Privacy-first planner: where do your records live?
Last updated: 2026-10-10
Tasks and calendars hold appointments, family plans and work details, so you should know where they live and who can see them. This guide explains local-first design, what Pladay keeps on your device, what it sends to a server, and where the limits are.
What local-first means
Local-first means the original data lives on your device first. Actions are handled instantly on the device and synced when needed, so the app is fast offline and, if you never sign in, nothing is sent to a server. The trade-off is that unsynced data is hard to recover if you lose the device or clear the browser, which is why Pladay offers export, backup and optional sync.
What is stored where
This summarises the privacy policy, which is the authoritative source.
| Situation | Stored | Sent to server |
|---|---|---|
| Not signed in | Your device (browser storage) | No |
| Signed in: tasks, notes, habits | Device and server (sync) | Yes, encrypted in transit and at rest |
| Cycle, intimacy and medical modules | This device only by default | Only if you turn sync on for that module and confirm |
| AI with your own API key | Key stays on this device | Sent from your device directly to the AI provider, not via Pladay |
| Pladay Cloud AI | Text is passed when you run a feature | Only when you run it; sensitive records are excluded from automatic use |
| Public share link | Only the shared item | Limited to that item, revocable any time |
Sensitive records stay on the device by default
Cycle and contraception, intimacy, medical and health records and trackers such as drinking, smoking or anxiety are treated as sensitive. You give separate consent, they stay on this device by default, and cloud sync is a per-module opt-in with an extra confirmation. Turning it off or withdrawing consent deletes the server copy. They are never used for automatic AI briefings, pattern analysis, search, the day story or share cards.
Honest limits
- Synced data is encrypted in transit and at rest but it is not end-to-end encrypted. Keep records you never want on a server device-only or do not sign in.
- Servers are located in the United States; this is disclosed in the privacy policy.
- Encrypted backups can retain deleted data for a fixed period (30 days daily, 12 months monthly) and are used only for disaster recovery.
- Device security is yours: use a screen lock, and a PIN for sensitive modules.
Controls you have
- Use the app without an account and sign in only when you need sync.
- Withdraw consent or turn off sync per module in Settings.
- Export your data as CSV, Markdown or ZIP.
- Delete your account to remove your data from the database and storage.
- Choose on-device AI or your own key so requests skip Pladay servers.
No selling, no ad profiling
Pladay does not sell your tasks or use them for ad profiling. Visit statistics use a hashed random ID and totals only, and IP addresses are used in memory for rate limiting and not stored. Read next: the AI planner guide and the app comparison guide.
FAQ
If I never sign in, is anything sent?
Your tasks and records stay on the device. Site statistics (a hashed random ID and totals) and IP handling for rate limits can occur when you visit; see the privacy policy.
Does turning on sync upload my sensitive records?
Sensitive modules are device-only by default; only modules you enable and confirm are uploaded. Other modules such as tasks and notes sync when you are signed in.
Is my data used to train AI models?
Pladay does not sell your data or use it for ads. AI providers follow their own policies, so use on-device AI or your own key for sensitive text.