Privacy Policy

Version 1.5 | Effective August 2026

Priority Planner is a local-first productivity app. Your planner data is never collected, transmitted, or stored by us — with three explicit exceptions: the optional Push Notification Alarms feature described in Section 3, the optional Debug Reports feature described in Section 4, and the optional Early Access Lifetime Verification feature described in Section 5. All three require your deliberate action to activate, and all three can be fully disabled so that no data ever leaves your device.

Core Philosophy: Your tasks, notes, and calendar data never pass through our servers. All data processing occurs on your local device. Every feature that does use our server is off by default — none of them activate on a new install. Each one requires you to explicitly turn it on in Settings, and each can be turned off again at any time. Server-held data is never used for advertising, profiling, or any purpose beyond delivering the specific feature you enabled.

1. Where Your Data Lives

Your planner content — including tasks, notes, categories, routines, weekly reviews, weekly wins, and app settings — is written exclusively to your device's local storage (localStorage). You are the sole custodian of this data. We do not host, receive, or have any access to it.

Exports (CSV and PDF) are generated entirely on-device and saved directly to your device's file system. No export data passes through our servers.

2. Google Integrations (Calendar & Drive)

Priority Planner offers optional connections to Google Calendar and Google Drive. Both are authorized via Google OAuth. The OAuth authorization handshake is routed through our Railway server as required by Google's redirect URI requirements — however, no data is logged, read, or stored on that server during this process. Once authorization is complete, all calendar and Drive data flows directly between your browser and Google's APIs.

Priority Planner's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

Google Calendar

Google Drive Backup

Our servers: The app is hosted on Railway solely to serve the static app file. Railway never processes, sees, or stores any of your Google account data, calendar events, Drive files, or credentials.

Google's policy: Google's own privacy policy governs how Google handles your data within their systems. We recommend reviewing it at policies.google.com/privacy.

3. Push Notification Alarms (Optional — Off by Default)

Priority Planner includes an optional push notification alarm feature that delivers on-time alerts for your tasks — even when the app is closed. This feature is off by default on every new install. It requires our server to hold a small amount of data temporarily, and it will never activate unless you explicitly enable it in Settings. If you do not enable push notifications, nothing described in this section is ever sent to or stored on our server.

What is stored on the server

When you enable push notifications, the following is stored in our Railway-hosted PostgreSQL database:

How this data is used

The server checks for due alarms every minute and sends a push notification to your device when one is ready. That is the only purpose this data serves. It is never used for advertising, analytics, profiling, or any purpose other than delivering your alarm at the scheduled time.

Deletion — alarms are removed after delivery

Each alarm record is permanently deleted from the database immediately after the push notification is successfully delivered to your device. Alarms are not retained once fired. If a delivery attempt fails due to a temporary network issue, the record is retried on the next minute's check and then deleted on success. If your push subscription has expired or been revoked, the entire device record and all associated alarms are automatically removed from the database.

Opting out and disabling push alarms entirely

You are in full control. You can disable push notification alarms at any time in Settings. When you do, the app sends a deletion request to the server that permanently removes your device UUID, push subscription, and all pending alarm records from the database. After that point, the server holds no data whatsoever for your device.

4. Debug Reports (Optional — User-Initiated Only)

Priority Planner includes an optional "Debug Report" feature in Settings to help diagnose technical problems. This is entirely user-initiated — it does not run automatically, and no data leaves your device unless you manually trigger it. It is the only other circumstance in which any information reaches us.

When you choose to send a debug report, the following is included:

What is never included in a debug report: task text, notes content, category names, routine details, calendar events, or any other content you have entered into the app. All personal content is stripped and replaced with placeholders before the report is assembled.

Debug reports are sent to priorityplanner2026@gmail.com via your device's email app. This information is used solely to diagnose and fix technical issues and will never be sold, shared with third parties, or used for any other purpose.

5. Early Access Lifetime Verification (Optional — Off by Default)

Priority Planner offers a Lifetime Access program for early supporters. This feature is off by default and will never contact our server unless you explicitly enable it in Settings and enter your access code. If you do not turn this on, no data related to this feature ever leaves your device.

How it works

When you enable this feature and enter your access code, the app sends a single verification request to our server to confirm that your code is valid. This is also repeated periodically in the background (at most once per app session) to keep your access status current — for example, after reinstalling the app or restoring from a backup.

What is sent to the server

What is stored on the server

Our server's lifetime access database stores the following for each issued access code:

No task data, planner content, or personal information is ever included in or associated with these records.

How this data is used

This data is used solely to verify that your lifetime access code is valid and has not been used by anyone else. It is never used for advertising, analytics, profiling, or any purpose other than confirming your access status.

Offline access

If the verification server is unreachable (for example, you are offline), the app falls back to a locally cached verification flag stored on your device. Your access is never revoked simply because a network check could not complete.

Disabling lifetime access verification

You can disable this feature at any time by toggling it off in Settings. When disabled, no verification requests are made and no data is sent to the server. Your access code remains saved locally so you can re-enable it later without re-entering the code.

6. Third-Party Services

Priority Planner is designed to be tracking-free. There are no analytics packages, advertising scripts, tracking pixels, or cookies in the app.

The following minor external connections occur during normal use:

7. Data Security

Because your planner data lives entirely on your own device, its security depends on your device's own protections. All communication between the app and Google's APIs (Calendar and Drive), and between the app and our alarm server, is transmitted over HTTPS using modern encryption. Push notification payloads are additionally encrypted end-to-end using the Web Push standard before leaving our server. We recommend:

8. Children's Privacy

Priority Planner is not directed toward children under the age of 13. We do not knowingly collect any personal information from children.

9. Changes to This Policy

Any changes to this policy will be reflected in an updated version number and effective date at the top of this document.

10. Contact

Questions about this privacy policy or how the app handles data can be directed to: priorityplanner2026@gmail.com