Privacy Policy
Last updated: July 10, 2026
PlanItShare (planitshare.app) is operated by Miltos Vafiadis, an individual based in Greece, as an independent, non-corporate project. This policy explains what personal data the app collects, why, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Who controls your data
The data controller is Miltos Vafiadis, resident in Greece, contactable at privacy@planitshare.app or by post at Paralia Fourkas, Halkidiki 63077, Greece. Because PlanItShare is run by an individual rather than a company, this is also the person legally responsible for how your data is handled. The lead supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, dpa.gr).
2. Information we collect
- Account data: email address, display name, and password (stored and hashed by our authentication provider, Supabase — we never see your plaintext password).
- Trip and expense data you enter directly: trip names, dates, itinerary items, locations, expense amounts, currencies, categories, and notes.
- Confirmation emails you forward or paste in: the raw content of booking confirmations (flights, hotels, activities), which may include other travelers' names if they appear in the email.
- Group and invitation data: who you invite to a trip, and the email address you invite them at.
- Preferences: language, currency, date format, and theme, stored in a cookie and, once signed in, against your account.
- Technical data: IP address and basic request logs, kept only as long as needed for security and abuse prevention (e.g. bot protection on signup and comment forms).
3. Why we process your data
We process your account, trip, and expense data because it's necessary to provide the service you've signed up for (GDPR Art. 6(1)(b), contract performance). We process technical/security data (like bot-protection checks) under our legitimate interest in keeping the service usable and abuse-free (Art. 6(1)(f)). Where we ask for explicit consent — for example, before an anonymous visitor's browser session is used to let them track their own pending blog comment — we rely on Art. 6(1)(a).
4. AI-assisted email parsing
When you forward or paste a confirmation email into the app, its content is sent to Anthropic's Claude API to automatically extract structured trip details (dates, locations, confirmation numbers) so we don't make you re-type them. Anthropic acts as our data processor for this specific purpose under a data processing agreement.
- Anthropic's API does not use data submitted through the API to train its models (unlike consumer chat products).
- Anthropic retains API inputs only briefly for abuse and safety monitoring, then deletes them, per its own API terms.
- This processing happens outside the EEA (Anthropic's infrastructure is US-based); it's covered by Standard Contractual Clauses as the transfer safeguard.
- The email content you forward or paste is used only to extract your trip details — never to train or fine-tune any model on our behalf, and never shared with other PlanItShare users beyond the trip data you choose to keep.
5. Sharing with other users
PlanItShare is built around shared trips. Once you add a plan or expense to a trip, the other members of that trip can see it — that's core to how the app works, not an incidental disclosure. Don't add anything to a shared trip that you wouldn't want your travel companions to see.
6. Service providers we use
- Supabase — database, authentication, and file storage.
- Anthropic (Claude API) — parsing of forwarded/pasted confirmation emails (see §4).
- Resend — transactional email (invitations, password resets, confirmations).
- Cloudflare Turnstile — bot/abuse protection on signup and comment forms.
- Mapbox — map rendering for itinerary locations.
Each of these providers only receives the data needed to perform its specific function and is contractually restricted from using it for its own purposes.
7. International data transfers
Some of the providers listed above may process data outside the European Economic Area, most notably Anthropic (United States). Where that happens, the transfer is covered by Standard Contractual Clauses or an equivalent safeguard recognized under GDPR Chapter V.
8. Data retention
We keep your account and trip data for as long as your account is active. Forwarded emails that couldn't be automatically filed remain in your personal "unfiled" inbox until you file or dismiss them. Audit log entries for sensitive actions (expense edits/deletes, role changes, invitations) are retained for accountability purposes even if the underlying record is later changed. There's currently no self-service "delete my account" control — to close your account, email us (§14) and we'll process it manually. Trips and data that are entirely yours are deleted outright once we confirm the request with you. If you've contributed expenses or plans to a trip shared with others, we may need to ask you to first reassign or remove those specific records, since deleting them outright would corrupt other members' shared expense history; we can't bypass that for your own request any more than for anyone else's. Once deletion is complete, your personal data is removed except where we're required to keep it (e.g. financial records subject to a legal retention period, or audit trail entries about actions you took while a member of someone else's trip).
9. Security
Access to your data is enforced at the database level through row-level security policies scoped to your account, not just application-level checks. Traffic to the app is encrypted in transit. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, proportionate measures for an application of this size.
10. Your rights
Under GDPR, you have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. You can already update your profile details and preferences directly from your account settings. For access, export, deletion, restriction, or objection requests, email us — see §14 — and we'll handle it manually; we aim to respond within a month, as GDPR requires. You also have the right to lodge a complaint with the Hellenic Data Protection Authority, or with the supervisory authority in your own EU country of residence.
11. Cookies and local storage
We use a single first-party cookie to remember your language, currency, date format, and theme preferences, plus your authentication session. We don't use third-party advertising or tracking cookies.
12. Children's privacy
PlanItShare isn't directed at children, and we don't knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we'll remove it.
13. Changes to this policy
If this policy changes materially — for example, a new category of data we collect, a new recipient we share it with, or a new purpose we use it for — we'll update the date at the top of this page and email registered users at least 30 days before the change takes effect. Continuing to use PlanItShare after that date counts as accepting the update; if you'd rather not, you can delete your account before the change takes effect (see §8).
14. Contact us
Questions or requests about your data: privacy@planitshare.app.