Key Information Summary
PlanToCode keeps desktop workspace state on your computer and uses online services for account access, mobile relay, billing, notifications, and user-requested AI features. This policy explains those data flows and the legal bases that may apply. Contact Email to exercise your privacy rights.
Introduction and Scope
This Privacy Policy describes how helpful bits GmbH ("we," "us," or "our") collects, uses, and shares your personal information when you use PlanToCode Desktop, the PlanToCode mobile apps, the PlanToCode browser extension, the website, and related services.
Controller and Processor Roles
helpful bits GmbH is the controller for PlanToCode account, website, billing, security, support, and direct customer-relationship processing:
helpful bits GmbHSüdliche Münchner Straße 55
82031 Grünwald, Germany
Email: Email
For a business customer's project or end-user content, helpful bits GmbH may instead act as a processor where an executed agreement assigns those roles. The role depends on the data flow and agreement; publication of the DPA page alone does not execute that agreement.
Data Protection Contact: For data protection inquiries, please contact our Data Protection Contact at Email.
Country-Level Availability Controls
PlanToCode availability varies by product surface, deployment, app-store territory, and payment configuration. At service and website edges, we may infer a country code from your network IP address to apply product-availability and security rules. App Store, Google Play, Microsoft Store, and payment providers may apply their own territory settings.
Purpose and limits: Country-level IP geolocation is used to decide whether a configured service or download is available and to protect the Service from abuse. It does not establish your identity, residence, citizenship, or sanctions status, and it is not restricted-party screening.
Access decisions: A configured edge may deny a request when the inferred country is unavailable or unknown. The request still passes through network infrastructure and may appear in ordinary security or access logs. Because IP geolocation can be inaccurate, contact us if you believe an availability decision is wrong.
Retention: Country codes and source IP addresses are retained with the relevant infrastructure or security logs only for as long as those logs are needed for operation, security, dispute handling, or legal obligations. The applicable period depends on the deployed service and is not a fixed universal period.
Definitions
- Personal Data: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on personal data, including collection, storage, use, or deletion
- Data Subject: The natural person to whom personal data relates
- Controller: The entity that determines the purposes and means of processing personal data
Data Categories We Collect
- Account and Authentication Data: Email address, profile name when supplied by the identity provider, account and device identifiers, authentication tokens, and session metadata. Auth0 and enabled identity providers handle the sign-in flow; PlanToCode does not ask for your identity-provider password.
- Billing Data: Stripe customer and transaction records for prepaid credits, Google Play purchase tokens used for Android entitlement verification, and StoreKit subscription state processed by the iOS app. Apple and Google handle mobile payment-card details.
- AI Interaction Data: Prompts, requested project content, files, diffs, attachments, command output, dictated audio or text, browser results, review recordings, and generated responses processed to complete the action you request
- Browser Extension Data: Tab URLs, tab titles, search queries, search results, page text, iframe content, visible page screenshots, extracted Markdown, DOM/accessibility metadata, interactive element labels, and local file upload metadata such as file names and counts when you ask PlanToCode to use the browser extension
- Mobile Device Data: App version, device model, trusted-device identifiers, APNs or Firebase Cloud Messaging tokens, subscription state, dictated audio, and user-initiated Review Mode recordings
- Website Data: Requests and access logs; interaction events sent to PlanToCode's acknowledgement endpoint; and, only after cookie acceptance when configured, Google Analytics and X advertising-pixel data
Desktop Application Data
PlanToCode Desktop stores workspace state, session links, command output, settings, and diagnostic error records locally. During a run, Codex and enabled tools may read project files or command output needed for your request and send relevant content to the configured provider under your approval and sandbox settings. Installing or opening PlanToCode does not by itself upload an entire repository. Local diagnostics are not application telemetry; they leave the device only if you choose to share them or a requested workflow includes them.
Legal Basis for Processing
We process your personal data based on the following legal bases under Article 6 of the GDPR:
- Consent (Art. 6(1)(a) GDPR): For optional website analytics or advertising scripts, promotional communications, and other non-essential storage or access
- Contract Performance (Art. 6(1)(b) GDPR): For service provision, account management, processing payments, and fulfilling our contractual obligations
- Legitimate Interests (Art. 6(1)(f) GDPR): For security measures, fraud prevention, service improvement, and protecting our systems and users
- Legal Obligation (Art. 6(1)(c) GDPR): For tax compliance, regulatory requirements, and other legal obligations
Where we rely on legitimate interests, the relevant assessment considers the purpose, necessity, impact on individuals, and available safeguards. You may object as described below.
Desktop Application
PlanToCode Desktop combines local workspace storage with network services used for sign-in, updates, mobile relay, and user-requested provider operations:
- Local Data Storage: Workspace sessions, command output, local settings, and application diagnostics are stored on your computer
- Requested Runs: Codex and enabled tools may inspect and transmit the prompts, project content, command output, attachments, or browser results needed to complete your request
- Service Metadata: Account, device, app-version, network, relay, update, and security metadata may be sent when the related online feature is used
- Aggregate Request Telemetry:When an allowlisted online operation uses PlanToCode's servers, the server reduces the request to a count by fixed operation, outcome, latency range, binary release, and server region. Authentication, billing, device-management, support, consent, webhook, unknown, and catch-all routes are excluded. The rollups do not contain an account, device, installation, session, IP address, user agent, request path, request content, or free-form property. These are request counts, not counts of people or completed workflows.
- No Client App-Interaction Telemetry: The checked desktop and mobile releases do not send screen taps, local navigation, local diagnostics, crash reports, or onboarding events to a general app-interaction analytics pipeline.
Local Data: Project files remain on your computer unless a run or tool reads them for an action you requested. Session history and settings remain local unless you send or expose them through a requested relay, browser, support, or provider operation.
Data Transmission: Provider content is determined by the requested task, the files and tools used during the run, and the active provider configuration. Review approvals and generated changes before accepting them.
Browser Extension
PlanToCode Browser Bridge connects Chrome to the local PlanToCode desktop app through Chrome native messaging. The extension acts only on commands from the local desktop bridge.
- Browser tasks: When you ask PlanToCode to use Chrome, the extension may open or reuse tabs, open Google Search results, extract page text, inspect page controls, click, type, scroll, select options, set checkbox/radio/switch state, attach user-requested local files to web forms, take visible page screenshots, and close extension-created tabs.
- Browser data: Requested browser tasks may process tab URLs, tab titles, search queries, search result content, visible page text, iframe content, extracted Markdown, screenshots, DOM/accessibility metadata, labels or placeholders for form controls, and local file upload metadata such as file names and counts. Files that you ask PlanToCode to attach to a web form may be sent to that website by Chrome as part of the requested browser task.
- Sensitive content on requested pages: Page content and screenshots can incidentally contain personally identifiable information, health information, financial or payment information, authentication information, personal communications, user-generated content, or location information. The browser bridge processes such content only as part of the browser task you request; it is not used for advertising, credit decisions, or an unrelated purpose.
- Cookies: The extension does not request cookie permissions and does not export cookies. Markdown extraction does not intentionally include current form input values, but screenshots and visible page content may include sensitive data shown on the page.
- Local storage: Chrome local storage holds connection status, metadata-only command, result, and cleanup summaries, and records for extension-created tabs and dedicated windows. Extracted page content, screenshots, and full browser command results are not retained in Chrome local storage.
- Local bridge: The extension communicates with the PlanToCode native messaging host on the same computer. Browser command results are returned to PlanToCode Desktop, may appear in the run timeline, and may be included in agent context sent to your configured AI provider to complete the browser task you requested.
- Limited use: Browser data is used to provide the requested browser bridge feature, support the service, protect security, or comply with legal obligations. We do not sell browser data or use it for personalized advertising. The extension is designed so browser access starts with a command from the local PlanToCode bridge.
Mobile Apps
The PlanToCode Android and iOS apps are companion controls for desktop-owned sessions. They use native screens for project selection, workspace chat, files, diffs, settings, notifications, subscriptions, dictation, and Review Mode.
- Workspace content: Prompts, queued follow-ups, selected files, diffs, attachments, dictated text, and generated AI responses may be sent to PlanToCode services, the selected desktop, and configured AI providers only for the action you request.
- Notifications: iOS uses Apple Push Notification service tokens and Android uses Firebase Cloud Messaging tokens to route enabled notifications to the signed-in device.
- Subscriptions: Apple processes iOS subscription purchases and the iOS app reads StoreKit entitlement state. Google Play processes Android subscriptions and PlanToCode sends purchase tokens to Google Play for entitlement verification.
- Connected-workspace preview: After the first successful desktop RPC, PlanToCode stores non-reversible keyed identity digests with preview start and expiry timestamps in one shared account-control database. The digests are derived separately from the verified provider subject and normalized account email; PlanToCode does not store those raw values or a regional account ID. This minimal eligibility record remains while the preview program operates, including after account deletion, to prevent repeated claims.
- Dictation and Review Mode: Microphone audio is collected only after you start dictation or Review Mode. Screen media is collected only after you start Review Mode or choose media for analysis. The app uses the relevant system permission prompts and sends the recording for the requested transcription or analysis.
- AI-output reports: The mobile apps may let you send the project or session, prompt, generated output, and your explanation to support for review.
Sharing and Processors
We use third-party services to provide specific parts of PlanToCode. We do not sell personal data. Optional website analytics and advertising scripts may disclose browser and event data to their providers after you accept optional cookies; see “Cookies and Tracking” below. Service providers include:
- Auth0: Account authentication and identity-provider routing
- Stripe: Website and desktop payment processing and billing management
- Apple: iOS subscription processing and Apple Push Notification service delivery
- Microsoft Store: Windows desktop application distribution and updates
- Google Play: Android subscription processing and purchase-token verification
- Firebase Cloud Messaging: Android push notification delivery
- AI Service Providers: OpenAI, Anthropic, Google AI, xAI, and OpenRouter (depending on the selected feature and provider configuration)
- Website measurement and attribution: Google Analytics and the X pixel when configured and accepted
- Hosting, edge delivery, traffic security, and email: Hetzner, InterServer, Cloudflare, Amazon Web Services, and Mailgun where the related deployment or communication path uses them. Cloudflare currently proxies public website and API traffic and may process IP addresses, request metadata, URLs, country-routing signals, and content in transit.
- Help and feedback: Featurebase when you open the hosted support or feedback portal
For the public list of supported providers and links to their policies, visit our subprocessors page.
Third-Party AI Providers
When you use AI features in our application, your prompts and associated data may be processed by third-party AI service providers. Important details about AI data processing:
- Provider settings: Data use and retention depend on the provider, feature, account type, and active configuration. Where PlanToCode controls the provider configuration, we use available controls that limit training or secondary use. Settings controlled by your own provider account remain your responsibility.
- Task content: A requested operation may send prompts, files, command output, browser results, audio, video, or other context needed to complete that operation; it is not limited to text manually pasted into a prompt.
- Provider retention: Providers may retain content or security logs under their own terms and configuration. Review the linked policies and the current subprocessor page before sending sensitive material.
AI Provider Privacy Policies
- OpenAI: Privacy Policy
- Anthropic: Privacy Policy
- Google Gemini: Privacy Policy
- OpenRouter: Privacy Policy
- xAI: Privacy Policy
For the complete and current list of AI providers we work with, please check our subprocessors page.
International Transfers
Personal data may be processed outside the European Economic Area when a selected provider operates there. Processing locations and transfer mechanisms vary by feature, account, provider, and contract. Any adequacy decision, Standard Contractual Clauses, UK addendum, transfer-impact assessment, or supplementary measure that we rely on must be identified in the applicable executed customer or provider agreement.
For the current public list of providers, their purposes, and policy links, visit our subprocessors page.
Data Retention Periods
Retention: There is no single retention period for every PlanToCode data flow. Current behavior is:
- Desktop workspace data: Stored locally until you delete the related session, project data, local database, or application data. Codex may maintain its own local session files under its configured data directory.
- PlanToCode account data: Kept while the account is active. The account-deletion flow removes the user record and associated PlanToCode database records that are configured to cascade with it.
- Billing records: PlanToCode database billing rows are removed with account deletion, but Stripe, Apple, Google, banks, or tax records may remain under their own retention rules or where accounting, dispute, fraud-prevention, or legal obligations require them.
- Provider content: Retention of prompts, outputs, audio, video, files, and security logs depends on the provider, account type, and configuration used for the requested operation.
- Browser bridge data: Full extracted content and screenshots are not retained in Chrome extension local storage. Results may remain in the related local run or provider context until you delete that data under the applicable product controls.
- Website data: Access and security logs follow the deployed infrastructure policy. Optional analytics or advertising data follows the configured provider and consent settings.
- Aggregate request telemetry: Identifier-free hourly server operation, outcome, and latency counters are kept for up to 25 months. General reporting aggregates them by day and suppresses cells below 25 requests. The threshold is not a distinct-user count or an anonymity guarantee. Deleted live rows may remain in rolling infrastructure backups for up to seven additional days.
Retention criteria: Where a fixed period is not implemented, we consider the purpose of the data, account state, user deletion actions, security needs, legal obligations, disputes, applicable limitation periods, and processor-controlled retention. Contact us for the current period that applies to a particular server-side record.
Security Measures
We use technical and organizational measures intended to protect personal data. Current source and deployment configuration support the following concrete controls:
- Transport security: Supported production service configurations use HTTPS and WSS; the checked Nginx configuration permits TLS 1.2 and TLS 1.3.
- Authentication and authorization: Auth0-backed account access, authenticated relay connections, and server-side authorization boundaries protect account and device operations.
- Local storage: Desktop workspace records and diagnostics are kept in the local application data store. Mobile release settings exclude token-bearing storage from ordinary backup or device transfer where implemented.
- Selective secret protection: Sensitive tokens and configured secrets use the platform or application protection implemented for that field. We do not claim that every local or server-side field is encrypted with one universal algorithm.
- Data minimization: Mobile apps do not request GPS location, contacts, advertising identifiers, or payment-card details for the current product flows.
No method of electronic transmission or storage is completely secure. Security controls vary by platform, deployment, and processor, and we do not guarantee absolute security.
Your Rights
Under the GDPR and other applicable data protection laws, you have the following rights regarding your personal data:
- Right of Access: Obtain information about processing of your personal data and receive a copy of your data
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure: Request deletion of personal data ("right to be forgotten") under certain circumstances
- Right to Restriction of Processing: Restrict processing in certain situations
- Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct advertising purposes
- Right to Withdraw Consent: Withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal
- Right to Lodge a Complaint: Lodge a complaint with a supervisory authority if you believe your rights have been violated
- Rights Related to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you
How to Exercise Your Rights
Contact us at Email with your request. We will respond within one month of receiving your request, as required by GDPR Article 12(3). In complex cases, this period may be extended by two additional months.
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority. In Germany, you may contact:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)Promenade 18
91522 Ansbach, Germany
Email: Email
Detailed Legal Basis for Processing
We process your personal data only when we have a valid legal basis under Article 6 of the GDPR:
| Processing Activity | Data Categories | Legal Basis |
|---|---|---|
| Account creation and management | Email, username, authentication data | Contract performance (Art. 6(1)(b)) |
| Payment processing | Billing data, transaction records | Contract performance (Art. 6(1)(b)) |
| AI service provision | Prompts, workflow data | Contract performance (Art. 6(1)(b)) |
| Requested browser bridge tasks | Browser extension data, run data, command results | Contract performance (Art. 6(1)(b)); legitimate interests for security and abuse prevention (Art. 6(1)(f)) |
| Security and fraud prevention | IP addresses, access logs | Legitimate interests (Art. 6(1)(f)) |
| Analytics (when enabled) | Usage data, performance metrics | Consent (Art. 6(1)(a)) |
| Service reliability | Allowlisted server requests reduced to identifier-free aggregate operation, outcome, and latency counters | Contract performance (Art. 6(1)(b)); legitimate interests in service reliability (Art. 6(1)(f)) |
| Tax and legal compliance | Transaction records, billing data | Legal obligation (Art. 6(1)(c)) |
Cookies and Tracking
The website stores a cookie named plantocode_cookie_consent for up to 365 days to remember whether you accepted or rejected optional cookies. When the corresponding environment identifiers are configured, Google Analytics and the X advertising pixel load only after the cookie records acceptance.
- Consent choice: The banner offers Accept and Reject controls and does not preselect acceptance.
- PlanToCode interaction endpoint: Some page actions send an event name, page URL, referrer, screen width, time zone, and language to a PlanToCode endpoint. The current endpoint validates and acknowledges the event but does not forward or persist the request body as an analytics record.
- Optional providers: If accepted and configured, Google Analytics receives measurement events and the X pixel may receive browser or conversion-attribution data under those providers' policies.
- Withdraw or reject: Select Reject when the banner appears. If you previously accepted, clear the
plantocode_cookie_consentcookie and related provider cookies in your browser, reload the page, and select Reject.
Types of Cookies We Use
- Preference: The PlanToCode consent-choice cookie
- Authentication and security: Cookies used by sign-in, billing, or security flows when you use those website functions
- Analytics: Google Analytics when configured and accepted
- Advertising attribution: The X pixel when configured and accepted
Children's Privacy
The Service is not intended for anyone under 18 years of age, and we do not knowingly offer accounts to children. If you believe a child provided personal information through PlanToCode, contact us. We will investigate and delete or otherwise handle the information as required by applicable law.
Changes to This Policy
We may update this privacy policy to reflect changes in our practices, technology, or legal requirements. We will post the updated version with a revised effective date and provide any additional notice required by applicable law.
Contact Us
If you have any questions about this privacy policy or our data practices, please contact us at Email. You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
Data Breach Notification
We will handle personal data breaches under applicable notification requirements. Under the GDPR, notification to the competent supervisory authority is made without undue delay and, where feasible, within 72 hours when the breach is likely to result in a risk to individuals. Affected individuals are notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms.