Privacy Policy
Last updated: 16 August 2026
Plannorium ID is the account system used to sign in to Plannorium products. This policy explains exactly what we store, why we store it, how long we keep it, and the rights you can exercise over it.
Document sections
1. Data we collect
We collect only what an identity provider needs to operate. Everything below corresponds to a field this service actually stores.
- Account identity — your full name, email address, and whether that email is verified. Optionally a username, short bio, profile links, and a profile image.
- Authentication credentials — your password stored only as a bcrypt hash (never in plain text), and, if you enable them, two-factor settings and passkey (WebAuthn) credentials. We never store the private key of a passkey.
- Recovery details — an optional recovery email address.
- Session records — a session token, its creation and expiry time, and the account it belongs to.
- Security events — sign-in and security activity including the IP address and timestamp of the event, shown to you in your security settings.
- Connected application data — for each application you approve, the client it was granted to and the scopes you consented to.
2. What we do not collect
Stating the boundary plainly is part of the policy.
- We do not collect payment card details. Plannorium ID does not process payments.
- We do not read the content held inside connected products; an application receives only the scopes you approve.
- We do not sell personal data, and we do not share it with advertisers.
- We do not use your data to build advertising profiles.
3. Why we use it, and our legal basis
Under the GDPR we must name a lawful basis for each purpose. Ours are:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and operating your account | Account identity, credentials | Performance of a contract |
| Signing you in to connected applications | Session records, consent records | Performance of a contract |
| Verifying your email and recovering access | Email, recovery email | Performance of a contract |
| Protecting accounts from abuse and fraud | Security events, IP address | Legitimate interests |
| Two-factor and passkey protection | 2FA settings, WebAuthn credentials | Consent |
| Meeting legal and regulatory obligations | Account and security records | Legal obligation |
4. How long we keep it
We do not keep personal data indefinitely by default.
- Account data is kept while your account is open, and deleted within 30 days of you deleting the account.
- Session records expire automatically and are removed once expired.
- Authorization codes and SDK sign-in sessions are single-use and expire within minutes.
- Security event history is retained for up to 12 months so you can review suspicious activity.
- We may retain limited records for longer where the law requires it, and only for that purpose.
5. Your rights
If you are in the UK, EU, or EEA, the GDPR gives you the rights below. We extend the same controls to every user regardless of location. Nigerian users hold equivalent rights under the NDPA.
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct data that is inaccurate or incomplete.
- Erasure — delete your account and associated personal data.
- Portability — export your data in a structured, machine-readable format.
- Restriction — ask us to limit how we process your data.
- Objection — object to processing carried out on the basis of legitimate interests.
- Withdraw consent — revoke an application's access, or disable two-factor and passkeys, at any time.
- Complain — lodge a complaint with your data protection authority.
6. Exercising your rights
Most controls are self-service and take effect immediately: you can export your data, review connected applications, revoke access, and delete your account from your privacy settings. For anything not available there, contact us using the details below. We respond within 30 days.
7. Subprocessors
A current list of the processors we use, together with their purpose and processing region, is available on request — email support@plannorium.com. Every processor is bound by a data processing agreement and may only act on our instructions.
8. International transfers
Some processors above operate outside your country. Where personal data leaves the UK, EU, or EEA, transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard. You may request a copy of the safeguard applying to a specific transfer.
10. How we protect it
Passwords are hashed with bcrypt and never stored or logged in plain text. Sign-in supports two-factor authentication and passkeys. Sessions use HttpOnly, Secure, SameSite cookies. Applications must use exact-match redirect URIs and PKCE, and credentials issued to applications are short-lived and single-use. Access is transmitted over TLS.
11. Children
Plannorium ID is not directed at children under 16, and we do not knowingly create accounts for them. If you believe a child has an account, contact us and we will remove it.
12. Changes to this policy
If we make a material change, we will update the date at the top of this page and notify signed-in users before the change takes effect. Continued use after that date means the updated policy applies.
13. Contact
For privacy questions or to exercise a right that is not self-service, contact support@plannorium.com. If we cannot resolve your concern, you may complain to your local data protection authority.