Privacy
Updated 16 September 2026
When you share a project from Plano, the Plano app on your Mac sends it to the plano.sh server. This page says what that server keeps, where, for how long, who can read it, and how you delete it. Everything you don't share stays on your Mac.
What the server stores
Two things, and nothing else:
- Your account. Your GitHub user ID, login, display name, and avatar address, as GitHub reports them when you sign in. For each Mac you sign in from, the server keeps the Mac's name and a one-way hash of the token it gave that Mac. The token itself is never stored, and neither is your GitHub token.
- The projects you share. The plans, their blocks and revisions, the board, and the records, as the app sends them. Each project is its own file.
The server's logs record what kind of request came in, which project and account it was for, its size, how long it took, and how it ended. They never record a token, a login, a display name, or anything you wrote. Logs are kept for two weeks.
Where it is stored
On one server in Hetzner's data center in Falkenstein, Germany, on an encrypted disk. Backups go to one encrypted storage bucket in the same location.
How long it is kept
A project stays on the server until its owner deletes it. After that, copies remain in the backups for up to thirty days and are then removed for good.
Who can read it
The members of a project, and the two people who look after the server: Miguel Carvalho, who runs it, and Pedro Gonçalves, who can open it when Miguel can't. Nobody else. The server doesn't sell, share, or analyze your data.
How deletion works
When the owner deletes a project in Plano, the server removes it at once. The backups age out within thirty days, after which no copy remains.