Planium Privacy Policy
Effective date: 19 August 2026
Planium is a social app for planning activities with friends, available as a website, an installable web app, and an app for iPhone. This policy explains what personal data Planium collects, why, and what your rights are. It is written to be read by humans — if anything is unclear, email me and I'll explain.
Need help with something rather than a legal answer? See the support page.
1. Who is responsible for your data
Planium is made and operated by a single independent developer:
Mike Balvert (operating as "Softium"), based in the Netherlands
Contact: mike@softium.nl
I am the "data controller" under the EU General Data Protection Regulation (GDPR). There is no company, no team, and no data department — messages to the address above reach me directly.
I am also the only person with access to the servers and the database. For moderation I use a private, owner-only dashboard that shows reports and account-deletion requests; it is read-only and no one else can log in to it.
2. What data Planium collects
Planium only collects data that you actively provide or that is needed to run and protect the service. There is no analytics, no advertising, no tracking, and no profiling of any kind.
Your account
- Email address, username, and display name
- Your password — stored only as a secure hash (I cannot see it)
- Profile picture, if you upload one, and profile decorations (stickers)
- Account settings, such as who can see your friends list, who can see your display name, and whether friends must ask before adding you to a group
- Account creation date, email-verification status, whether you finished the introduction, and — if you ask for deletion — the date you requested it
- Any optional or hidden feature switches you have turned on in the app
Your devices and sign-ins (for security)
For each device you stay logged in on, Planium stores the IP address, device type (e.g. iOS, Windows), browser or "Planium App", the browser's user-agent string, and when the session was created and last used. You can see this list yourself in Settings → Devices and log out any device remotely.
To protect accounts against break-in attempts, Planium also keeps short-lived security records: failed-login counts per IP address (with an escalating block), email-verification codes and how often they were sent or guessed, password-reset tokens, and — when you log in to the iPhone app — a one-time hand-off code that the app exchanges for its own login token. See the retention section for how long each of these lives.
Your friends, lists and groups
- Friends: friend connections and friend requests (who asked whom, and when).
- Blocks: which users you have blocked, and when.
- Lists: your own private groupings of your friend list (a name plus which friends are in it). Lists are visible only to you — they are a saved filter, not a shared space.
- Groups: shared groups you create or are added to. Stored per group: the group's name, its settings (who may add members, who may rename it), and for every member their role (owner, admin, member), who added them, when they joined, and whether they still have a pending invite. Unlike a list, a group is shared — see "Who can see your content" below.
- Reminders: when you become friends with someone, Planium may remind you to sort them into a list. To avoid nagging you twice about the same person, a small record of that reminder is kept.
Your activities (the planning data)
Everything you enter when planning an activity: title, description, start and end dates and times, category/theme, participants and invitations (including who invited whom), the activity's own permission switches, whether it was cancelled, and the location details you type in (place name, street, city, postal code, country). You can also save locations to reuse later. Location details are only what you type — Planium never accesses your device's GPS or location services.
Also stored per activity:
- Polls and votes: poll questions and options (for names, places, dates, times, combined "fusion" polls, and custom polls), who voted for what, and who created or closed each poll.
- Add-ons: extra things attached to an activity — currently links (for example a shared playlist, a payment request, or tickets). Planium stores the link itself, its label, and who added it. A link is content you typed or pasted; Planium does not visit it for you.
- An activity timeline: a record of what happened in the activity — who joined, left, was invited or removed, who added or closed a poll, who added or removed an add-on, and which details were changed. These entries are shown to the participants inside the activity's chat.
Your chat messages
Messages in activity group chats, including edits, replies, read receipts (for the chat and for polls), and stickers you send or upload. Two things you should know:
- When you delete a message, it is hidden from everyone in the chat, but the text remains stored in the database. This is kept for moderation purposes — for example, so that abusive messages cannot be erased before they can be reviewed.
- When someone reports a message, a snapshot of that message (its text or, for a sticker, which sticker it was, plus the sender and the reporter) is saved separately so it can be reviewed even if the original is edited or deleted.
- A small list of words is masked out (shown as
#) when messages are displayed. This happens as the message is sent to a reader, not when it is stored — what you typed is kept unchanged, and the masking is applied for everyone equally. No message is analysed or scored beyond this word match, and nothing about it is recorded.
Your stickers
Which profile stickers you own and when each one was unlocked, whether a sticker has its "prismatic" style unlocked, and how you have arranged them on your profile (position, rotation, layer, and which side of the sticker faces out). Chat stickers you upload are stored as image files, one per slot.
Prismatic stickers shine when you tilt your phone. That effect reads your device's motion sensor in the app itself, purely to draw the shine — the readings are never stored, never sent to the server, and never used to identify you or your device.
Reports you make
When you report a message, a user, or a whole activity, Planium stores who reported what, the category you selected (for example spam, harassment, hate, inappropriate content, or impersonation), and the time. For a reported message it also keeps a snapshot of that message; for a reported activity it keeps a snapshot of the activity's title and who was hosting it, so the report stays identifiable if the activity is later renamed or deleted. Reports are used only for moderation and are reviewed by me; they are not shown to other users, and the person you reported is not told who reported them.
Activity summaries
Planium shows simple in-app summaries built from your own activity — for example, how many activities you've shared with a particular user, or an occasional recap of your activity. These are generated from data you already provide, are not stored as a separate profile of you, and are never shared with anyone or used for advertising.
Notifications (optional)
- In the browser or installed web app: Planium stores a web-push subscription — a delivery address at your browser's push service, its encryption keys, and a device label.
- In the iPhone app: Planium stores the opaque device token Apple issues for push notifications, plus the platform, linked to that device's session.
- Your preferences: which kinds of notifications you want and whether each one makes a sound.
- When Planium is open in front of you, notifications are shown as a banner inside the app instead of being delivered by your operating system.
- On iPhone, message notifications are rendered in iOS's "communication" style. To make that possible the notification payload includes the sender's display name and profile-picture link, and the activity's name and theme image. It is encrypted in transit and Apple cannot read it.
Notifications are optional and you can turn them off at any time in settings or by revoking the browser/OS permission.
Technical logs
Standard server logs (such as requests and errors) that may include IP addresses, kept briefly for security and debugging.
Data that stays on your device
Preferences like theme, default calendar and maps app, an unfinished activity you started creating but haven't posted yet, the app files Planium caches so it works offline, and whether you switched notifications on. This data is stored only on your own device and never sent to the server.
3. The Planium app for iPhone
The app is the same Planium, wrapped in a native shell and distributed through Apple's App Store. A few things are specific to it:
- No tracking, at all. The app contains no analytics, advertising, attribution, or crash-reporting SDKs. It does not use the advertising identifier (IDFA) and will never ask permission to track you across other apps or websites.
- Permissions it asks for. Notifications, if you want them. Access to motion data, used only to draw the tilt shine on prismatic stickers. That's it.
- Choosing a picture. When you set a profile picture or upload a sticker, the app opens Apple's own photo picker. That picker runs outside Planium and hands back only the one image you chose — the app is never granted access to your photo library, and iOS does not even need to ask you for permission.
- Permissions it does not ask for. As of this version, Planium does not access your contacts or address book, your photo library, camera, microphone, location services, calendar, health data, or the files on your phone. If a later version needs one of these, iOS will ask you for it first and you can say no; this policy will be updated to explain what it is used for before that version ships.
- Version check. The app tells the server which platform and app version it is, so the server can tell it when a required update is available. That request carries no extra personal data.
- Signing in. Login happens on the Softium website; a one-time code (valid for one minute, usable once) hands the session to the app, which then keeps its own login token for that device.
- Links and sharing. External links open in an in-app browser window, which has its own separate cookies. Sharing a profile or activity link uses the iOS share sheet — Planium never learns which app or person you chose.
- Apple's own data. Downloading and updating the app happens through your Apple Account. Apple collects that on its own behalf, under Apple's privacy policy; I never see your Apple Account details.
4. What Planium does NOT do
- No advertising — there are no ads and never any ad networks.
- No analytics or tracking — no Google Analytics, no Facebook SDK, no crash-reporting services, no fingerprinting, no advertising identifiers, nothing.
- No selling or renting of data — your data is not shared with anyone for their own purposes.
- No profiling or automated decisions — no algorithm evaluates you or decides anything about you.
- No device location access — locations in activities are text you type, nothing more.
- No contact-list upload — Planium never reads your contacts, and you find people by searching for their username.
5. Why the data is processed (legal bases)
- Providing the service (your account, activities, chats, friends, lists, groups, and the verification and password-reset emails): contract — Art. 6(1)(b) GDPR.
- Push notifications: consent — Art. 6(1)(a); you can withdraw it at any time.
- Security (login protection, verification codes, device management, server logs): legitimate interest — Art. 6(1)(f): keeping accounts and the service safe.
- Moderation (handling reports, keeping deleted messages reviewable): legitimate interest — Art. 6(1)(f): keeping the community safe.
- Backups: legitimate interest — Art. 6(1)(f): not losing everyone's data.
6. Who can see your content
Planium is a social app, so some of your data is visible to other users by design:
- Your username, display name (depending on your privacy setting), profile picture, and profile decorations are visible to other users, including via user search.
- Participants of an activity can see the activity details, its add-ons and links, the chat, your messages and stickers, your poll votes, and the activity timeline — which names who did what.
- Groups are shared spaces. Every member of a group sees the group, its name, and every other member — including members who are not your friends. Only your own friends can add you to a group, and by default that takes effect immediately; you can require an invite instead with "Ask before adding me to groups" in your privacy settings. Membership is independent of friendship afterwards: unfriending or blocking the person who added you does not remove you from the group. You can leave a group at any time. Groups you and another person are both in are shown on each other's profiles — only the ones you share, never the rest of their groups.
- Your lists are private to you. Nobody is told which list you put them in, or that lists exist.
- Your friends list visibility can be limited in your privacy settings.
- Profile pictures and uploaded stickers are served via direct web links; anyone who has such a link can view the image, even without an account.
7. Who else receives data (processors)
I use a small number of service providers to run Planium. None of them may use your data for their own purposes.
- GitHub, Inc. (USA — certified under the EU–US Data Privacy Framework): hosts the app's web files. When your device loads the app, GitHub sees your IP address, like any website host.
- Apple Inc. (USA/EU — certified under the EU–US Data Privacy Framework): distributes the iPhone app through the App Store; delivers Planium's emails (verification, password reset, account deletion, data export) via iCloud Mail; stores server backups in iCloud; delivers push notifications to Apple devices through APNs. Notification content is encrypted and not readable by Apple.
- Google / Mozilla push services (USA — Data Privacy Framework / EU standard safeguards): deliver push notifications to devices using Chrome or Firefox on the web, if you enable notifications there. Content is encrypted and not readable by them.
- Google (connectivity check): only when the app cannot reach the server, it pings a Google address to check whether your internet works. Google sees only your IP address for that single request.
If you tap "open in Maps" or "add to calendar", your device opens Google Maps, Apple Maps, or Google Calendar with the activity's details. If you open a link someone attached to an activity, your device goes to that website. Both happen only when you tap, and are then governed by that provider's privacy policy.
Everything else — the database, the API, and real-time messaging — runs on servers located in the Netherlands, operated directly by me.
8. How long data is kept
- Account, profile, friends, lists, groups, activities, chats: until you delete them or your account. Leaving a group removes your membership; deleting a group removes it for everyone.
- Deleted chat messages (hidden text): retained for moderation while the chat exists; removed with the activity or per request (see your rights).
- Reports (of messages and of users): up to 12 months after review.
- Logged-in device records: deleted when you log out a device; expire automatically after 1 year of inactivity.
- Push subscriptions and app push tokens: deleted when you turn notifications off, log that device out, or the delivery address stops working.
- Failed-login records per IP: kept only as long as the block and its escalation are relevant (hours) and pruned automatically; never longer than 30 days.
- Email-verification codes: 15 minutes. App login hand-off codes: 1 minute, single use. Password-reset tokens: expire shortly after being requested and are invalidated once used.
- Unfinished registrations (email never verified): deleted automatically after 24 hours.
- Server logs: up to 90 days.
- Backups: rotated; each backup is deleted after at most 6 months.
When you delete your account, it is deactivated immediately and you receive a confirmation email. There is a 14-day grace period during which you can change your mind by logging back in and reactivating it. After that, your account, profile picture, devices, push subscriptions and app push tokens, saved locations, lists, group memberships, and friend connections are permanently deleted — counting from your request, within 2 weeks, one month at most. Your chat messages and activity participation are anonymized — the content of group conversations survives for the other participants, but is no longer linked to you. Copies in backups disappear as backups rotate, within 6 months at the latest.
9. Your rights
Under the GDPR you can, at any time:
- Access — ask for a copy of the data I hold about you
- Rectification — correct wrong data (most of it you can edit yourself in the app)
- Erasure — delete your account and data (available in the app, or email me)
- Portability — receive your data in a machine-readable format (e.g. JSON)
- Restriction and objection — object to processing based on legitimate interest
- Withdraw consent — e.g. turn off push notifications at any time
To use any of these rights, email mike@softium.nl. I will respond within one month, as the GDPR requires. I may need to verify that you own the account (for example by asking you to reply from the account's email address).
Data copies (access/portability) are delivered as a machine-readable JSON export, emailed only to your account's registered email address — that is also the identity check. The export contains the personal data stored about your account: your account details and settings, devices, stickers, friends and blocks, lists, activities, invitations, poll votes, add-ons, chat messages, chat stickers, read receipts, reports, and the activity timeline entries about you. If you think something about you is missing from it, email me and I will send that too. It deliberately excludes security material (your password hash, session and app tokens, verification and reset tokens, and push encryption keys) and other people's private data: other users appear in your export by username only, and your data held in their exports is limited the same way. Export requests are logged so I can demonstrate they were fulfilled; deletion and export both remain available while an account is pending deletion.
If you believe your data is handled unlawfully, you have the right to complain to the Dutch supervisory authority: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) — or the data protection authority of your own EU country.
10. Security
Passwords are stored using strong one-way hashing. All connections between the app and the server use encryption (HTTPS/TLS), and push notification payloads are end-to-end encrypted to your device. Login attempts are rate-limited per IP address with escalating blocks, verification codes are short-lived and limited in how often they can be sent or guessed, and resetting your password logs out every session on every device. You can review and log out your devices at any time in settings. No system is perfectly secure, but if a data breach ever affects your personal data, I will notify you and the supervisory authority as required by law.
11. Age requirement
Planium is not directed at children. You must be at least 16 years old to create an account. If I learn that an account belongs to someone younger, I will delete it.
12. Changes to this policy
If this policy changes in a meaningful way, you will be notified in the app and by email before the change takes effect. Older versions can always be requested by email.
The August 2026 update describes features added since the previous version: the Planium app for iPhone, shared groups, activity add-ons, the activity timeline, sticker collecting and prismatic stickers, reporting a whole activity, the masking of a few words in displayed messages, and the security records behind email verification codes and app sign-in. No new purpose of processing was introduced, nothing new is shared with third parties beyond the App Store distribution described above, and no data is used for advertising, analytics, or profiling.
Last Updated: August 19 2026