Privacy Policy

At Planify, protecting your personal data is a priority. This page transparently explains how we collect, use and protect it.

Last updated: June 9, 2026

Data We Collect

1
  • Upon registration: first name, last name, email address and password (hashed).
  • Profile data: optional avatar, username, language and theme preferences.
  • Usage data: projects, tasks, milestones, notes, calendar events, comments and files you create or upload.
  • Mini cloud files: name, type, size and path of each file uploaded to your project spaces.
  • Technical data: IP address, browser type, operating system and access logs for security purposes.
  • Anti-abuse fingerprint: a hash of your IP address and browser (non-reversible) is recorded on each upload to detect and block multi-account storage abuse.
  • Authentication tokens: JWT tokens stored in the database, automatically purged upon expiry.

How We Use Your Data

2
  • Provide, operate and improve Planify's features.
  • Authenticate your identity and secure your account.
  • Send notifications related to your projects and collaborations.
  • Enable real-time communication via WebSocket between project members.
  • Analyse overall usage (aggregated and anonymised) to improve the service.
  • We never sell your data to third parties.

Per-Project Mini Cloud

3
  • Each Planify project has a dedicated storage space (mini cloud) to centralise your team's files.
  • You can upload documents, images, archives, audio/video files and code files — up to 500 MB per file.
  • Storage is limited to 5 GB per project and 10 GB per user account across all projects.
  • Files can be organised into hierarchical folders and subfolders.
  • Only project members (Owner, Admin, Member) can upload. Viewers can only download.
  • Every download requires authentication — no file is accessible without being logged in.
  • Deleted files are permanently removed from the server; no recycle bin is kept.

Anti-Abuse & Multi-Account Protection

4
  • To ensure a fair service, we use a technical fingerprint based on your IP address and browser (User-Agent).
  • This fingerprint is stored as a non-reversible SHA-256 hash — we do not retain raw browser data for profiling.
  • We track the total volume of data uploaded per fingerprint to detect storage abuse across multiple accounts from the same device.
  • Beyond 10 GB uploaded per fingerprint (matching the per-account quota), uploads are automatically blocked for that device.
  • This measure only applies to uploads; browsing, reading and downloading are not affected.
  • In case of unjustified blocking (shared IP, corporate proxy…), contact us at contact@infoblue.fr for manual unblocking.
  • Fingerprint data is never shared with third parties and is retained solely for security purposes.

Storage & Security

5
  • Your data is stored in a secure database with encryption at rest.
  • Passwords are hashed via bcrypt — they are never stored in plain text.
  • Communications are encrypted in transit via HTTPS/TLS.
  • Access tokens expire after 1 hour; refresh tokens after 7 days.
  • We apply rate limiting on sensitive endpoints (login, registration) to prevent brute-force attacks.
  • Mini cloud files are stored on a private server under a random UUID filename — the original name is never exposed in the download URL.
  • Each upload is protected by a dual software lock (per-project and per-user) to ensure quotas cannot be exceeded even under simultaneous uploads across multiple projects.
  • A quota of 5 GB per project and 10 GB per account is strictly enforced server-side, regardless of the client.

Your Rights (GDPR)

6
  • Right of access: you can view your personal data at any time from your account settings.
  • Right of rectification: you can edit your personal information in settings.
  • Right to erasure: you can request deletion of your account and all associated data.
  • Right to portability: you can request an export of your data in a standard format.
  • Right to object: you can object to the processing of your data for purposes other than providing the service.
  • To exercise these rights, contact us at the address below.

Local Storage

7
  • Planify does not use cookies. Session data is stored in your browser's localStorage.
  • Authentication tokens: your JWT tokens (access and refresh) are stored in localStorage to maintain your session.
  • Preferences: your theme (light/dark) and interface language are saved locally on your device.
  • This data stays on your device and is never transmitted to third parties.
  • You can clear it at any time by clearing your browser's local storage, which will log you out.
  • No advertising, analytics or third-party tracking cookies are used.

Third-Party Sharing

8
  • We do not share, sell or rent your personal data to any third parties.
  • Your data may be shared only when required by law (court order, legal obligation).
  • Project members can see your name and avatar as part of collaboration.

Friend System

9
  • Planify offers an optional friend system allowing you to connect with other users.
  • A unique friend code is automatically generated for each account. You can share it to receive friend requests.
  • When a user sends you a friend request, your name and username are visible to them.
  • Accepted friends can see your first name, username and avatar.
  • You can decline a friend request at any time.
  • Your friend code and friend list are included in your data export.

Contact

10
  • For any questions regarding this privacy policy or your personal data, contact us:
  • Infoblue — contact@infoblue.fr
  • We commit to responding within 30 days.

Questions about your data?

Our team is available to answer any questions you may have about your personal data.