Privacy Policy
At Preplani, we respect your privacy and are committed to protecting your personal data. This policy explains what data we collect, why we collect it, and your rights under the EU General Data Protection Regulation (GDPR) and applicable Belgian law.
1. Data Controller
Preplani is operated as an independent service. For all data-related enquiries, please contact us at privacy@preplani.com. We are based in Belgium and subject to Belgian and EU data protection law.
2. Data We Collect
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, encrypted password | Provided by you at registration |
| Content data | Goals, study plans, chapters, checklist items, notes | Created by you inside the app |
| Uploaded files | PDF, EPUB, MOBI files submitted for AI extraction | Uploaded by you |
| Usage data | Pages visited, features used, timestamps of actions | Automatically collected |
| Technical data | IP address, browser type, device type, operating system | Automatically collected |
| Preference data | Theme preference (light/dark/auto) stored in localStorage |
Stored locally in your browser |
We do not collect sensitive personal data (e.g. health information, financial details, political opinions) and ask that you do not include such data in your notes or goals.
3. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)) — Processing your account data and content data is necessary to provide the Preplani service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — We process usage and technical data to maintain service security, detect abuse, and improve performance. Our legitimate interest does not override your fundamental rights and freedoms.
- Consent (Art. 6(1)(a)) — Where we process data for purposes beyond service delivery (e.g. product analytics), we will obtain your explicit consent first. You may withdraw consent at any time without affecting prior processing.
- Legal obligation (Art. 6(1)(c)) — We may retain certain data to comply with Belgian/EU legal requirements.
4. How We Use Your Data
- Service delivery — Creating and managing your account, storing your goals, plans, chapters, and notes.
- AI processing — Files and URLs you submit are sent to third-party AI providers (Groq, Google Gemini, or Anthropic) solely to extract structured content for your study plans. We do not use your content to train models.
- Security & fraud prevention — Monitoring for unauthorised access, abuse, or misuse of the platform.
- Service improvement — Aggregated, anonymised analytics to understand which features are used and where the product can be improved.
- Transactional communications — Password reset emails and other account notifications via Devise.
5. Third-Party Data Processors
We share minimal data with carefully selected processors who act under our instructions and are bound by data processing agreements:
- Groq, Inc. — AI inference (llama-3.3-70b-versatile). File content is transmitted for extraction and not retained by Groq beyond the request.
- Google (Gemini API) — Fallback AI provider. PDFs may be sent as inline data per Google's API terms.
- Anthropic, PBC — Fallback AI provider. Content is transmitted per Anthropic's API usage policy.
- Hosting provider — Our infrastructure provider processes technical and content data to run the service.
We do not sell your data to any third party.
6. Data Retention
| Data type | Retention period |
|---|---|
| Account & content data | Until you delete your account, then permanently erased within 30 days |
| Uploaded files (PDF, EPUB, MOBI) | Processed and discarded immediately after AI extraction; not stored on our servers |
| Server access logs (IP, timestamps) | 30 days, then automatically purged |
| Email interest list (Premium waitlist) | Until you unsubscribe or request deletion |
7. Cookies & Local Storage
We use a minimal set of tracking technologies:
- Session cookie — A strictly necessary, server-set cookie that keeps you logged in. It expires when you sign out or close your browser.
- CSRF token cookie — A security cookie required by Rails to prevent cross-site request forgery attacks.
-
localStorage (theme preference) — We store your chosen colour theme
(light/dark/auto) in your browser's
localStorage. This never leaves your device and contains no personal data.
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics scripts (e.g. Google Analytics) at this time. If this changes, this policy will be updated and consent will be requested where required.
8. Data Security
We implement appropriate technical and organisational measures to protect your data, including password hashing (bcrypt via Devise), HTTPS-only transport, CSRF protection, and parameterised database queries to prevent injection attacks. No method of transmission or storage is 100% secure; we encourage you to use a strong, unique password.
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access (Art. 15) — Request a copy of all personal data we hold about you.
- Right to rectification (Art. 16) — Correct inaccurate or incomplete data via your account settings, or by contacting us.
- Right to erasure (Art. 17) — Delete your account and all associated data at any time via Settings → Delete Account. We will erase your data within 30 days.
- Right to restriction (Art. 18) — Request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20) — Request an export of your data in a machine-readable format.
- Right to object (Art. 21) — Object to processing based on legitimate interests (e.g. analytics). We will stop unless we can demonstrate compelling grounds.
- Right to withdraw consent — Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any right, email privacy@preplani.com. We will respond within 30 days. You also have the right to lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).
10. International Data Transfers
Some of our AI providers (Groq, Google, Anthropic) are based in the United States. When your content is sent to these providers for AI extraction, it may be processed outside the EU/EEA. We rely on the EU Standard Contractual Clauses (SCCs) and/or applicable adequacy decisions as the legal transfer mechanism.
11. Children's Privacy
Preplani is not directed at children under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be notified by email to registered users at least 14 days before they take effect. The "Last updated" date at the top of this page will always reflect the most recent version.