Release details
Current published document
- Version
- 1
- Published
- August 23, 2026
- Effective
- August 23, 2026
Retention and Deletion Information
Effective date: 21 August 2026
This page explains Planique's current retention periods and deletion process. It supplements the Privacy Notice. Planique is operated by Cropol Labs d.o.o., Ulica sv. Ane 30A, 31000 Osijek, Croatia, company number 030322161.
1. Core rules
- Planique does not keep private-vault content merely because it may be useful in the future.
- Cancelling a subscription does not delete the account or private content.
- Completing a deletion removes the selected information from ordinary use in live Planique systems.
- Related Planique-created calculations, reminders, Calendar projections, search entries, temporary copies and known files follow deletion of their source record.
- Encrypted database backups are used for disaster recovery, not ordinary processing.
- A documented legal hold may pause deletion only for the narrow information needed for a binding duty, investigation or actual or reasonably anticipated claim. The hold must have a reason, scope, owner, review date and end condition.
2. Current retention schedule
| Information | Retention | End-of-period action |
|---|---|---|
| Account and ordinary profile information | While the account is open and during controlled deletion | Delete active authentication and profile identifiers, subject to the limited records below. |
| Private-vault records and files | Until the user deletes the record, profile, relevant module or account, or the inactive-account process completes | Delete source records, linked files and related Planique-created information and prevent recreation from deleted sources. |
| Health content | Until record or profile deletion, Health deactivation, account deletion or inactive-account closure | Health deactivation deletes all Health profiles and Health information, including cycle history and estimates, files, reminders and related Calendar entries, from live systems. |
| Ordinary subscription and entitlement state | Account lifetime plus 24 months after account deletion or the last entitlement event, whichever is later | Delete ordinary aliases, webhook and state information; retain only any required accounting or dispute evidence. |
| Accounting, invoice, tax and settlement evidence | 11 years after the end of the relevant financial year, or longer where a specific binding rule or hold requires it | Delete the separated statutory record when the period and any hold end. |
| Support correspondence | 2 years after ticket closure | Delete messages and attachments; a genuine dispute subset moves to the claim schedule. |
| Ordinary privacy-rights request record | 3 years after closure | Delete request metadata and correspondence. Planique does not retain the delivered vault export in the case record. |
| Identity or authority evidence collected for a request | Only as long as necessary and normally no later than 30 days after verification or case closure | Delete source documents and retain only a minimized method, result and date where needed. |
| Privacy or misuse source evidence | Only as long as necessary and normally no later than 30 days after verification or case closure | Delete restricted source copies unless a documented legal hold applies. |
| Minimized ordinary privacy or misuse case | 3 years after closure | Delete the case record; a genuine claim subset follows the claim schedule. |
| Escalated dispute or legal claim | 5 years after final closure, subject to applicable limitation rules and annual review | Delete when the period and any documented hold end. |
| Security or privacy incident case | 6 years after closure, subject to annual review | Delete the case; routine copied logs are removed earlier unless evidentially necessary. |
| Prepared data-copy archive | Up to 48 hours after approval or readiness; immediately if replaced or cancelled | Delete the stored archive. Each generated download URL lasts about 60 seconds. |
| Terms, Privacy Notice and 18+ evidence | 5 years after supersession or account deletion, whichever is later | Delete minimized version, action, time and language evidence. No vault content is stored in it. |
| Private Vault Terms, household declaration, Health or cycle activation and withdrawal evidence | 5 years after supersession, deactivation, purpose end or account deletion, whichever is later | Delete minimized version, scope, action and deletion-result evidence. |
| Deleted-account audit outcome | 180 days after the deletion request | Delete the HMAC-minimized outcome through bounded maintenance. |
| Routine security, Auth, API, database, server-function and operational logs | 7 days | Rolling deletion. These logs must not contain private free text or vault payloads. |
| Notification scheduling and delivery records | While needed for delivery, then 7 days after completion or failure | Bounded maintenance deletes the operational records. They contain no private-vault content. |
| Push installation or token | While active; revoked or invalid history for 30 days | Disable immediately, cancel pending jobs and delete the unreferenced token row after 30 days. |
| Detailed RevenueCat subscription event | 30 days after successful handling; unresolved events remain only until resolved and then for 30 days | Remove detailed event data and retain only subscription, accounting and deletion evidence still needed. |
| Vercel contact-form transit | Only while needed to route the inquiry; no durable Vercel form-submission store | Route the minimum non-sensitive fields to the controlled destination. Runtime and security logs use the shortest production period available for the selected service configuration and must not contain the form body. |
| Expo push receipt | Expo's current service period, normally no more than 24 hours | Planique does not rely on the receipt as an archive. The payload is generic. |
| APNs or FCM queued generic notification | Until the job expiry supplied by Planique, capped at 28 days | The provider discards the queued message at expiry. No private content is included. |
| Residual encrypted database backup | Designed to expire within 7 days | The backup is overwritten or expires. If restored, recorded deletion instructions are reapplied before ordinary service resumes. |
| Deleted user-owned Storage object | No separate Planique recovery copy unless a later public schedule expressly says otherwise | Delete through the Storage API. Database backups contain object metadata, not the deleted file itself. |
3. Data-copy archives remain on their own schedule
A data-copy archive that was already prepared remains protected by the authenticated export controls and expires under the separate 48-hour export schedule, even if the source account, module, profile or record is deleted during that period. It is not converted into an email attachment or permanent link. Planique deletes it sooner if the export is replaced or cancelled.
Deleting source information does not make an already delivered copy disappear from the user's device or a destination the user selected. The user controls that copy after download or sharing.
4. Inactive accounts
Planique records one server-generated timestamp for the latest successful authenticated account activity. It does not keep a behavioral history of screens, actions or private-vault content for this purpose.
After 24 consecutive months without recorded activity, Planique may begin a manual inactive-account process. The Privacy Officer normally sends warnings approximately 60 and 30 days before planned deletion. Opening Planique while signed in and online, or contacting us to keep the account, cancels the process.
Immediately before deletion, the Privacy Officer manually rechecks activity, subscription status, open privacy requests, complaints, incidents, disputes, legal holds and warning delivery. Any uncertainty pauses deletion. Eligible accounts are deleted through the controlled storage-first account-deletion process. There is no automatic deletion based only on the timestamp or a candidate report.
5. Your deletion choices
Delete a record or profile. Deleting a record removes related Planique-created information. Deleting a Health profile also removes that profile's Health records, reminders, Calendar entries, files and related calculations from live systems.
Turn off cycle estimates. This deletes estimated dates and related reminders. Period history and other user-entered Health records remain.
Deactivate Health. This deletes all Health profiles and information saved in Health, including cycle history and estimates, files, reminders and related Calendar entries, from live systems. It does not delete the Planique account or other modules.
Delete the account. This deletes the active account, profile and private-vault information across modules and known private files, cancels relevant automation and starts necessary provider deletion. A minimized deleted-account outcome remains for 180 days. Required accounting, legal or claim information may remain separately for its stated purpose.
6. Backups and restoration
Active-system deletion does not selectively edit an already-created encrypted database backup. Residual database copies may remain until the seven-day backup period ends. They are access-restricted and not used for ordinary processing. If a database backup is restored, Planique must reapply recorded deletion instructions before ordinary service resumes.
Supabase database backups contain Storage metadata but not the actual objects held through the Storage API. Planique therefore deletes user-owned files through the Storage API and does not describe the database backup as a file recovery copy.
7. Contact
Use the relevant in-app control, contact support, or write to planique.planner@gmail.com. Do not send Health records, identity documents, passwords or a private-vault export through the contact form or ordinary email.