must use exact-match redirect URIs and PKCE, and credentials issued to applications are short-lived and single-use. Access is transmitted over TLS.

11. Children

Plannorium ID is not directed at children under 16, and we do not knowingly create accounts for them. If you believe a child has an account, contact us and we will remove it.

12. Changes to this policy

If we make a material change, we will update the date at the top of this page and notify signed-in users before the change takes effect. Continued use after that date means the updated policy applies.

13. Contact

For privacy questions or to exercise a right that is not self-service, contact support@plannorium.com. If we cannot resolve your concern, you may complain to your local data protection authority.