General privacy
General Privacy Policy
Post-Mission Planner ("Post-Mission Planner," "we," "us," or "our") provides a personal
calendar, goals, habits, and relationship-planning app for iPhone, together with its website,
accounts, synchronization, and optional integrations (collectively, the "Service"). This policy
explains what information we collect, how it is stored, who can access it, and the choices you
have. It is a notice, not a blanket consent. Where the law requires consent, we ask for it
separately.
Planning content can include spiritual, physical, health-related, relationship, or location
details. You choose what to enter. Additional rules for information that may be consumer health
data are in the Consumer Health Data Privacy Policy below.
1. How planning data is stored
Content you create in the app — calendars, events, goals, habits, notes, People records, map
places, and similar material — is user-created data. To sync that data across
your signed-in devices and to run optional integrations, we store it on our servers. The app
also keeps a local cache on your device so it can work when you are offline. Authentication
credentials are stored in secure device storage where the operating system supports it.
Selected journal fields are encrypted at rest with keys we hold: event notes, event location
text, invitees, goal descriptions, contact notes, interaction titles and descriptions, map-place
notes, and Google Calendar sync tokens. Event titles, times, names, email addresses, and phone
numbers remain stored in a form the Service can process so search, Google Calendar sync, Partner
Access, and the app can function. Newly created or updated events do not store photos on our
servers. Older accounts may still have previously stored event-photo data until it is
overwritten or the account is deleted.
This is not end-to-end encryption. Post-Mission Planner and the infrastructure providers that
host the Service (including Railway, which hosts the database) can technically access stored
account data. Device-local caches are protected by your device and iOS settings and remain until
you sign out, delete the app, clear the relevant feature, or erase the device. Notifications may
show event titles, times, locations, or reminders on the lock screen depending on your
notification settings.
2. Information we collect
-
Account and identity. Name, email address, password hash, timezone, account
identifiers, authentication records, session information, and records of which policy versions
you accepted. If you sign in with Apple or Google, that provider may give us a verified
identifier, name, email address, or an Apple private-relay address.
-
User-created planning data. Calendars, events, locations, invitees, goals,
habits, recurrence, reminders, categories, settings, notes, People records, contact details,
addresses, tags, relationship history, saved map places, dropped pins (including latitude and
longitude), and other content you enter, import, or synchronize.
-
Map and location. If you grant location permission while using Map, we may
process your precise location only while the app is in the foreground, so the map can center
or re-center on you. We do not use background location or advertising identifiers. If you
geocode a People address, the address text is processed on your device; coordinates may be
cached locally. Saved map places and dropped pins store the latitude and longitude values you
selected.
-
Information about other people. You may add or import another person's name,
contact details, addresses, event participation, relationship notes, and interaction history.
That person may not have a Post-Mission Planner account.
-
Integrations. Provider account identifiers, email addresses, authorization
scopes, encrypted authorization credentials, sync status, source calendar identifiers,
calendar-feed URLs, and the calendar content needed to run an integration you enable.
-
Purchases. Apple processes payment. RevenueCat receives account-linked
purchaser identifiers, product and entitlement status, transaction environment, purchase
dates, and restoration or revocation status. We do not receive full payment-card numbers.
-
Service logs. IP address, timestamp, request route with sensitive query
values excluded, response status, authentication or security events, and limited device,
operating-system, browser, or app-version information sent with requests.
-
Support. Your email address and the content of messages you send us.
3. Optional integrations
These features run only if you enable them and grant the relevant permission.
-
Apple Calendar and Reminders. With permission, the app reads or writes the
calendars and reminders you select, using Apple's on-device frameworks. You control access in
iOS Settings.
-
Apple Contacts. With permission, the app reads contacts available under your
iOS permission to present an import review. Only contacts you select are copied to your
account. Granting permission does not upload your entire address book.
-
Map. The app may ask for location when you open Map or tap My Location. That
is foreground use only: to center the map while you are using it. It is not background
location, not App Tracking Transparency tracking, and not used for advertising.
-
Google Calendar. If you connect Google, we receive the identity, scopes,
tokens, and calendar content needed to list, import, synchronize, or write events according to
your settings. OAuth credentials are encrypted at rest. You can disconnect in the app and
revoke access in your Google account.
-
Calendar feeds and files. If you provide a Canvas or other iCalendar feed URL
or an .ics file, we process that URL or file and the events it contains. A feed URL can act
like a secret link; treat it accordingly.
-
Partner Access. If an account sponsors Full Access for another account, we
process the invitation, email address, relationship status, cooldown, and entitlement records.
While Partner Access is active, both accounts share their planner calendars, including event titles, times, locations, and notes. Google Calendar, Apple device calendars and reminders, and subscribed iCalendar feeds are not shared through Partner Access.
4. Sources of information
We receive information from you; from the app, website, and servers when you use them; from
Apple, Google, RevenueCat, and calendar providers you enable; from someone who includes you in
an event or a Partner Access invitation; and from files or feed URLs you provide.
5. How we use information
- Provide accounts, planning features, offline use, synchronization, integrations, purchases, and support;
- Authenticate users and protect accounts, providers, and infrastructure from fraud, abuse, and security threats;
- Diagnose errors and keep the Service reliable;
- Handle account deletion, privacy requests, provider disconnection, and purchase restoration;
- Enforce our Terms, comply with law, and establish, exercise, or defend legal claims.
We do not sell personal information. We do not use private planning content to serve ads, build
advertising profiles, or track you across other companies' apps or websites. We do not use
Google user data, calendar content, private planning content, or contact information to train
generalized artificial-intelligence or machine-learning models.
6. Sensitive planning content
Spiritual goals can reveal religious or philosophical beliefs. Physical goals, habits, event
details, reminders, locations, and notes can reveal health or other sensitive information. We
process that information only when you enter or connect it, and only to provide, secure, support,
or legally comply in connection with the Service. Basic planning features do not require you to
enter sensitive details.
Where the law requires explicit consent for sensitive data, we request it when you access your
account. You may withdraw consent for future optional processing by removing the content or
integration, deleting your account, or contacting us. Withdrawal does not undo processing already
performed lawfully and may disable the related features.
7. Google API data
Post-Mission Planner's use and transfer to any other app of information received from Google APIs
will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements. Google user data is used only to provide or improve the
user-facing integration, maintain security, comply with law, or perform another use expressly
permitted by that policy. Humans do not read Google user data unless you give affirmative
permission for a specific support or security purpose, it is necessary for security or abuse
investigation, or applicable law requires it.
8. Legal bases for EEA and UK users
Where the GDPR or UK GDPR applies, we rely on:
- Contract. Processing needed to create your account and deliver the features you request;
- Legitimate interests. Proportionate processing for security, fraud prevention, support, and reliability, where those interests are not overridden by your rights;
- Consent. Optional integrations, sensitive categories where explicit consent is required, and other processing for which we specifically request consent;
- Legal obligation and legal claims. Processing required by law or reasonably necessary to establish, exercise, or defend claims.
9. When we disclose information
-
Infrastructure and processors. Railway and associated database infrastructure
host the backend and stored account content. Resend delivers account emails. RevenueCat
processes purchase entitlements. Apple and Google process information when you use their
authentication, store, device, or calendar services. Each receives only what it needs for its
function.
-
Partner Access. While a partnership is active, each partner can see the other
account's planner-calendar event titles, times, locations, and notes. Google Calendar, Apple
device calendars or reminders, and subscribed iCalendar feeds are not included.
-
At your direction. Information is sent to a provider when you connect, sync,
write to, or otherwise use that provider.
-
Safety and legal process. We may preserve or disclose information when
reasonably necessary to comply with law or valid legal process, protect rights and safety,
investigate abuse, or secure the Service.
-
Business transaction. Information may transfer in a merger, financing,
acquisition, bankruptcy, reorganization, or sale of the Service, subject to applicable law and
continued protection of the information.
We do not disclose private planning content to data brokers, advertisers, or advertising networks.
10. Retention and deletion
We keep active account information and synchronized content while the account is open and as
needed to provide the Service. Sign-in challenges expire within minutes. Password-reset links
expire after one hour. Operational and security logs are kept only as long as reasonably needed
for security, troubleshooting, legal compliance, and disputes. Support messages are kept while
needed to resolve the request and keep an appropriate record.
When you delete your account through
Settings → Account → Delete Account, we delete the account and
associated content from the active database and request deletion of the associated RevenueCat
subscriber record. Provider backups and operational logs may retain limited copies for a
restricted period under those providers' schedules. Those copies are isolated from ordinary use
and are deleted or overwritten on that schedule unless the law requires preservation. Deleting
the app from your phone does not delete the server account.
After you delete an event, goal, contact, interaction, or map place, a tombstone record remains
so other devices can sync the deletion. Selected journal-style fields on those tombstones (notes,
descriptions, location text, invitees, and similar) are scrubbed after 90 days. Tombstone rows
themselves are not removed, because removing them would break deletion sync across devices.
We do not promise indefinite retention. If the Service or its servers are permanently
discontinued, server-stored information may become unavailable and may be deleted. Where
reasonably practicable, we will try to provide notice, but notice may not be possible.
11. Security
We use technical and organizational safeguards, including transport encryption, password hashing,
account access controls, and encryption at rest for Google Calendar OAuth credentials and for
selected journal fields listed in Section 1.
Because we hold the encryption keys for those journal fields, and because titles, times, names,
emails, and phone numbers are stored in processable form, this is not end-to-end encryption.
Humans do not read your private planning content except as needed to operate or secure the
Service, to investigate abuse or a security incident, to handle a support request you have made,
or as required by law. Authorized personnel and processors receive only the information needed
for those functions.
No method of transmission or storage is completely secure. We cannot guarantee that unauthorized
access, loss, or disclosure will never occur.
12. Your rights and choices
Depending on your location, you may have rights to:
- Access and receive a copy of personal information associated with you;
- Correct inaccurate personal information;
- Delete personal information, subject to lawful exceptions;
- Receive portable information where required;
- Restrict or object to certain processing;
- Withdraw consent for future processing where consent is the legal basis;
- Appeal a denied privacy request where applicable law provides that right;
- Use an authorized agent where applicable law permits it;
- Complain to the data-protection or consumer-protection authority in your jurisdiction.
To request access to or a portable copy of your account-owned planning data, email
help@postmissionplanner.com from the email
address on your account. Provider credentials are not included in an export. To delete your
account, use Settings → Account → Delete Account in the app or email
us. Describe the request and the account involved. We may verify your identity and an agent's
authority before acting. If you are described in another user's contact or relationship records,
contact us and we will evaluate the request while protecting that other user's rights. We will
not discriminate against you for exercising a privacy right.
13. California disclosures
We collect the categories described in Section 2 for the purposes described in Section 5 and
from the sources described in Section 4. We do not sell personal information or share it for
cross-context behavioral advertising. If California law applies, residents may submit applicable
access, correction, deletion, portability, and opt-out requests by emailing us. We do not offer
financial incentives for personal information.
14. International transfers
Information may be stored or processed in the United States and other countries where our
processors operate. When legally required, we use an available transfer mechanism and related
contractual or technical safeguards. The privacy laws of those countries may differ from those in
your location.
15. Website tracking and cookies
We do not serve advertisements, use advertising trackers, or request App Tracking Transparency
permission. The marketing website does not intentionally use advertising or analytics cookies.
Hosting infrastructure may create basic operational and security logs.
16. Children
The Service is intended only for people who are at least 18. We do not knowingly collect personal
information from children. If you believe a child has provided personal information, contact us
so we can investigate and delete it where required.
17. Changes to this policy
We may update this policy and will post the revised version with a new date. Before a material
change applies, we will provide reasonably conspicuous notice and request consent where required.
We will not use previously collected information for a materially incompatible new purpose without
the notice or consent required by law.
18. Contact
Post-Mission Planner is the operator responsible for the information described in this policy.
Privacy questions, requests, or complaints may be sent to
help@postmissionplanner.com.
This section supplements the General Privacy Policy. It applies when a consumer health privacy
law covers a person or information processed through the Service. Post-Mission Planner is a
general planning app, not a healthcare provider. We do not receive medical records from clinics
or labs unless you type that information in yourself.
1. What may count as consumer health data
Information becomes potentially health-related only when you choose to enter, import, or
synchronize it. Depending on what you provide, that may include:
- Physical or mental-health goals, habits, routines, symptoms, appointments, treatments, medications, or related notes;
- Fitness, sleep, nutrition, wellness, or other behavioral activities and reminders;
- Calendar events, locations, contacts, or relationship records that identify or permit an inference about health services or health status;
- Dropped map pins and saved map places, including coordinates and notes you attach, if those notes or associated events describe health services or appointments;
- Other information you enter that identifies, describes, or permits an inference about past, present, or future physical or mental health.
We do not collect medical records from healthcare providers, biometric identifiers, or genetic
data through a dedicated health sensor. The Map feature may process your precise location in
the foreground as described in Section 2; that is not a health sensor and is not used for
advertising.
2. Sources
We receive this information from you and from calendar, reminder, contact, file, or feed
integrations you enable. Another user may also include information about you in that user's
private planning content.
3. How we use it
We use consumer health data only to provide the planning, storage, synchronization, reminder,
integration, security, support, deletion, and legal-compliance functions you request. We do
not use it for advertising, data brokerage, eligibility decisions, profiling unrelated to the
Service, or training generalized artificial-intelligence models. Humans do not read it except
as described in Section 11 of the General Privacy Policy.
4. Disclosure and processors
We do not sell consumer health data. It may be processed by Railway and its associated database
infrastructure to host and secure the Service. It may be sent to Apple, Google, or another
calendar provider when you direct an integration to read or write that content. We may preserve
or disclose information when required by law or reasonably necessary to protect rights, safety,
and Service security.
If Partner Access is active, a partner can see planner-calendar event titles, times, locations, and notes, which may include health-related details you entered there. Google Calendar, Apple device calendars and reminders, and subscribed iCalendar feeds are not shared through Partner Access.
RevenueCat receives purchase and entitlement information and is not intended to receive
calendar, goal, habit, note, contact, or health-related content. Resend receives account email
addresses and the content of account emails, not private planning content.
5. Your choices and rights
You control whether to enter health-related planning content or connect a source that contains
it. Depending on applicable law, you may request access, confirmation, correction, or deletion,
or withdraw consent for future collection or disclosure. You may remove individual content,
disconnect an integration, delete your account through
Settings → Account → Delete Account, or email
help@postmissionplanner.com.
We may need to verify your identity and an authorized agent's authority. If we deny a request,
you may appeal by replying to the decision with "Privacy Appeal" in the subject line. You may
also contact the appropriate consumer-protection authority, including the Washington State
Attorney General where applicable.
6. Changes
We will disclose a new category or a materially different purpose before collecting, using, or
disclosing consumer health data for that purpose, and we will obtain affirmative consent where
the law requires it.
7. Contact
Questions and requests may be sent to
help@postmissionplanner.com.