Privacy Notice
Last updated: 31 August 2026
We collect only what we need, never sell your data, and never show you ads. This notice applies wherever in the world you use Planur, and covers the Planur student app, Planur for Tutors and this website.
1. Who we are
Planur is operated by Planur Ltd, a company registered in England and Wales. We are the data controller (and, where applicable, the “data fiduciary” or “business”) for your personal data — with one important exception for tutors and schools, set out in §11. This notice applies worldwide. Depending on where you live it is governed by your local data-protection law — for example the UK GDPR, the EU GDPR, US federal and state privacy laws (including COPPA and the California CCPA/CPRA), India’s Digital Personal Data Protection Act 2023 (DPDP), Canada’s PIPEDA and Quebec’s Law 25, Brazil’s LGPD and other Latin American laws, African laws such as South Africa’s POPIA and Nigeria’s NDPA, and APAC laws such as Australia’s Privacy Act and Singapore’s PDPA. These are examples; whichever law applies to you, we honour it. For any privacy question, use the contact form on this website.
2. What we collect and why
When you create an account and use the Planur student app:
| Data | Why |
|---|---|
| Email and/or phone number | Sign-in via one-time code |
| Display name, and optionally date of birth / age band, gender, school, year group, subjects | Set up your planner and tailor it to you |
| Your content — timetable, assignments, to-dos, exams, sports fixtures, group-study plans | The core features of the app, and the copy that restores your planner on a new phone (see §6) |
| Your focus sessions and any calendar sources you connect | Kept only on your device. These are never uploaded to us — which also means they do not come back if you move to a new phone. |
| Friends & contacts | If you choose to find friends, contacts are matched as one-way hashes — we never store your raw contacts. Connections and invites you create are stored. |
| Device push token | To send reminders and invites (Firebase Cloud Messaging) |
| Subscription status | To unlock paid plans (via RevenueCat and the app store). We never receive your card details. |
| Country of registration | The country you select when you sign up. Used to apply the correct age and parental-consent rules for you. |
| Approximate location — city and country, derived from your IP address | Shown to you on your own profile as your “last used location”. It is stored only on your device — we do not upload it to our servers, use it for any other purpose, or share it with anyone (including parents). To look up the city name, your device sends your IP address to our geolocation provider (see §6). |
When you sign up as a tutor and run your practice in Planur:
| Data | Why |
|---|---|
| Your email and/or phone number | Sign-in via one-time code |
| Your name, your practice name, and the roles of anyone you add to the practice | To run the practice and apply the correct permissions |
| Your students’ details — name, year, class, and a parent or guardian contact you enter | To build your roster, mark attendance and raise invoices. See §11: for this data you are the controller and we act on your instructions. |
| Batches, sessions, attendance marks, class materials you upload, and practice tests you generate | The core features of the tutor app |
| Fees and invoices you record | To track billing. We do not take payments from parents on your behalf, and we never see their card details. |
| Your subscription status and plan band | To apply your plan’s limits. Tutor plans are billed by Stripe on a page in your browser, not through an app store. We never receive or store your card details. |
| Device push token | To send you app notifications |
What we never send to the AI. When you generate a practice test, the only things that leave Planur are the topic, the subject, the difficulty and the number of questions you typed. No student names, results, attendance, fees, parent contacts or uploaded materials are included — see §5.
On this website, when you join the waitlist or contact us: first name, email, year group and country (waitlist); and your name, email, subject and message (contact form, including tutor enquiries, where we also store the practice details you choose to give us).
We do not collect your precise (GPS) location or your home/postal address, and we do not profile you or show third-party advertising in either app.
3. Legal bases for processing (UK/EU GDPR)
- Providing the app and your account — performance of a contract.
- AI features — when you request a study plan, revision quiz or practice test, the subject/topic details you provide are sent to our AI processing provider(s) (Mistral AI, Groq, Anthropic and Google (Gemini)) to generate it — contract / legitimate interests.
- Reminders & invites (push) — contract / consent.
- Waitlist & enquiries — legitimate interests (Article 6(1)(f)).
- Security, safety & fraud prevention — legitimate interests / legal obligation.
- Running your practice — performance of our contract with you. For the personal data you enter about your students, your own lawful basis as controller applies; see §11.
Where consent is the basis, you can withdraw it at any time.
4. Children
Planur is intended for students aged 13 and over. Across every market we minimise the data we collect, default to high-privacy settings, and do not profile children, serve them targeted advertising, or track them for advertising. We offer a Parent mode for guardian involvement, and we obtain parental consent where the law requires it. Age thresholds differ by country:
- UK & EU/EEA — we follow the UK ICO’s Age Appropriate Design Code (the “Children’s Code”) and equivalent EU rules. The age of digital consent is 13–16 depending on the country; below it we seek verifiable parental consent.
- United States — under the Children’s Online Privacy Protection Act (COPPA) we do not knowingly collect personal data from children under 13 without verifiable parental consent.
- India — under the Digital Personal Data Protection Act 2023, anyone under 18 is a child. We obtain verifiable parental/guardian consent before processing their data, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
- Canada, Brazil and other Latin American countries, Africa, the Asia-Pacific and everywhere else — we apply local requirements (for example Canada’s Law 25, Brazil’s LGPD, South Africa’s POPIA, Australia and Singapore) and, at a minimum, the protections above.
These are examples only — whatever your country’s rules, we follow them. If you are a parent or guardian and believe your child has provided us data without the required consent, contact us and we will delete it.
Connecting a student to a tutor is gated on age. When a join code is entered, we decide on our servers — from the account’s date of birth and the age of consent for that country, never from the app — whether the connection can complete. A parent connects immediately. A student at or over the age of consent connects immediately. A student under it, or with no date of birth on file, is held: nothing about the tutor’s classes or materials is visible until a parent approves through a link they open in any browser. An unknown age is treated as under-age, because that is the safe assumption rather than the convenient one.
5. AI features, and what is never sent
Our AI features generate academic content only. We use providers whose terms exclude using our content to train their models, and we re-check that on a schedule rather than assuming it stays true. If a provider is unavailable, you are told — we do not silently substitute something worse.
- In the student app, a study plan or revision quiz is generated from the subject, topic and exam details you enter. Your friends, your messages and your personal notes are not part of the request.
- In Planur for Tutors, a practice test is generated from four fields: topic, subject, difficulty and number of questions. Nothing about a child is included — not names, results, attendance, fees, parent contacts, or the materials you have uploaded. That is not a policy statement; it is the entire content of the request.
6. How we store and protect your data, and who we share it with
Your data is stored securely in Supabase (EU region), which is GDPR-compliant and SOC 2 Type II certified. Data is encrypted in transit (HTTPS/TLS) and the student app’s on-device database is encrypted at rest (AES-256). Backend access is restricted by authentication and row-level security rules enforced in the database itself. We do not store payment information.
Why we keep a copy, and what comes back. The student app works from a database on your own phone, and each change is also saved to your Planur account. That copy is what your planner is restored from when you sign in on a new phone: your assignments and their sub-steps, exams, AI revision plans and their blocks, timetable and to-dos. It happens by itself, once, on a phone that has no planner on it yet — we never overwrite a planner you are already using. Some things are not restored: your friends list, group sessions and invites have to be set up again; focus history and connected calendar sources never leave your device in the first place; and a photo attached to an assignment stays on the phone that took it, so a restored assignment has no photo. If you delete your account (§9) or it is removed after 24 months of inactivity (§12), there is nothing left to restore from.
Planur in a browser. There is a read-only student view at theplanur.co.uk/app where you can check your timetable, assignments and exam dates. It stores nothing in your browser — no planner, no cached copy of your work — and it cannot change anything: it reads what it needs each time and keeps none of it. The encrypted database described above is on your phone, and that is still the only copy of your planner held on any device. Signing out of the browser therefore leaves nothing behind, which matters if you use a school or library computer.
We do not sell, rent or trade your personal data. We share it only with service providers (sub-processors) acting on our instructions:
- Supabase Inc. — database, authentication and sync (EU servers)
- Google Firebase — push notifications
- AI provider(s) — Mistral AI (EU servers), Groq, Anthropic and Google (Gemini) — to generate study plans, revision quizzes and practice tests. None of them use your prompts or answers to train their models.
- RevenueCat and Google Play / Apple — student app subscriptions and payment
- Stripe — tutor subscriptions and payment. Tutors subscribe on a Stripe-hosted page in a browser rather than through an app store, so Stripe receives the tutor’s name, email address and payment details directly. We never receive or store card details.
- Geolocation provider — ipapi.co (over HTTPS) — receives your IP address to return an approximate (city-level) location, which is then shown only on your own device. It is not given any other data.
- Hosting provider — website and app delivery
7. International data transfers
Because Planur operates globally, your data may be processed in countries other than your own — including the UK, the EU/EEA, the United States and India — for example by our cloud and AI providers. Wherever we transfer data across borders, we use appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses, and equivalent contractual or legal mechanisms recognised under the applicable law of your country.
8. Your rights & regional protections
Whoever and wherever you are, you can access, correct and delete your data, and withdraw consent, using the app or the contact form on this website. We do not sell your personal data or share it for cross-context behavioural advertising. Depending on where you live, you also have these specific rights:
- UK & EU/EEA (GDPR) — access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent. You can complain to the UK ICO or your local EU supervisory authority.
- United States (California & similar state laws) — the right to know, access, delete and correct your data, to data portability, and to opt out of “sale”/“sharing” and certain profiling. We honour these for all US users and do not discriminate against you for exercising them.
- India (DPDP Act 2023) — the right to access, correction and erasure, the right to grievance redressal, and the right to nominate another person to exercise your rights. You may withdraw consent at any time. If we cannot resolve a complaint, you may escalate to the Data Protection Board of India.
- Canada — access and correction rights under PIPEDA (and Quebec’s Law 25), enforced by the Office of the Privacy Commissioner of Canada.
- Brazil & Latin America — under Brazil’s LGPD (and similar laws) you may confirm, access, correct, delete, port and object to processing, via the ANPD.
- Africa — equivalent rights under laws such as South Africa’s POPIA (Information Regulator) and Nigeria’s NDPA.
- Asia-Pacific — equivalent access/correction and complaint rights under local law (for example Australia’s Privacy Act via the OAIC, and Singapore’s PDPA via the PDPC).
- Everywhere else — whatever rights your local data-protection law gives you, you can exercise them with us.
To exercise any right, email our Privacy Contact at support@theplanur.co.uk or use the contact form. We acknowledge within 30 days and complete data-rights requests within one month (extendable by up to two further months for complex requests) — see §13.
If your request concerns a student on a tutor’s roster — for example a parent asking to see or delete what a tutor holds about their child — that data belongs to the practice, not to us. We will pass the request to the tutor and support them in answering it. See §11.
9. Deleting your account and data
You can delete your account and all associated data at any time — in the app via Profile → Delete account, or see theplanur.co.uk/delete-account for full instructions.
You can delete your tutor account and your practice at any time — see theplanur.co.uk/delete-account for what happens to your roster, register, invoices and uploaded materials, and what your students see afterwards.
10. Cookies & tracking
This website uses no tracking cookies, advertising cookies, or third-party analytics (no Google Analytics or similar). Fonts are self-hosted — no requests to Google Fonts or any external font service, and in fact the site makes no external requests at all. Only strictly necessary browser storage is used.
11. Tutors: who controls your students’ data
This is the most important section for a tutor to read, because the answer is not the same for all the data in your account.
- Your own data — your name, email, practice details and subscription. We are the controller. Everything else in this notice applies to it as normal.
- Your students’ data — the names, year groups, parent contacts, attendance marks, fees and results you enter or record. You (your practice) are the controller and we are the processor: we hold and process that data on your instructions, to provide the app to you, and for no purpose of our own. We do not use it to market to your students or their parents, we do not sell it, and we never send it to an AI provider.
Because you are the controller of that data, some responsibilities are yours rather than ours: you need a lawful basis for entering a student’s and a parent’s details into Planur, and the parents you record should know that you use a third-party app to run your teaching. This notice is written so you can point them at it.
What we enforce for you, in the database rather than on screen:
- A tutor never sees a student’s own planner — their homework, revision and private notes. You see the classes you teach and the results of tests you set.
- No practice can read another practice’s data. A student who studies with two tutors cannot carry your batches, materials or fees across to the other.
- Fee data is invisible below the owner tier. A teacher you add to your practice genuinely cannot read it — a separate permission at the database level, not a hidden screen.
- No student account can reach an answer key.
These rules are covered by an automated test suite that runs against the real database before any change ships.
11. Schools: who is responsible for what
This is the public summary. The full Data Processing Agreement — the one your legal team will want, with the Article 28 / DPDP processor terms in full, the sub-processor list as an annex and the security schedule — is signed with you at onboarding. Ask and we will send you the current draft before you commit to anything.
Your school is set up in Planur as a practice — the same structure a tutoring business uses, at school scale. The answer to “who is responsible for this data” is not the same for everything in your account.
- Your school’s own account data — the names and email addresses of the staff who administer the account, and your subscription. We are the controller (“Data Fiduciary” under India’s DPDP Act 2023). The rest of this notice applies to it normally.
- Everything you record about students, guardians and staff — names, classes, guardian contacts, attendance, marks, fees, and staff records such as joining dates, presence and leave. Your school is the controller / Data Fiduciary. We are the processor / Data Processor. We hold and process that data on your documented instructions, to provide the service to you, and for no purpose of our own. We do not market to your students, their parents or your staff, we do not sell it, and we never send it to an AI provider.
What being your processor commits us to
These are the obligations a processor owes a controller under UK/EU GDPR Article 28, and the equivalent duties of a Data Processor under the DPDP Act. Stated here in plain words; stated in full in the agreement.
- Process the data only on your documented instructions, including for any transfer out of your country.
- Keep everyone we allow near it under a duty of confidentiality.
- Apply the security measures described in §6, and keep them appropriate to the risk.
- Not add or change a sub-processor without telling you first — the current list is in §6 — and give you a fair opportunity to object.
- Help you answer requests from a student, parent or employee to access, correct, export or delete their data.
- Tell you without undue delay if there is a personal data breach affecting your data, with what you need in order to notify your regulator — the ICO in the UK, the Data Protection Board of India under DPDP — and, where required, the people affected.
- Help you with a Data Protection Impact Assessment and any prior consultation that follows from it. Most schools will need one before deploying software of this kind; we will give you what we hold.
- At the end of the contract, return or delete the data at your choice. Plan limits never delete what is already there — see §12.
- Make available the information you reasonably need to verify all of the above, and submit to audits on the terms set out in the agreement.
Children
Every student record a school holds is a child’s record, and two things follow.
- India (DPDP Act 2023). Anyone under 18 is a child. Your school obtains the verifiable parental or guardian consent for its own processing — that duty sits with the Data Fiduciary, which is you. We provide the technical controls and the records to support it, and we will not knowingly work around them. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited under the Act; Planur does none of them anywhere in the world.
- UK & EU/EEA. We follow the ICO’s Age Appropriate Design Code and equivalent EU rules, and default to high-privacy settings — see §4.
- The student’s own connection is separately gated. If a student links their personal Planur planner to your school, and they are under the age of digital consent for their country — or we hold no date of birth — they see nothing of your classes until a parent approves. Age is decided on our servers, and an unknown age is treated as under-age.
- Nothing about a child is sent to an AI provider. See §5. A practice paper is generated from the topic, subject, difficulty and question count you type — and nothing else.
Staff records
Where you record employment information — joining dates, daily presence, lateness, leave — we are your processor for that too, on the same terms. Employment records usually have to be kept longer than student records; the retention period is yours to set, not ours, and we will hold them for as long as you instruct.
Sensitive documents: not yet, and please do not. Planur does not currently provide secure storage for caste, income, disability, Aadhaar or other government certificates, and those documents should not be uploaded into class materials, which are ordinary shared files. Secure document storage is a separate planned feature, encrypted with a key your school holds, so that we cannot read the files even if asked to. Until it exists, please keep that paperwork in your own systems.
When records leave us
If you take a year-end export of your records into your own storage, your school becomes their sole custodian from that moment. We can no longer action an erasure or correction request against exported files, because we no longer hold them — that responsibility passes to you, and the agreement says so explicitly.
What we enforce in the database, not on a screen
- No school can read another school’s data. A student who also studies elsewhere cannot carry your classes, materials or fees across.
- Fee and staff data are permission-gated. A class teacher cannot read the fee ledger or another member of staff’s leave record — a separate permission at the database level, not a hidden screen.
- Students keep a planner of their own. You see the classes you teach and the results of tests you set. Their homework, revision and private notes stay theirs.
- No student account can reach an answer key.
These rules are covered by an automated test suite that runs against the real database before any change ships.
Where your data is held, and transfers. See §6 and §7. Data is stored in Supabase’s EU region; where data crosses a border we rely on the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or the equivalent mechanism recognised by the law that applies to you.
12. How long we keep your data
- Account & app data — kept while your account is active; deleted when you delete your account, and deleted or anonymised after 24 months of inactivity.
- Account & school data — kept while your account is active, and deleted when you delete it. A school account that goes completely unused is removed after 36 months rather than the 24 that applies elsewhere, because a school's year is longer than anyone else's. Before anything is removed we extract your records and return them to you, and we will have warned you well before the deadline. If you must retain records for a statutory period beyond that, tell us in writing and we will hold them.
- Practice data — your roster, register, invoices and uploaded materials are kept for as long as your practice exists, including if you drop to a free plan or stop paying: plan limits stop you adding, they never delete what is already there. It is removed when you delete the practice.
- Staff and employment records — kept for as long as your school instructs. Employment law in your country usually requires longer than student records; that period is yours to set and we follow it.
- Waitlist signups — kept until you have had the chance to create an account, or until you request deletion.
- Contact messages — up to 12 months after your enquiry is resolved, then deleted.
When an account is deleted we keep only a one-way hash of your email/phone (a deletion record with no readable personal data) and records we are legally required to retain (e.g. billing records held by the app stores).
13. Contact, complaints, and changes
For any privacy question, to exercise your rights, or to raise a complaint, contact our Privacy Contact, A Chandel — email support@theplanur.co.uk — or use the contact form. If you are in India, the same person is our Grievance Officer under the DPDP Act 2023 and can be reached at the same address.
How quickly we respond. We acknowledge every privacy request or complaint within 30 days. Where you are exercising a data-protection right (such as access, correction, erasure or portability), we complete it within one month, and may extend this by up to a further two months (three months in total) for complex or numerous requests — we will always tell you within the first month if we need the extra time. Other complaints are resolved as soon as reasonably practicable.
You also have the right to complain to your data-protection regulator, including: the UK ICO; your EU/EEA supervisory authority; the relevant US state Attorney General (e.g. California); the Data Protection Board of India; Canada’s OPC; Brazil’s ANPD; South Africa’s Information Regulator; Australia’s OAIC; Singapore’s PDPC; or your local data-protection authority wherever you live.
We may update this notice as Planur develops. If we make material changes we will update the date at the top and, where appropriate, notify you.