1. Data we collect
Account data such as your name, email address, profile image, workspace membership, and authentication events. Content data such as prompts, uploaded media, generated assets, captions, schedules, campaign notes, and analytics you choose to connect.
When you connect a provider, we receive the profile and publishing data required by the permissions you approve: account identifier, display name, avatar, scopes, publishing status, and token metadata. OAuth access and refresh tokens are encrypted at rest and are never returned to the browser or included in ordinary list responses.
2. How we use data
We use data to authenticate you, operate your workspace, generate content through the selected AI provider, publish only after your explicit confirmation, maintain schedules, prevent abuse, provide support, and improve reliability. We do not sell personal information or use connected-account data to build advertising profiles.
3. AI processing
Prompts and selected evidence may be sent to the AI provider configured for your workspace. We do not ask providers to train on your data unless their current terms expressly permit it and you have chosen that provider. AI output is assistive, may be inaccurate, and is presented for human review before publishing.
4. Third-party APIs
Connected platforms process data under their own terms and privacy policies. We request the narrowest permissions needed for the selected workflow, explain why they are requested, and provide disconnect and deletion controls. Disconnecting stops future access; it does not revoke a platform grant, so use the provider's app settings when full revocation is required.
5. Cookies and analytics
Necessary session cookies keep you signed in. Optional product analytics, web-vitals, heatmaps, and masked session replay run only after consent. You can change your choice at any time from the cookie preferences control or by clearing the consent setting in your browser.
6. Retention and deletion
We retain workspace data while your account is active, plus limited security and billing records required by law. You can disconnect providers, delete imported data, export your workspace, or permanently delete the account from Settings or the Delete data page. Backups age out according to our retention schedule.
7. Your rights
For GDPR, UK GDPR, CCPA, and similar requests, contact us using the details below. We may verify identity before fulfilling a request.
- Access, correct, export, or delete your personal data.
- Object to or restrict processing where applicable.
- Withdraw optional analytics consent without affecting necessary service operation.
- Lodge a complaint with your local data-protection authority.
8. Contact
The data controller for CPlanner can be reached at support@cplanner.com. We will update this policy when our processing materially changes.
Questions? Email support@cplanner.com.