Privacy Policy
In effect since
Who we are
Throughplan is provided by GRIIND s. r. o., Mierová 1099/66, 064 01 Stará Ľubovňa, Slovakia, company ID 53 821 173, VAT ID SK2121505331, registered in the Commercial Register of the District Court Prešov, section Sro, file no. 42298/P. In this policy, “we” and “us” mean that company.
We are the controller of the personal data described in this policy. We have not appointed a data protection officer; for anything about your data, write to info@throughplan.com.
What this policy covers
Throughplan is a tool for planning software projects: it draws wireframes and writes technical specifications. It consists of our website, the web app, the desktop app and the cloud service behind them.
This policy covers the data we handle to run your account and the service. The content an organization stores in its projects — including any personal data in it and the data about the people it invites — is handled on that organization’s behalf. For that content the organization is the controller and we act as its processor under the Data Processing Addendum.
What we collect, why, and on what legal basis
- Access requests. While access is invite-only you can leave your email address to be let in. We use it to confirm the request and to send you a sign-up link when a place opens, and we send ourselves a notice with that address. Basis: steps you asked for before entering into a contract (GDPR Art. 6(1)(b)). Kept until we remove the handled request, or earlier if you ask.
- Your account. Name, email address, whether the address is verified, and your password, stored only as a salted hash. If you sign in with Google, we receive your name, email address and profile picture link, and store the Google account identifier and the tokens Google issues for the sign-in. We use none of them to reach any other Google data. Basis: performing our contract with you (Art. 6(1)(b)). Kept until you delete your account.
- Sign-in sessions. A session token, the IP address and browser (user agent) the session was started from, when it started and expires, and which workspace is active. We use them to keep you signed in, to show you your active sessions and to protect your account. A session stays valid for 7 days and is extended while you use the product. Basis: our contract (Art. 6(1)(b)) and our legitimate interest in security (Art. 6(1)(f)). Kept until you sign out or revoke the session, or until your account is deleted.
- Workspaces and collaboration. Workspace names, members and their roles, invitations (the invited email address and who invited them), client invitations and access grants, share links and who created them, comments (including the name a guest types when commenting through a share link), change requests, decisions, saved versions and project activity. Basis: our contract (Art. 6(1)(b)); for people an organization adds, the organization is the controller. Kept while the workspace exists.
- Project content. Wireframes, specifications, project instructions, your messages to the built-in assistant, images you attach to those messages, and the records of agent runs (their output, token counts and cost). Basis: our contract (Art. 6(1)(b)), on the organization’s behalf. Kept while the project and its workspace exist.
- Payments and invoices. When a workspace buys a plan, Stripe processes the payer’s name, billing email, billing address, VAT number if given, and card details. We receive the last four digits and brand of the card, the billing email, and the invoices. Basis: performing our contract with you (Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)). We keep invoices for ten years, as accounting law requires, even after the account or workspace is deleted; by then they are no longer linked to the workspace.
- Feedback. The message you send through “Send feedback”, with your account and the workspace you sent it from, so we can reply and improve the product. Basis: our legitimate interest (Art. 6(1)(f)). Kept until you delete your account.
- Product usage records. When you sign in and when you create a project: the time and the workspace you were in, never the project’s name or content. And for each day you use the web app or the desktop app, which of the two it was, taken from the request the app makes to load your session. They show us whether the product is being adopted, and they are linked to your account.
- Page views. Which screen of the web app or page of our public site was shown — its route pattern (for example /projects/:id), never the full address, the project it points to or anything you typed — whether it started a visit, and, for the first page of a visit, the name of the website that linked to it. A page view is linked to your account and the workspace you were in only when you are signed in and have accepted optional diagnostics; otherwise it is linked to nothing. We store no IP address or browser details with it.
- Website and app measurement through Google Tag Manager. If you accept optional cookies, your browser loads Google Tag Manager, which loads the measurement tags we have configured. From then on, each page you open sends that tag manager the page’s path — the real path for our public pages, and only the shape of the address (for example /projects/:id) for screens inside the product, so no project, workspace or account identifier reaches it — together with the page title, and the information your browser sends with any request, including your IP address and browser details. Those tags may set cookies in your browser and may let Google connect the visit to one of our advertising campaigns. Basis: your consent (Art. 6(1)(a)), which you can withdraw at any time in Settings → Legal & privacy. Nothing of this is loaded before you accept, and how long Google keeps what it receives is described in its own privacy policy.
- Desktop app launches. The app version, operating system and processor type, each time the desktop app starts its window. A launch is linked to nothing, not even when the app is connected to your account.
- Security records. An audit log of sensitive actions in a workspace — who did what and when, and for some actions (such as deleting or restoring a project, creating or revoking a share link, inviting a client, approving a specification or changing the plan) the IP address the action came from. Basis: our legitimate interest in security and accountability (Art. 6(1)(f)). Kept for as long as the workspace exists.
- Server logs. For each request: its time, method, route, response status, a request identifier and the IP address it came from. We use them to operate and secure the service; passwords, tokens and similar secrets are removed before anything is written. Basis: our legitimate interest (Art. 6(1)(f)). Kept only on the server, and discarded when the logs rotate or the service is redeployed.
- Error reports. When something breaks, a technical report of the error: what failed and where in the code, the steps that led to it (screens opened, requests made, buttons clicked), the address of the page, the app version, your browser or operating system, and your language and time zone. Reports carry no name or email address, secrets are removed before a report is sent, reporting is set up not to record your IP address, and in the browser it stores nothing on your device. Errors on our servers are reported on the basis of our legitimate interest in keeping the service working and secure (Art. 6(1)(f)). Your browser sends reports only if you accept optional diagnostics in the cookie banner or in Settings → Legal & privacy (consent, Art. 6(1)(a)); it then also tells the provider when a session starts, so we can see how often sessions end in an error. The desktop app sends reports only if you allow error reports when it asks after you sign in, or in Settings → Legal & privacy (consent, Art. 6(1)(a)); it then also tells the provider when the app starts and whether it closed normally, and withdrawing stops reporting at once. To be able to report a crash, the desktop app keeps details of the running session, and of any crash, in its own folder on your computer; they leave it only as reports you have allowed. Kept by our error-monitoring provider for at most 90 days.
- Contract withdrawals. The name and account email address you enter in the withdrawal form, and when we received them. We use them to confirm the withdrawal to that account and keep the confirmation as our record of it; nothing is sent when no account uses the address. Basis: our legal obligation under consumer protection law (Art. 6(1)(c)). Kept for 3 years, the general limitation period for claims under the contract.
- Emails. We send account verification, password reset, workspace invitations (to the invited person, naming who invited them and the workspace), client invitations, and access-request confirmations and approvals. Basis: our contract (Art. 6(1)(b)).
Product usage records, desktop app launches and page views that are linked to nothing rest on our legitimate interest in understanding how the product is used so we can improve it (Art. 6(1)(f)); page views linked to your account rest on your consent (Art. 6(1)(a)). All of them are counted on our own servers. A separate count reaches Google Tag Manager, and only for visitors who accept optional cookies; the two are described separately above because they are two different things.
We do not sell personal data, we show no advertising inside the product, and we make no decisions about you by automated means that have legal or similarly significant effects. We do advertise Throughplan elsewhere: if you accept optional cookies, the tags described above let an advertising platform attribute your visit to one of our campaigns, and that platform may use what it receives for its own advertising purposes under its own terms. Declining leaves that out entirely.
The AI engine and your content
The engine that turns your descriptions into wireframes and specifications runs inside the Throughplan desktop app on your own computer. It uses the AI tool you have installed and signed in to yourself — Claude Code from Anthropic or Codex from OpenAI.
To do its work, the engine sends that provider a summary of your project, the project’s instructions, what you are editing, your messages and, for Claude, the images you attach. This goes straight from your computer to the provider under your own agreement with them; it never passes through our servers, and we neither receive nor control that processing.
Our cloud service never runs an AI model and never sends your project content to one.
Who receives your data
We use these providers to run the service. Each processes personal data only on our instructions and under a data processing agreement:
- Contabo GmbH — Server hosting for the application, its database and file storage. Location: Germany; the server is located in the European Union.
- Mailjet SAS (part of the Sinch group) — Sending account, invitation and access emails. Location: France (European Union); email data is hosted in the European Union. Transfer safeguard: for its support providers outside the EU, the European Commission’s Standard Contractual Clauses in its data processing agreement.
- Stripe Payments Europe, Limited — Taking card payments, issuing invoices and sending billing emails for paid plans. Location: Ireland (European Union). Transfer safeguard: for transfers to Stripe, Inc. in the United States, the EU–US Data Privacy Framework and the European Commission’s Standard Contractual Clauses in its data processing agreement.
- Google Ireland Limited (Google Tag Manager) — Loading the measurement tags we have configured on our website and apps, and only for visitors who accept optional cookies. Location: Ireland (European Union), with processing by Google LLC in the United States. Transfer safeguard: EU–US Data Privacy Framework certification, with the European Commission’s Standard Contractual Clauses as a fallback.
- Functional Software, Inc. (Sentry) — Error monitoring for our servers, and for the web app when you allow it. Location: United States. Transfer safeguard: EU–US Data Privacy Framework certification, with the European Commission’s Standard Contractual Clauses as a fallback.
If you choose to sign in with Google, Google Ireland Limited handles that sign-in as its own controller under its own privacy policy.
Inside the product, the people you work with see what you share with them: members of your workspace, clients you invite, and anyone holding a share link you created. We disclose data to authorities only when the law requires it.
Where your data is kept
Our database and file storage run on a server in the European Union. Error reports go to Sentry in the United States, which is certified under the EU–US Data Privacy Framework; the European Commission’s Standard Contractual Clauses apply as a fallback. Our email provider keeps email data in the European Union; its support providers outside the EU work under the Standard Contractual Clauses. If you accept optional cookies, the measurement data described above goes to Google Ireland Limited and is processed by Google LLC in the United States, which is certified under the EU–US Data Privacy Framework, with the Standard Contractual Clauses as a fallback. Google as a sign-in provider, and the AI provider you use, handle any transfer of your data under their own terms.
Deleting your data
You can delete your account in Settings → Account. It takes effect immediately and deletes your profile, sign-in methods and sessions, your workspace memberships, your feedback and notifications, and your usage records. Projects you created in a team workspace, or that were handed to you there, stay with the team: they pass to the workspace’s longest-standing owner (or, if there is none, an admin or the longest-standing member). The same happens when you are removed from a team workspace. Workspaces in which you are the only member are deleted with it, including their projects and files. If you are the only owner of a workspace that still has other members, you must first remove them or delete that workspace.
A workspace owner can delete the whole workspace in Settings → Danger zone. This deletes its projects, members, invitations, client access, comments, activity, audit log and the images attached in its builder chats. Page views and usage records linked to it lose that link and expire on their normal schedule.
Some records stay after you leave a team workspace or delete your account: that workspace’s audit log and project history keep a reference to your account (and, in the audit log, the IP address of the action) for as long as the workspace exists, and an access request stays until we remove it. We delete any of these on request.
Deleting a project moves it to the trash, where it stays — and can be restored — until the workspace is deleted.
Product usage records, page views and desktop app launches are kept for 90 days. The days on which your account was active, and daily totals derived from these records, are kept for 400 days. The dates you were first and last active, last signed in and created your first project are kept for as long as your account exists. Deleting your account deletes every one of these records that is linked to it; records linked to no account expire on the same schedule, and the daily totals are not linked to any account and remain.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy of it;
- have inaccurate data corrected — you can change your name in Settings → Account;
- have your data erased — see “Deleting your data” above;
- restrict how we use your data while a complaint about it is being resolved;
- receive your data in a portable format — Settings → General exports all of a workspace’s projects as JSON with Markdown, and any project can be exported on its own as JSON, Markdown or PDF;
- object to processing based on our legitimate interest — see “Your right to object” below;
- withdraw your consent to optional diagnostics at any time, in Settings → Legal & privacy or through the cookie banner, without affecting what was sent before.
Your right to object. Where we rely on our legitimate interest — product usage records, page views linked to nothing, desktop app launches, security records, server logs, feedback and error reports from our servers — you can object at any time, on grounds relating to your particular situation, by writing to info@throughplan.com. We then stop that processing for you unless we have compelling legitimate grounds that override your interests, such as keeping the service and its users secure, or need it for legal claims.
For anything the product does not let you do yourself, write to info@throughplan.com. We answer within one month, and we may ask you to confirm the request from the email address of your account.
You can also complain to a data protection authority. Ours is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovakia (https://dataprotection.gov.sk); you may also go to the authority where you live or work.
How we protect your data
- All traffic to the service is encrypted in transit (HTTPS).
- Each workspace’s data is isolated in the database with row-level security, and the application connects with a role that cannot bypass it.
- The database is reachable only over a private network, not from the internet.
- Passwords are stored only as salted hashes; you can review and revoke your sessions.
- Requests are rate-limited, sensitive actions are written to an audit log, and secrets are removed from logs and error reports.
What you must provide
An email address and a name are needed to create an account; without them we cannot provide the service. Everything else you add is your choice.
Children
Throughplan is a tool for professional work and is not aimed at children. If someone under 16 uses it, any consent the service asks for, such as for optional diagnostics, must be given or approved by their parent or guardian.
Changes to this policy
When we change this policy we update the date at the top. We announce material changes in the product or by email before they take effect.
Contact
Privacy questions and requests: info@throughplan.com, by phone on +421 918 940 280, or by post to GRIIND s. r. o., Mierová 1099/66, 064 01 Stará Ľubovňa, Slovakia.