Privacy Policy
Last updated: 12 July 2026
PlainWeek is a local-first planner: your tasks are plain markdown files on your own device, and the free app needs no account and sends us nothing. This policy explains the limited personal data we process when you choose to use the optional paid sync service, why we process it, and the rights you have under the General Data Protection Regulation (GDPR).
The short version.
• The free app is entirely on your device. No account, no tracking, no telemetry.
• If you turn on paid sync, we store the vault files you sync so we can deliver them back to your other devices. We do not sell your data, use it for advertising, or use it to train AI. Content reaches Google Calendar, an ICS feed recipient, or a push vendor only when you choose the relevant optional feature.
• Payments are handled by Paddle (our Merchant of Record). We never see your card.
• You can export (you already have your files locally) or delete your account at any time. Deletion removes live synced data immediately; residual version copies are removed within 30 days for text and 14 days for attachments. Legally required billing records remain for their statutory retention period.
1. Who is responsible for your data
The data controller is:
Mario El Hawat (EI) — SIREN 106 798 366, RCS Paris — trading as PlainWeek, published by Fab Garden.
Data-protection contact: privacy@plainweek.app.
2. What we collect and why
The free local app collects nothing. Everything below applies only if you create an account for paid sync or connect an optional integration.
Account data
When you sign up we store your email address (kept in plain text as your account identity) and, if you use a password, a one-way argon2id hash of it — never the password itself. If you sign in with Google instead, we store your Google account identifier and email. We use this to create and secure your account and to contact you about the service.
Your synced vault content
If you enable paid sync, the markdown files in your vault (your tasks, notes, dates, and any attachments) are uploaded so we can synchronise them across your devices, keep a short version history, and power the calendar and reminder features. We store this to provide the sync service to you and for no other purpose.
Sync, calendar-outbox, and token records
To operate sync, we keep device and connector sync-token records. The Cloudflare Durable Object called the calendar outbox also processes task titles and times so we can send calendar updates. These records are used only to provide sync and the optional calendar features.
Google Calendar (optional)
If you connect Google Calendar, we request the
calendar.events and openid email scopes. We store a
Google refresh token, encrypted at rest (AES-256-GCM), plus which calendar
you chose. We sync events two ways: your Google events are copied into your vault, and your
planned tasks are written to your Google Calendar. You can disconnect at any time, which
revokes and deletes the stored token.
Reminders (optional)
If you enable web-push reminders, we store your browser’s push subscription (an endpoint URL and its encryption keys) so we can deliver reminders at your chosen times.
Billing data
Payments run through Paddle, the seller and our Merchant of Record. Paddle collects and holds your payment details; PlainWeek never sees or stores your card data. Paddle holds the transaction, invoice, tax, and accounting records. We store only opaque billing identifiers Paddle returns (a customer id, a subscription id), your subscription status, and the current period end, so we know whether your account is entitled to premium features.
Technical & security data
To keep accounts secure we log, with each login session, the IP address and browser user-agent used, and we use your IP address transiently to rate-limit sign-in and abuse attempts. We keep an operational heartbeat of background jobs (aggregate counts only, no personal data).
3. Important disclosures
Some things about how sync works deserve to be said plainly:
- Your synced files are stored unencrypted on our infrastructure. Sync is not end-to-end encrypted. Your uploaded vault content is held in readable form on Cloudflare so we can serve it back to your devices and run calendar/reminder features. “Local-first” means the source of truth stays on your device — it does not mean the synced copy is encrypted. If you need end-to-end encryption, keep your vault local or use your own encrypted sync (for example Syncthing).
- Deleting a note does not erase its history instantly. We keep a short version history so you can roll back: up to the last 50 versions or 30 days for text, and the last 10 versions or 14 days for attachments. Earlier or deleted bytes are removed by a background sweep after that window.
- The calendar (ICS) feed URL is a secret link. Your subscribe URL contains a random token; anyone who has that URL can read the task titles and times in your feed. Keep it private and regenerate it if it leaks.
- Reminders carry your task text. A push reminder includes the task’s title and time, delivered through your browser or operating-system vendor’s push service (for example Google, Mozilla, Apple, or Microsoft).
4. Legal bases (GDPR Article 6)
| Data / purpose | Legal basis |
|---|---|
| Account, sync, calendar, reminders — delivering the service you signed up for | Performance of a contract (Art. 6(1)(b)) |
| Connecting Google Calendar; enabling push reminders | Your consent (Art. 6(1)(a)), withdrawable at any time |
| PlainWeek’s minimal billing entitlement records (customer/subscription identifiers, status, current period end) | Performance of a contract (Art. 6(1)(b)) and our legitimate interest in managing access and disputes (Art. 6(1)(f)) |
| Paddle’s transaction, invoice, tax, and accounting records as seller and Merchant of Record | Paddle’s independent legal obligations and contractual relationship with the buyer; PlainWeek does not hold Paddle’s tax or accounting records |
| Security logging (session IP/user-agent), rate limiting, abuse prevention | Legitimate interests in securing the service (Art. 6(1)(f)) |
5. Processors and other recipients
We use a small set of providers. Their role matters: Cloudflare acts on our instructions as a processor, while Paddle and Google act as separate or independent controllers for the optional data they receive. Browser and operating-system push vendors act as independent controllers or, depending on the vendor and arrangement, as processors for delivering the push reminder you enabled.
| Provider | Role | Status |
|---|---|---|
| Cloudflare, Inc. (USA) | Hosting & all storage: compute, database, file storage for synced vaults | Processor — live |
| Paddle.com Market Limited (UK) | Merchant of Record: payment processing, invoicing, tax | Independent controller — live for paid plans |
| Google LLC (USA) | Calendar sync & Google sign-in — only if you connect it | Separate controller — optional |
| Browser/OS push services: Google, Mozilla, Apple, Microsoft | Delivering push reminders — only if you enable them | Independent controllers or, depending on the vendor and arrangement, processors — optional |
PlainWeek sends no data to any AI provider today. If you enable Bring-Your-Own-Model (BYOM), your browser sends your prompts directly to the provider you choose — Anthropic or OpenRouter — using a key stored only on your device. This is a transfer you initiate directly, not through PlainWeek’s servers, and is governed by that provider’s own terms and privacy policy.
6. International transfers
| Recipient | Location and transfer safeguard |
|---|---|
| Cloudflare, Inc. (processor) | USA — EU–US Data Privacy Framework certification and/or Standard Contractual Clauses (SCCs). |
| Google LLC (optional separate controller) | USA — EU–US Data Privacy Framework certification and/or SCCs. |
| Paddle.com Market Limited (independent controller) | United Kingdom — covered by the European Union’s UK adequacy decision. |
| Browser/OS push services (Google, Mozilla, Apple, Microsoft) — optional | The relevant vendor may process the push subscription and reminder delivery outside the EEA. Any transfer is governed by that vendor’s applicable adequacy decision, EU–US Data Privacy Framework certification, and/or Standard Contractual Clauses, as applicable to the vendor and arrangement. |
These are appropriate safeguards for the transfers described above. Copies of the SCCs are available on request at privacy@plainweek.app.
7. How long we keep your data
- Account and synced content: for as long as your account is open. When you delete your account, your live synced data is purged immediately, and any residual version-history copies are removed within 30 days for text and 14 days for attachments.
- Version history: up to 50 versions / 30 days (text) or 10 versions / 14 days (attachments), then swept.
- Security logs (session IP/user-agent): for the life of the session, removed when the session expires, you log out, or you delete your account.
- Google refresh token: until you disconnect Google Calendar or delete your account.
- Push subscription: until you disable reminders or delete your account.
- Cloudflare calendar-outbox task data: while the calendar feature is enabled, or until you delete your account.
- Device and connector sync-token records: until you revoke them or delete your account.
- ICS feed token: until you regenerate or disable it, or delete your account.
- Analytics aggregates: no longer than 13 months.
- Billing records: Paddle, as seller and Merchant of Record, keeps the invoice and accounting records for the statutory accounting period (generally about 10 years where French law requires it). PlainWeek keeps its opaque entitlement identifiers only while your account is active, plus a short reconciliation window.
An email address and credentials are required to use paid sync. If you do not provide them, you cannot use paid sync; the free local app remains available. To obtain a copy of relevant SCCs, email privacy@plainweek.app.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (“right to be forgotten”);
- receive your data in a portable format — in practice your vault already lives as plain markdown files you hold;
- restrict or object to certain processing;
- withdraw any consent you gave (for example for Google or push), without affecting past processing;
- lodge a complaint with a supervisory authority (see section 15).
You can delete your account from within the app at any time. That removes live synced data immediately; residual version copies are removed within 30 days for text and 14 days for attachments, while legally required billing records remain for their statutory period. For any other request, email privacy@plainweek.app; we respond within one month.
9. Security
We protect data in transit with HTTPS. Passwords are hashed with argon2id. Session, device, and connector tokens are stored as SHA-256 hashes. Only the Google refresh token is encrypted at rest, using AES-256-GCM. We also rate-limit authentication. No system is perfectly secure, but we design to minimise what we hold and to fail safely. Because your vault is yours and lives on your device, you should keep your own backups; server-side version history is a convenience, not a backup.
10. Analytics & cookies
The PlainWeek app uses no analytics and no advertising cookies. We use
self-hosted Umami, a cookieless audience-measurement tool, only on the
/welcome marketing and checkout pages. It does not use cross-site tracking
and is configured to qualify for the CNIL consent exemption for audience measurement.
The IP address is hashed and truncated at collection; this is pseudonymised data, not fully
anonymised data. Umami is never used in the app or on these legal pages. We retain
aggregate statistics for no longer than 13 months. Our lawful basis is our legitimate
interest in measuring aggregate audience (GDPR Art. 6(1)(f)). You may object to this
processing at any time by emailing
privacy@plainweek.app.
The only cookies set by the service are strictly necessary paid-sync session cookies:
-
Name:
__Host-session; purpose: keep you signed in to paid sync; lifetime: until logout or session expiry. -
Name:
__Host-csrf; purpose: security — protects your signed-in session against request forgery; lifetime: same as the session cookie. -
Name:
__Host-google-oauth; purpose: transient security binding used only while you complete Google sign-in; lifetime: minutes (deleted when sign-in completes or fails).
11. Special-category data
PlainWeek does not solicit, require, or intentionally process special-category data, such as health information, beliefs, or similar sensitive information. We cannot pre-screen the contents of your notes, and you are responsible for what you choose to sync. If you do not want sensitive data processed on our servers, keep it in a local-only, unsynced vault. If you choose to sync such content, we process it solely to provide the sync service you requested, and you must ensure that you have a lawful basis to store it.
12. Children
PlainWeek is not directed at children. A paid subscription requires that you are 18 or that a parent or guardian enters into it. For optional processing based on consent, the minimum age in France is 15; below that age, parental consent is required. The free local app has no minimum age because it does not require an account or send data to us.
13. What deletion cannot remove
Deleting your PlainWeek account cannot delete records held by independent controllers: Paddle’s transaction records, events already written to your Google Calendar, push notifications already delivered, or copies held by anyone who saved your ICS feed link. Those records are governed by their own controllers’ policies. To limit further sharing, disconnect and revoke PlainWeek’s Google access, regenerate or disable your ICS feed token, disable push reminders, and contact Paddle about its transaction records.
14. Changes to this policy
We may update this policy as the service evolves or the law changes. Before any new or materially different processing purpose, recipient, or international transfer, we give you prior notice. Where the new processing relies on consent, we obtain fresh consent. We will post the new version here with an updated date and, for material changes affecting your rights or an active subscription, notify you by email or in the app.
15. Contact & complaints
Questions or requests about your personal data: privacy@plainweek.app.
If you believe we have mishandled your data, you have the right to complain to your local data-protection authority. In France this is the CNIL — www.cnil.fr. Contacting PlainWeek first is optional: you may complain directly to the CNIL or the supervisory authority of your residence, workplace, or place of the alleged infringement.