Account data
When you create an account we store your name, email address, and a password hash through Supabase Auth. Profile details such as plan, timezone, and working hours stay in your PlanMyHours database and are shown in Account Settings.
Workspace data
Workspaces, projects, notes, and time entries are visible to members of that workspace. Row level security limits each signed-in person to workspaces they belong to.
Calendars
Google Calendar connect is optional and uses a separate OAuth client from sign-in. Calendar tokens are stored so PlanMyHours can list and sync events for that workspace. You can disconnect a calendar from the workspace.
Cookies
Sign-in sets an httpOnly session cookie on the PlanMyHours domain. The cookie is used to call the API. It is not available to page scripts.
Contact
Questions about this policy can go to privacy@planmyhours.com or through the contact page.