Planium Privacy Policy

Effective date: 19 August 2026

Planium is a social app for planning activities with friends, available as a website, an installable web app, and an app for iPhone. This policy explains what personal data Planium collects, why, and what your rights are. It is written to be read by humans — if anything is unclear, email me and I'll explain.

Need help with something rather than a legal answer? See the support page.

1. Who is responsible for your data

Planium is made and operated by a single independent developer:

Mike Balvert (operating as "Softium"), based in the Netherlands
Contact: mike@softium.nl

I am the "data controller" under the EU General Data Protection Regulation (GDPR). There is no company, no team, and no data department — messages to the address above reach me directly.

I am also the only person with access to the servers and the database. For moderation I use a private, owner-only dashboard that shows reports and account-deletion requests; it is read-only and no one else can log in to it.

2. What data Planium collects

Planium only collects data that you actively provide or that is needed to run and protect the service. There is no analytics, no advertising, no tracking, and no profiling of any kind.

Your account

Your devices and sign-ins (for security)

For each device you stay logged in on, Planium stores the IP address, device type (e.g. iOS, Windows), browser or "Planium App", the browser's user-agent string, and when the session was created and last used. You can see this list yourself in Settings → Devices and log out any device remotely.

To protect accounts against break-in attempts, Planium also keeps short-lived security records: failed-login counts per IP address (with an escalating block), email-verification codes and how often they were sent or guessed, password-reset tokens, and — when you log in to the iPhone app — a one-time hand-off code that the app exchanges for its own login token. See the retention section for how long each of these lives.

Your friends, lists and groups

Your activities (the planning data)

Everything you enter when planning an activity: title, description, start and end dates and times, category/theme, participants and invitations (including who invited whom), the activity's own permission switches, whether it was cancelled, and the location details you type in (place name, street, city, postal code, country). You can also save locations to reuse later. Location details are only what you type — Planium never accesses your device's GPS or location services.

Also stored per activity:

Your chat messages

Messages in activity group chats, including edits, replies, read receipts (for the chat and for polls), and stickers you send or upload. Two things you should know:

Your stickers

Which profile stickers you own and when each one was unlocked, whether a sticker has its "prismatic" style unlocked, and how you have arranged them on your profile (position, rotation, layer, and which side of the sticker faces out). Chat stickers you upload are stored as image files, one per slot.

Prismatic stickers shine when you tilt your phone. That effect reads your device's motion sensor in the app itself, purely to draw the shine — the readings are never stored, never sent to the server, and never used to identify you or your device.

Reports you make

When you report a message, a user, or a whole activity, Planium stores who reported what, the category you selected (for example spam, harassment, hate, inappropriate content, or impersonation), and the time. For a reported message it also keeps a snapshot of that message; for a reported activity it keeps a snapshot of the activity's title and who was hosting it, so the report stays identifiable if the activity is later renamed or deleted. Reports are used only for moderation and are reviewed by me; they are not shown to other users, and the person you reported is not told who reported them.

Activity summaries

Planium shows simple in-app summaries built from your own activity — for example, how many activities you've shared with a particular user, or an occasional recap of your activity. These are generated from data you already provide, are not stored as a separate profile of you, and are never shared with anyone or used for advertising.

Notifications (optional)

Notifications are optional and you can turn them off at any time in settings or by revoking the browser/OS permission.

Technical logs

Standard server logs (such as requests and errors) that may include IP addresses, kept briefly for security and debugging.

Data that stays on your device

Preferences like theme, default calendar and maps app, an unfinished activity you started creating but haven't posted yet, the app files Planium caches so it works offline, and whether you switched notifications on. This data is stored only on your own device and never sent to the server.

3. The Planium app for iPhone

The app is the same Planium, wrapped in a native shell and distributed through Apple's App Store. A few things are specific to it:

4. What Planium does NOT do

5. Why the data is processed (legal bases)

6. Who can see your content

Planium is a social app, so some of your data is visible to other users by design:

7. Who else receives data (processors)

I use a small number of service providers to run Planium. None of them may use your data for their own purposes.

If you tap "open in Maps" or "add to calendar", your device opens Google Maps, Apple Maps, or Google Calendar with the activity's details. If you open a link someone attached to an activity, your device goes to that website. Both happen only when you tap, and are then governed by that provider's privacy policy.

Everything else — the database, the API, and real-time messaging — runs on servers located in the Netherlands, operated directly by me.

8. How long data is kept

When you delete your account, it is deactivated immediately and you receive a confirmation email. There is a 14-day grace period during which you can change your mind by logging back in and reactivating it. After that, your account, profile picture, devices, push subscriptions and app push tokens, saved locations, lists, group memberships, and friend connections are permanently deleted — counting from your request, within 2 weeks, one month at most. Your chat messages and activity participation are anonymized — the content of group conversations survives for the other participants, but is no longer linked to you. Copies in backups disappear as backups rotate, within 6 months at the latest.

9. Your rights

Under the GDPR you can, at any time:

To use any of these rights, email mike@softium.nl. I will respond within one month, as the GDPR requires. I may need to verify that you own the account (for example by asking you to reply from the account's email address).

Data copies (access/portability) are delivered as a machine-readable JSON export, emailed only to your account's registered email address — that is also the identity check. The export contains the personal data stored about your account: your account details and settings, devices, stickers, friends and blocks, lists, activities, invitations, poll votes, add-ons, chat messages, chat stickers, read receipts, reports, and the activity timeline entries about you. If you think something about you is missing from it, email me and I will send that too. It deliberately excludes security material (your password hash, session and app tokens, verification and reset tokens, and push encryption keys) and other people's private data: other users appear in your export by username only, and your data held in their exports is limited the same way. Export requests are logged so I can demonstrate they were fulfilled; deletion and export both remain available while an account is pending deletion.

If you believe your data is handled unlawfully, you have the right to complain to the Dutch supervisory authority: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) — or the data protection authority of your own EU country.

10. Security

Passwords are stored using strong one-way hashing. All connections between the app and the server use encryption (HTTPS/TLS), and push notification payloads are end-to-end encrypted to your device. Login attempts are rate-limited per IP address with escalating blocks, verification codes are short-lived and limited in how often they can be sent or guessed, and resetting your password logs out every session on every device. You can review and log out your devices at any time in settings. No system is perfectly secure, but if a data breach ever affects your personal data, I will notify you and the supervisory authority as required by law.

11. Age requirement

Planium is not directed at children. You must be at least 16 years old to create an account. If I learn that an account belongs to someone younger, I will delete it.

12. Changes to this policy

If this policy changes in a meaningful way, you will be notified in the app and by email before the change takes effect. Older versions can always be requested by email.

The August 2026 update describes features added since the previous version: the Planium app for iPhone, shared groups, activity add-ons, the activity timeline, sticker collecting and prismatic stickers, reporting a whole activity, the masking of a few words in displayed messages, and the security records behind email verification codes and app sign-in. No new purpose of processing was introduced, nothing new is shared with third parties beyond the App Store distribution described above, and no data is used for advertising, analytics, or profiling.

Last Updated: August 19 2026