1. Who we are, and the two kinds of people in our data
PlanFlow Planner is operated by PlanFlow Planner, LLC ("we," "us"). This policy covers two very different groups, and being clear about the difference is most of being honest:
- Customers — planners, families, committees, and event businesses who create accounts and enter data. For your account data, we decide how and why it is processed (we are the "controller").
- Guests and other people our customers enter — wedding guests, classmates, donors, padrinos, vendors, clients. The customer who entered you collected your information and controls it; we process it on their behalf and on their instructions (we act as a "processor"). Section 7 is written for you.
2. What we collect
You give us
- Account data: name, email, password (stored only as a salted hash), plan and billing status.
- Event content: everything you put into your plans — guest lists (names, emails, phone numbers, addresses, dietary needs, RSVP status), budgets, vendor records, seating charts, timelines, notes, photos and documents you upload.
- Payment data: processed entirely by Stripe. We receive confirmation of payment, the plan purchased, and card metadata (last four digits, brand) — never your full card number.
- Messages to us: support emails and feedback.
Collected automatically
- Service logs: IP address, browser type, pages and actions, timestamps — the standard operational record every web service keeps, used for security, debugging, and abuse prevention.
- Delivery metadata: whether an invitation email or SMS was delivered, bounced, or failed (from Resend and Twilio), so your dashboard can tell you.
We do NOT collect
- No advertising identifiers, no cross-site tracking pixels, no data purchased from brokers, no social-media scraping of your guests. If the classmate tracker says "found," it is because a human on your committee found them — the product does not go looking.
3. How we use it
We use data to: operate the Service (host your plans, render your dashboards, send the invitations and reminders you trigger or schedule); process your purchases; secure the Service (rate-limiting, abuse and intrusion detection); support you when you write in; send you transactional email about your account (receipts, security notices); and — only if you opt in — product news, which you can leave with one click. Legal bases for users in regions that require them are listed in Section 13.
4. The AI advisor — full transparency
The standard for this section: if the AI doesn't do something, it is not claimed here. If it does, we explain why it does it, how it works, and everything in between. This is the longest section of the policy on purpose.
What the AI advisor is
Each plan includes an assistant you can ask questions in plain language ("how many yeses for Saturday?", "what's still unpaid?") and ask to draft changes ("move the ceremony a week," "draft a reminder to the no-replies"). It is powered by a large language model from our AI provider (Anthropic). We use a third-party model because building a private one would not make it safer — the safety is in what we send, which is the point of everything below.
Exactly what happens when you ask a question
Your question is paired with plan context, not your database
The advisor is given your question plus the relevant slice of the event's data (counts, statuses, dates, budget lines) — never a dump of your account, never other customers' data, never data from your other events unless you ask across them.
Names are stripped before anything leaves
Before the request leaves the Service, personal names of guests, clients, and contacts are replaced with neutral placeholder labels (like "Guest 12"). A mapping between placeholders and real names stays inside your plan's own storage. The model answers about "Guest 12"; your screen shows the real name because the Service swaps it back on the way in. The AI provider sees the shape of your plan, not the people in it.
The scrub is verified — and it fails closed
After stripping, the outgoing request is checked against the plan's known names. If a name cannot be verified as removed — an unusual spelling, a name embedded in free text — the request is blocked, not sent. You get an error instead of a leak. We chose refusing over guessing, and this is enforced in code, not policy.
Proposals only — you approve every action
When you ask the advisor to change something, it returns a proposal: what it wants to create, update, delete, or send, spelled out. Nothing executes until you tap Approve. No silent edits, no auto-sent messages. Decline and nothing happened.
Everything is logged where you can read it
Every advisor interaction — what was asked, what context was included, what was proposed, and what you approved or declined — is written to an audit log inside your account. You can read your own AI history any time.
What data the AI provider receives and keeps
The provider receives the scrubbed request described above and returns a response. Under our agreement with the provider, API inputs and outputs are not used to train their models and are retained by them only briefly for abuse monitoring per their API terms. We do not send the provider your email address, your account identity, your payment information, or your files.
What the AI does NOT do — the complete list
- It does not act autonomously. It cannot send an email, text a guest, change a date, or delete a record on its own. Every action requires your explicit approval, every time. There is no "auto mode."
- It does not train on your data. Not our models (we train none), not the provider's (contractually excluded).
- It does not see guest, client, or contact names. They are stripped before egress and verified stripped; unverifiable requests are blocked.
- It does not browse the web, search social media, look up your guests, or pull information from outside your plan.
- It does not run in the background. It does nothing unless you are asking it something.
- It does not touch money. It cannot make purchases, issue refunds, or interact with any payment system — including ours.
- It does not share context across customers. Your advisor knows your event; it has never heard of anyone else's.
- It is not a person, and its answers are not guaranteed accurate. It can miscount, misread, and mis-suggest. The approve step exists because of this.
5. Who we share with — the complete sub-processor list
We share personal data only with the service providers below, only for the purpose stated, each bound by data-protection terms. We have no other sharing arrangements: no data sales, no advertising partners, no brokers.
| Provider | Purpose | What they process |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime infrastructure | All Service data, encrypted in transit and at rest, hosted in the United States |
| Stripe | Payment processing | Your payment details (they are the ones who see your card, not us) |
| Anthropic | AI advisor inference | Scrubbed, name-stripped requests only — see Section 4 |
| Resend | Email delivery (invitations, RSVPs, receipts) | Recipient email addresses and message content you trigger |
| Twilio | SMS delivery (reminders you trigger) | Recipient phone numbers and message content you trigger |
| Cloudflare | Application hosting and delivery | Service logs, IP addresses |
We may also disclose data if legally compelled (subpoena, court order) — we will notify you unless legally barred — and in a merger or acquisition, in which case this policy continues to apply to data collected under it and you will be notified.
6. What we never do with your data
- We never sell it. Not guest lists, not emails, not "anonymized insights" packaged for vendors. Never.
- We never advertise with it. No ad networks, no retargeting, no letting caterers pay to reach your guest list. Our revenue is the price on the pricing page.
- We never message your guests for our own purposes. Guests receive only what you send. The most PlanFlow-branded thing they see is a footer line on pages we host for you.
- We never train AI on it (Section 4).
- We never browse it. Staff access to customer content is restricted to support cases you initiate, and is logged.
7. If you're a guest, classmate, or portal visitor
Someone planning an event — a couple, a family, a reunion committee, a planner — entered your details to invite you and manage the event. They control that data; we host it for them. What you should know:
- Your RSVP link is personal. It opens a page for you without requiring an account or app. Anyone holding the link can see that page, so treat it like an invitation, not a public URL. Hosts can revoke links.
- Portal logins are email-verified. Where a feature gives you a fuller portal (a client portal, a vendor sheet), access is verified against your email — codes, not passwords to remember.
- What you submit goes to your host. RSVPs, dietary notes, memory-wall posts, and photos go to the event's planners, who moderate and control them.
- Memory Wall posts are approved before they appear. If you post a memory or photo on a memorial event's Memory Wall, it goes to the hosting family first and appears on the page only after they approve it; hosts can also remove any post at any time. To remove a post you made, ask the host, or contact support@planflowplanner.com and we will help. The license and content rules for posts are in Terms Section 20.
- Every event email has a one-click unsubscribe. Invitations and reminders delivered through PlanFlow arrive under the event's name and include a working one-click unsubscribe. Using it stops future PlanFlow-delivered email to your address for that host's events — we keep your address on a suppression list for exactly that purpose and nothing else.
- The AI never sees your name (Section 4), and you will never get marketing from us because a host entered your details.
- To access, correct, or delete your information, ask your host first — it is their event record. If you cannot reach them or need our help, contact support@planflowplanner.com and we will assist, honoring applicable law and our processor role.
8. Security
In plain words, the real measures: all traffic is encrypted in transit (TLS) and data is encrypted at rest; every database table is protected by row-level security policies so accounts are isolated from each other at the database layer, not just the application layer; privileged operations run through narrowly-scoped server-side functions rather than broad database access; share links use long random tokens and can be revoked; passwords are hashed, never stored; and administrative access is limited and logged. No service can promise zero risk — if we ever suffer a breach affecting your data, we will notify you and regulators as applicable law requires, without games.
9. Retention & deletion
Your event data stays as long as your account is active — memories are part of the product (memorial pages, memory walls), so we do not auto-purge live accounts. If you close your account, deletion is immediate — there is no grace period. Your events, guests, uploaded files and memorial walls are removed from production systems right away; backups age out on their regular rotation cycle. Export anything you want to keep before you close the account, because we cannot recover it afterwards. We retain what law requires longer (tax and transaction records) and minimal fraud-prevention records. You can also delete individual events or guests at any time, effective immediately in production.
10. Your rights & choices
Regardless of where you live, we honor: access (see what we hold), export (take it with you, standard formats, any time, no fee), correction (fix it), deletion (Section 9), and marketing opt-out (one click; transactional email about your account continues because the Service needs to tell you about receipts and security). Requests: support@planflowplanner.com. We verify requests against your account email and answer within 30 days.
11. Cookies & analytics
We use strictly-necessary cookies for sign-in sessions and security. We do not use third-party analytics, advertising cookies, or cross-site trackers.
12. Children
PlanFlow accounts are for adults (18+), and we do not knowingly collect personal information directly from children under 13. Events themselves often involve minors — a bat mitzvah honoree, a quinceañera's court — whose information is entered and controlled by the adult planner as part of their guest and event records. Hosts are responsible for having the right to enter it (parents and family hosts generally do). If you believe a child has created an account directly, contact us and we will delete it.
Guest-facing pages — RSVP links, memory walls, portals — do not require an account and are not directed to children, and we do not knowingly accept RSVPs or Memory Wall posts submitted directly by children under 13; a parent or adult family member should submit on a child's behalf. Hosts can remove any guest submission instantly, and if you believe we hold information collected directly from a child under 13, contact support@planflowplanner.com and we will delete it.
13. Regional rights
California (CCPA/CPRA): we do not sell or "share" personal information as those terms are defined; the rights in Section 10 correspond to your statutory rights to know, delete, correct, and non-discrimination. EEA/UK (GDPR): legal bases are contract performance (operating the Service you bought), legitimate interests (security, service improvement), and consent (optional marketing); you additionally have rights to restriction, objection, portability, and complaint to your supervisory authority. Data is processed in the United States; where transfers from the EEA or UK occur, we rely on appropriate safeguards such as the Standard Contractual Clauses.
14. Changes & contact
If we change this policy materially — especially anything in Section 4 or 6 — we will notify account holders by email at least 30 days before it takes effect, with a plain summary of what changed. The AI transparency sections will never be weakened silently; that is the deal.
Privacy questions and requests: support@planflowplanner.com · PlanFlow Planner, LLC · PO Box 44426, Eden Prairie, MN 55344.