Last updated 5 October 2026
Planerah stores the account you create and the study data you put into it: your courses, tasks, deadlines, commitments and the plans it makes for you. We use it to run the planner and to make Planerah better. We don't sell it, we don't advertise against it, and we share it only with the services needed to run the app. You can delete your account, and everything in it, from Settings at any time.
Planerah is run by Parsa Soleiman Garmabaki, a private individual in Sweden, who is the data controller for the personal data described here. For anything in this policy, write to [email protected].
Your account
Your name, email address (and a new address while you are confirming a change), time zone and chosen accent color. If you set a password we store a bcrypt hash of it, never the password itself. Email verification codes are stored hashed and expire.
Signing in with Google
If you use "Continue with Google" we receive your Google account identifier, email
address and name, and store them to recognise you on your next visit. Planerah
requests only the openid,
email and
profile scopes. It has no access to your
Gmail, Drive, Google Calendar, contacts or anything else in your Google account, and
cannot act on your behalf.
What you put into the app
Courses, tasks, deadlines, study sessions, recurring commitments, study habits, your answers to the setup questions, and the plans Planerah generates for you. Each time a plan is generated we also keep a record of the input it was built from and any warnings it produced, so that we can find and fix mistakes in the planner. All of this stays associated with your account.
Canvas, if you connect it
Connecting Canvas stores the access token you provide (encrypted), your Canvas user ID, which school's Canvas you use, and the courses imported from it. Planerah reads your course list and nothing else. Disconnecting deletes the token; the imported courses stay in your account as ordinary courses, which you can edit or delete.
Timetable feeds, if you add them
If you add a TimeEdit or other calendar feed, we store its address (encrypted) and the events imported from it, such as lectures with their times, rooms and course codes. Feed addresses can identify you or your study programme, which is why they are encrypted. Removing a feed deletes the events imported from it.
Technical records
While you are signed in, your session record includes your IP address and browser details. Our servers also keep logs that include IP addresses. IP addresses are used to rate-limit sign-in, registration and calendar-feed requests, which is what stops someone guessing passwords or overloading the service.
If you delete your account
Before deleting, we ask why you are leaving. Answering is optional. Your answer is stored without your name, email or any link to your account, so it cannot be traced back to you.
Where we rely on legitimate interest, you can object at any time (see "Your rights"). We don't use your data for advertising, we don't sell it, and we don't use it to train AI models.
Account emails: verification codes, password resets, and security notices such as a changed password or a newly linked Google account. Occasionally, a request for feedback. No newsletters and no marketing.
Only cookies the site needs to work, which is why there is no cookie banner:
XSRF-TOKEN cookie that protects forms against forged requests from other sites;sf-theme cookie that remembers whether you chose light or dark, so the right one shows on first load.Cloudflare, which protects the site, may set a short-lived security cookie to tell people from bots. There are no advertising or analytics cookies.
If you subscribe to your Planerah calendar from Google Calendar, Apple Calendar or Outlook, the feed URL contains a long random token and is the only credential protecting it. Anyone who has that URL can read the schedule it exports, without signing in — that is how calendar subscriptions work everywhere. Treat it like a password, and rotate or disable it in Settings if you have shared it by accident.
Only the services that make the app work, and only for that purpose:
Cloudflare, Mailgun and Google are companies based in the United States. Where your data may leave the EU through them, the transfer is covered by the safeguards they provide, such as the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. Inside Planerah, access to the production database is limited to the people who run the service.
We do not sell personal data, and we do not share it for advertising. We will disclose data to authorities only where the law requires it.
Under the GDPR you can ask for a copy of your data, ask us to correct it, delete it, or restrict how we use it, ask for it in a portable format, and object to uses based on our legitimate interest. Account deletion is available directly in Settings. For anything else, write to [email protected]. We will answer within one month.
If you think we handle your data wrongly, please tell us first so we can fix it. You also have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se) or the data protection authority where you live.
Traffic is encrypted in transit with TLS. Passwords are stored as bcrypt hashes. Canvas tokens, timetable feed addresses and calendar export tokens are encrypted in the database. No system is perfectly secure; if a breach affects your data, we will tell you and, where required, the supervisory authority.
Planerah is for people aged 16 and over. If you are under 16, please don't create an account. If we learn that someone under 16 has an account, we will delete it.
If this policy changes materially we will update the date at the top and tell signed-in users before the change takes effect.