Plan AI — Privacy Policy
Effective date: `TO BE SUPPLIED: effective date **Last updated:** TO BE SUPPLIED: effective date
DRAFT — not yet published. Read COMPLIANCE-GAPS.md in this folder first. Several rights described below (deletion, export) do not yet have a working implementation, and the app has no age gate or verifiable parental consent. This document must be reviewed by a lawyer qualified in KVKK and children's privacy before it goes live.1. Who we are
Plan AI is a planning and scheduling app for children, used with their parents, guardians, and teachers.
| Data controller (KVKK: *veri sorumlusu*) | TO BE SUPPLIED: registered legal entity name |
| Registered address | TO BE SUPPLIED: registered company address in Türkiye |
| Registry number | TO BE SUPPLIED: Türkiye tax/registry number (vergi kimlik no / MERSİS) |
| VERBİS registration | TO BE SUPPLIED: KVKK VERBİS registration number, or a documented exemption |
| Privacy contact | TO BE SUPPLIED: privacy contact email address |
| EU representative (GDPR Art. 27) | TO BE SUPPLIED: EU representative under GDPR Art. 27 |
| Data Protection Officer | TO BE SUPPLIED: DPO name and contact, or a documented assessment that none is required |
We are established in Türkiye. We process personal data under the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where it applies to users in the European Economic Area and the United Kingdom, the GDPR / UK GDPR.
2. Plan AI is designed for children — please read section 9
The app is intended for children aged roughly 8 to 13, with a parent, guardian, or teacher as the responsible adult. Section 9 explains what that means in practice and what rights the responsible adult has. If you are a parent or teacher, please read section 9 as well as this section.
3. What we collect, and what we do not
We have written this section from the app's actual behaviour. If something is not listed here, we do not collect it.
3.1 Account information
Collected when an account is created, and only then:
| Data | Source | Why |
|---|---|---|
| Email address | You (or Google Sign-In) | To identify the account and let you sign in |
| Display name | You (optional) | To personalise the app |
| Profile photo URL | Google Sign-In (optional) | To show an avatar |
| Account identifier (UID) | Generated by Firebase | To link your data to your account |
| Account creation and update timestamps | Generated | Housekeeping |
Passwords are handled by Google Firebase Authentication. We never see, store, or have access to your password.
3.2 Content you create
Stored so it is available across your devices:
- Tasks — titles, notes, dates, times, categories, completion state, stickers.
- Routines — recurring activities and their schedules.
- Goals — the goal text you enter.
- A planning-style profile — the result of the in-app questionnaire
(a working-style summary, preferred deep-work and admin times, and similar planning preferences). This is a scheduling aid. It is not a psychological, medical, educational, or diagnostic assessment, and we do not treat it as one.
- Theme preference — your chosen colours and light/dark mode.
3.3 Photos you choose to upload
If you use the "plan from a photo" feature, the image you pick — for example a photo of a handwritten timetable — is sent to our server, which passes it to Google's Gemini AI service to read the schedule out of it.
- The photo is chosen by you from your device's file picker. **The app never opens
your camera and never browses your photo library on its own.**
- We do not store the uploaded photo in our database. It is processed to produce
the tasks and is not retained by us as an image.
- Only the tasks extracted from it are saved.
Please do not upload photos containing information you do not want processed — faces of other children, addresses, or medical or school records. The photo is sent to a third-party AI service (section 6).
3.4 Subscription information
If you buy a subscription, our payment provider handles the payment and tells us only which plan is active. Your subscription tier is stored on your account and also cached on your device.
We never receive, see, or store your card number, CVV, or bank details. Those go directly from you to the payment provider (section 6).
3.5 Stored on your device only
Some data never leaves your device. It is kept in your browser's or the app's local storage and is not uploaded to us:
- The whole reward system — points earned, the prize list a parent defines,
and which wheels have been spun. Including the parent PIN (see the warning in section 9.4).
- Weekly plan templates you save.
- Your chosen language.
- A queue of changes waiting to sync when you are offline.
3.6 What we do NOT collect
To be explicit, because apps in this category often do collect these:
- No analytics or usage tracking. There is no analytics SDK active in the app.
We do not track which screens you visit or which buttons you press.
- No advertising. No ad networks, no advertising identifiers, no profiling for
ads. We do not sell or share personal data for advertising.
- No location data. We never request or receive your location.
- No camera or microphone access.
- No contacts, calendar, SMS, or call-log access.
- No biometric data.
- No behavioural profiling to make automated decisions about you.
4. Why we process your data, and our legal basis
| What we do | Legal basis (GDPR) | Legal basis (KVKK) |
|---|---|---|
| Create and run your account | Performance of a contract (Art. 6(1)(b)) | Necessary for performance of a contract (Art. 5(2)(c)) |
| Store and sync your tasks, routines, goals | Performance of a contract (Art. 6(1)(b)) | Necessary for performance of a contract (Art. 5(2)(c)) |
| Process a photo you upload into tasks | Performance of a contract, at your request (Art. 6(1)(b)) | Necessary for performance of a contract (Art. 5(2)(c)) |
| Take payment for a subscription | Performance of a contract (Art. 6(1)(b)) | Necessary for performance of a contract (Art. 5(2)(c)) |
| Keep the service secure and diagnose faults | Legitimate interests (Art. 6(1)(f)) | Legitimate interests (Art. 5(2)(f)) |
| Meet legal and tax obligations | Legal obligation (Art. 6(1)(c)) | Legal obligation (Art. 5(2)(a)) |
Where the user is a child below the applicable age of digital consent, we rely on the consent of the holder of parental responsibility (GDPR Art. 8) in addition to the bases above. See section 9 and PARENTAL_CONSENT.md.
5. Automated decision-making
The AI features suggest and organise plans. They do not make any decision that has a legal effect on you or that significantly affects you within the meaning of GDPR Art. 22. Every suggestion is a suggestion: you can edit, ignore, or delete it. Nothing is scored, ranked, or reported to anyone.
6. Who we share data with
We use the following service providers ("processors"). We do not sell your data, and we do not share it with anyone for advertising.
| Provider | What they do | What they receive |
|---|---|---|
| Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Hosting) | Accounts, database, backend, hosting | Account information and the content you create |
| Google (Gemini AI, called from our server) | Turns your text or uploaded photo into a plan | The text or image you submit for that request |
| Stripe | International card payments | Your payment details, directly — not via us |
| iyzico | Payments in Türkiye | Your payment details, directly — not via us |
| Sentry | Technical error reports, only if enabled | Error and diagnostic details. Not currently enabled — see COMPLIANCE-GAPS.md §8 |
We may also disclose data where we are legally required to, or to protect the rights and safety of our users.
TO BE SUPPLIED: confirmation in writing from Google that prompts submitted via the paid Gemini API are not used to train models — this claim concerns children's data and must be verified against the contract in force, not assumed. See COMPLIANCE-GAPS.md §7.
7. International transfers
We are in Türkiye; the providers above process data outside Türkiye, including in the United States and the European Union.
TO BE SUPPLIED: the transfer mechanism actually in place — signed Standard Contractual Clauses for GDPR Art. 46, and the lawful KVKK cross-border basis under the amended Art. 9. See COMPLIANCE-GAPS.md §7. Do not publish this section until these exist.
8. How long we keep data
See DATA_RETENTION.md for the full schedule.
Honest note for the reviewer, to be removed before publication: the retention periods in that document are a policy to be implemented. No automatic deletion is in place today (COMPLIANCE-GAPS.md §6).
9. Children's privacy
This is summarised here and set out in full in CHILDRENS_PRIVACY.md. Consent is covered in PARENTAL_CONSENT.md.
9.1 Our approach
We collect the minimum needed to run a planner: an account so the child's work is not lost, and the plans they create. No advertising, no tracking, no profiling, no selling of data — ever, and specifically never for a child.
9.2 The responsible adult is in control
A parent, guardian, or school representative may at any time review the child's data, correct it, ask for it to be deleted, withdraw consent, or ask us to stop processing. Contact `TO BE SUPPLIED: privacy contact email address`.
9.3 Age and consent
When Plan AI is first opened we ask for a year of birth on a neutral screen. We keep only the resulting age band, not the date itself.
If the user is below the age of digital consent, the account is held by a parent or guardian, and the child's profile is not usable until that adult has completed our consent process. Consent is asked for in three separate parts, each of which can be refused on its own:
- The planner itself — the account and the plans your child creates. Required
for the app to work at all.
- AI planning from text — optional. The planner works fully without it.
- AI planning from a photo — optional, and separate from (2), because
sending an image carries more risk than sending a line of text.
You can withdraw any of these at any time, from the same place you granted them, and withdrawing one leaves the rest working. We record which items were agreed to, when, by which verified adult, and against which version of this policy.
TO BE SUPPLIED: the verification method. The consent flow is implemented, but which COPPA-recognised method of *verifying* the adult is lawful for this app has not been settled — "email plus" is restricted to internally-used data and this app discloses child content to Google's Gemini service. Counsel must choose; the implementation is built behind a swappable interface so that choice is a small change. Until it is made, this policy must not be published and COPPA compliance must not be claimed. See COMPLIANCE-GAPS.md §2.
9.4 About the parent PIN — please read
The app has a 4-digit PIN that protects the reward settings so a child cannot casually change their own prizes.
This PIN is a convenience feature, not a security control, and not consent. It is stored unencrypted on the device and can be recovered by anyone with technical access to it. Do not reuse a PIN or password you use anywhere else, and do not treat it as proof that an adult approved something.
10. Your rights
Under KVKK Art. 11 and GDPR Art. 15–22 you may ask us to:
- confirm whether we process your data, and get a copy of it;
- correct it if it is wrong or incomplete;
- delete it;
- restrict or object to how we process it;
- provide it in a portable format;
- withdraw consent, where we relied on consent;
- not be subject to solely automated decisions with legal effect (we make none).
Contact `TO BE SUPPLIED: privacy contact email address`. We respond within 30 days (KVKK) and one month (GDPR). There is no charge unless a request is excessive.
You may complain to the Turkish Personal Data Protection Authority (KVKK Kurumu, kvkk.gov.tr) or to your local EU/UK supervisory authority.
Reviewer note, to be removed before publication: deletion and export have no in-app implementation yet, so today these requests can only be served manually. See COMPLIANCE-GAPS.md §4 and §5.
11. Security
- All traffic uses HTTPS/TLS.
- Data at rest in Google Cloud is encrypted by Google.
- Database access rules are default-deny: a request is refused unless a rule
explicitly permits it, and users can only read and write their own records.
- Entitlement fields (such as subscription tier) cannot be altered by the client;
only our server can change them.
- Passwords are held and verified by Firebase Authentication, never by us.
No system is perfectly secure. If you believe your account is compromised, contact us at `TO BE SUPPLIED: privacy contact email address`.
12. Changes to this policy
If we make a material change we will update the date above and give notice in the app before it takes effect. Where the change concerns children's data and the law requires it, we will seek fresh parental consent rather than relying on notice.
13. Contact
TO BE SUPPLIED: registered legal entity name TO BE SUPPLIED: registered company address in Türkiye TO BE SUPPLIED: privacy contact email address