Privacy Policy
Last updated: 25 August 2026
This Privacy Policy explains how Codeaamy FZCO ("Planout", "we", "us") collects, uses, shares, and protects your information when you use the Planout mobile application and website (the "Service"). By using the Service, you agree to the practices described here.
The short version
We collect what the app needs to work: your account, the groups and plans you take part in, and — only if you connect one — when you are busy on your calendar. Your group sees that you are busy, never what you are busy with. We do not sell your data, and you can ask us to delete your account and everything attached to it at any time.
This summary is here for speed. The numbered sections below are the policy.
On this page
- 1. Who we are
- 2. Information we collect
- 3. Permissions we ask for
- 4. Your calendar
- 5. Groups & visibility
- 6. How we use it
- 7. Legal bases
- 8. How we share it
- 9. Third-party services
- 10. Where data is processed
- 11. Data retention
- 12. Deleting your account
- 13. Security
- 14. Your rights
- 15. Children
- 16. Automated decisions
- 17. Changes
- 18. Contact
1. Who we are
Planout is operated by Codeaamy FZCO, a company registered in Dubai, United Arab Emirates, together with its affiliate Codeaamy Private Limited in India (together "Codeaamy", "we", "us"). Codeaamy FZCO is the controller of your personal data. Codeaamy Private Limited provides engineering, infrastructure and support services to Codeaamy FZCO and processes personal data only on its instructions.
Where this policy gives you a right or asks you to contact us, you can use the single contact address at the end and it will reach whichever entity is responsible.
2. Information we collect
Information you provide
- Account details — your name, phone number and/or email, and profile photo.
- Profile & preferences — bio, status, time zone, interests, and availability/schedule you set.
- Content you create — groups, events, itineraries, messages, and shared expenses.
Information collected with your permission
- Contacts — if you allow it, we access your contacts to help you find friends already using Planout. We do not upload your entire address book without your action.
- Calendar — if you connect a calendar, we access availability information to help schedule plans.
- Notifications — a device token so we can send you push notifications.
Information collected automatically
- Usage & device data — app interactions, device type, operating system, and diagnostic/crash data used to keep the Service working.
3. Permissions the app asks for
Every permission below is optional and requested only at the point you use the feature that needs it. Declining one stops that feature working; it does not stop you using Planout. You can change your mind at any time in your device settings, and on Android you can also revoke a permission there after granting it.
- Notifications — so we can tell you when someone RSVPs, a plan changes, an expense is added, or a reminder is due. Reminders are also scheduled on your device so they still fire without a network connection, which is why Planout asks Android for permission to run after a restart: it rebuilds those pending reminders.
- Contacts — to show which of your contacts already use Planout, and to let you pick a number when adding someone to a plan or an expense. Contact details stay on your device unless you yourself add a specific person to a plan. We do not upload your address book.
- Camera and photo library — only so you can set a picture for a group or a plan. We access what you pick, not your library.
- Google Calendar — optional and separate from signing in. See Your calendar below for exactly what it does.
- Network access — required for the app to work at all.
Planout does not ask for your location, your microphone, your call logs, your SMS messages, or access to other apps on your device.
4. Your calendar
Connecting a calendar is optional, and it is a separate decision from signing in — nothing is read until you make it. This section is the plain-English version of what that permission does. It adds to the rest of this policy rather than replacing it.
What Planout reads
The times you are busy or free on the calendar you connect, and the events on the dedicated "Planout" calendar the app creates for you. Planout asks for Google's full calendar permission rather than the narrower events-only one because it creates and colours that separate calendar, and creating a calendar is a calendar-management operation.
What other people can see
Whether you are free or busy on a slot. That is the whole of it. Event titles, guests, locations and descriptions are never shown to anyone else in your group — they appear only in your own calendar view, inside the app.
What Planout writes
Only when you RSVP "going". The plan is added to the separate Planout calendar, so it never mixes with your own entries, and changing your RSVP takes it off again.
How to disconnect
Profile, then Disconnect calendar. Access is revoked with Google immediately and Planout stops reading anything. You can also revoke it yourself at myaccount.google.com/permissions. Your plans stay in the app either way.
5. Groups, and what other people can see
Planout is a group product, so some of what you do is visible to the other people in a group by design. It is worth being precise about which.
- Other members of a group can see your display name and profile photo, the plans in that group, your RSVP, messages and suggestions you post, expenses you add or are part of, balances between members, and your availability as busy or free.
- They cannot see your email address or phone number unless you have shared it yourself, your contacts, your calendar event titles or details, or anything from groups they are not in.
- Group owners and admins can add and remove members and delete group content. Adding someone to a group or a single event makes the group's content visible to them from that point.
- Content you post stays with the group. If you leave a group or delete your account, messages and expenses you contributed may remain visible to the remaining members, because removing them would rewrite a shared record other people rely on — a settled bill, for instance. Your name is masked on that content once your account is closed.
6. How we use your information
- To create and manage your account and provide the Service;
- To coordinate plans — matching availability, forming groups, sharing itineraries, and splitting expenses;
- To send you invites, reminders, and updates via notifications;
- To keep the Service secure and prevent abuse; and
- To fix problems and improve features.
We do not sell your personal information.
7. Legal bases for processing
If you are in the European Economic Area or the United Kingdom, the UK GDPR and the EU GDPR require us to have a lawful basis for each use of your personal data. Ours are:
- Performance of a contract — creating and running your account, showing you your groups and plans, splitting expenses, and delivering the Service you asked for.
- Consent — connecting your calendar, access to your contacts, camera and photos, and push notifications. You can withdraw consent at any time by revoking the permission in your device settings or disconnecting your calendar in the app. Withdrawing it does not affect processing already carried out.
- Legitimate interests — keeping the Service secure, preventing abuse and fraud, diagnosing crashes, and understanding in aggregate which features are used so we can improve them. We balance these against your rights, and you can object (see Your rights).
- Legal obligation — keeping transaction records where tax or accounting law requires it, and responding to lawful requests.
8. How we share your information
- With people you choose — your name, photo, availability, and the plans you create are shared with the group members and contacts you interact with, as part of using the Service.
- With service providers — trusted vendors who process data on our behalf to run the Service (see below).
- For legal reasons — where required by law, to protect our rights, or to prevent harm.
9. Third-party services
We use the following providers, each with its own privacy policy:
- Google Firebase — authentication, database (Cloud Firestore), storage, and push messaging.
- Google Sign-In and Apple Sign-In — for logging in.
- Calendar providers you connect — to read availability.
10. Where your data is processed
Planout runs on Google Cloud and Firebase infrastructure and your data may be processed in the United States, the European Union, India or the United Arab Emirates depending on the service and the region it is provisioned in. Our engineering and support team in India may access personal data to operate and support the Service.
Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with our providers' own transfer frameworks, to give your data a level of protection equivalent to that in your home country. You can ask us for details of the safeguards used.
11. Data retention
We keep your information for as long as your account is active or as needed to provide the Service. When you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain it to comply with legal obligations. Note that content already shared with other users (for example, a group plan) may remain visible to them.
12. Deleting your account and your data
You can close your account at any time from Profile in the app, or by emailing us from the address on your account. You do not have to give a reason.
When you close your account:
- Your profile is closed immediately and your name and photo are masked everywhere they appeared. You stop receiving notifications and you are removed from group membership.
- Your personal data is deleted from our live systems within 30 days, and from encrypted backups within 90 days, after which backups holding it have expired on their normal rotation.
- Shared group content you contributed — messages, expenses and the balances calculated from them — may remain visible to the other members of that group, with your name masked, because it forms part of a shared record they rely on. If you need that content removed too, ask us and we will work through it with the group.
- We keep the minimum needed for legal reasons — records of purchases for tax and accounting, and a note that an account was closed so it is not recreated in error.
- Deleting the app does not delete your account. Purchases are managed by Apple or Google and are cancelled in your store account, not here.
Disconnecting your calendar is separate and immediate: see Your calendar.
13. Security
We use industry-standard measures, including encryption in transit and access controls, to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
14. Your rights
Wherever you live, you can ask us to do all of the following, and we will not charge you or treat you differently for asking:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct anything inaccurate or incomplete.
- Erasure — have your account and personal data deleted, as described in Deleting your account.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format, or have us send it to another provider where technically feasible.
- Objection — object to processing we carry out on the basis of our legitimate interests.
- Withdraw consent — for your calendar, contacts, camera, photos or notifications, at any time, without affecting processing already carried out.
Email us at support@codeaamy.com from the address on your account. We respond to requests within 30 days. We may ask you to confirm your identity first, so that nobody else can make a request about you.
If you are in the EEA or the UK and you think we have handled your data badly, you can complain to your local data protection authority. We would rather you told us first, so we have a chance to put it right.
15. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal data, please contact us and we will delete it.
If you are under 18, you may only use the Service with the involvement and consent of a parent or legal guardian, as set out in our Terms & Conditions.
Child safety. We have a zero-tolerance policy on child sexual abuse and exploitation (CSAE). Anyone can report it — from the app, by pressing and holding the message or opening the image, group or itinerary stop concerned, or by emailing support@codeaamy.com with "Child safety" in the subject line. We remove the content, permanently close the account responsible, preserve the evidence for law enforcement, and report to the competent authority — including NCMEC where the United States is involved. These disclosures are made to comply with a legal obligation or to protect someone's vital interests. Our published Child Safety Standards explain all of this in full.
16. Automated decisions
Planout does not make decisions about you that produce legal or similarly significant effects using automated processing alone, and it does not profile you for advertising. It does suggest times and places based on the availability and preferences in your group, which you are free to ignore.
17. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above and, for material changes, notify you in the app where appropriate.
18. Contact & data deletion
For any privacy question, or to make any of the requests above, contact us. The controller of your personal data is Codeaamy FZCO; our India affiliate processes it on our instructions.
Codeaamy FZCO — controller
Email: support@codeaamy.com
Address: Dubai - UAE
Phone: +971 52 391 7447
Codeaamy Private Limited — processor, India
Reachable through the same address above.