Skip to main content
Planorial
WorkspacePricingAboutContactPrivacyTerms
Open workspace
WorkspacePricingAboutContactPrivacy policyTerms of service
HomePrivacy Policy

Legal · Privacy

Privacy Policy

How Planorial handles account information, floor-plan briefs, source images, generated results, payments, support requests, and technical data.

Updated
August 29, 2026
Reading time
11 minutes
Document
Public policy

Maintained by Planorial product team

A floor plan drawing enclosed by translucent architectural layers on a measured grid
Conceptual illustration — visual layers represent processing boundaries, not a security certification.

On this page

01Scope and overview02Information you provide03Floor-plan content04Technical data and cookies05How information is used06AI processing07Sharing and disclosures08Retention and deletion09Security10Choices and privacy rights11International processing12Children13Changes and contact
On this page
Scope and overviewInformation you provideFloor-plan contentTechnical data and cookiesHow information is usedAI processingSharing and disclosuresRetention and deletionSecurityChoices and privacy rightsInternational processingChildrenChanges and contact

At a glance. Planorial processes the information needed to operate accounts, respond to support requests, and create or revise concept-stage floor-plan images. A floor-plan brief or source image submitted to the public AI workspace is sent through our server to the configured AI provider. Signed-out History stays in the current page session. Signed-in History keeps up to nine recent results for 30 days and may use account-scoped browser storage as a local fallback. This recent History is not presented as a permanent project library or a promise of cross-device access. Account uploads, such as profile images or support attachments, follow a separate storage path and may persist.

1. Scope and overview

This Privacy Policy explains how the online service branded as Planorial (the “Service,” “Site,” “we,” “us,” or “our”) handles personal information. It applies when you browse the Site, use the public floor-plan workspace, create an account, purchase a product through Stripe checkout, or contact support. It does not govern a third-party website or service that has its own privacy notice.

Planorial is currently a concept-stage product. Analytics, social sign-in, email, storage, and payment providers can be enabled or disabled, so this Policy describes them conditionally. The operator’s legal name, address, and jurisdiction must be added before commercial launch; “Planorial” is the service name.

2. Information you provide

We receive information that you choose to enter or upload. The categories depend on the feature you use:

  • Account information: name, email address, password credential or social-sign-in identifier, email-verification status, profile image, and optional invite code.
  • Floor-plan requests: plan type, dimensions or area, units, room counts, layout choices, custom briefs, revision instructions, and preferred visual style.
  • Images: a source floor-plan image used for Edit or Render, a profile image, or an attachment included with a support request.
  • Support content: ticket subject, message, replies, and attachment URLs.
  • Transaction information: if checkout is enabled, selected product, amount, currency, billing interval, provider, order status, subscription identifiers, and invoice or transaction references.
  • Feedback and correspondence: any comments, questions, or other material you send to us.

Avoid placing sensitive information in a brief or image. Do not upload identification documents, payment-card images, health records, access codes, or sensitive residential-security details.

3. Floor-plan briefs, source images, and results

When you ask Planorial to generate a concept image, the structured layout details and prompt are transmitted to our server and then to the configured AI provider. If you use Edit or Render, the source image is read in your browser, encoded for the request, and transmitted with the instructions. The current public workspace accepts PNG, JPEG, or WebP source images within the displayed size limit.

Generated images return to the browser for display and download. When signed out, up to nine recent results remain only in page memory and may disappear after refresh, navigation, or closing the page. When signed in, up to nine recent results, their request details, and storage references are kept in account History for 30 days. The browser may also keep an account-scoped IndexedDB copy as a local fallback; clearing browser data or using another device may make that fallback unavailable. Network infrastructure and the AI provider may still process metadata or content; an HTTP no-store response prevents normal response caching but does not prove every processor immediately deletes logs.

Three architectural paper modules showing a request moving through a protected processing layer to a floor plan result
Conceptual illustration — a request moves through the Service and an AI-processing layer before a result returns.

4. Technical data, sessions, and cookies

When your browser communicates with the Site, we may receive IP address, browser and device type, operating system, locale, requested URL, timestamps, referrer, errors, and interaction events. For signed-out AI requests, the trusted edge address is used transiently to derive a day-scoped, one-way HMAC budget identifier. The anonymous-credit tables do not store the raw address, and the identifier changes with the UTC day. Browsers on one shared network may therefore share an abuse-prevention ceiling even though each browser keeps its own visitor wallet.

Necessary cookies may maintain a session and interface state. A signed, HttpOnly visitor cookie also gives a signed-out browser a pseudonymous daily-credit wallet; when you later sign in, the current UTC-day usage is linked to the account so the free allowance is not issued twice. Deleting that cookie does not reset the separate network-level daily safety budget. Browser storage may remember limited operations such as a verification-email cooldown and may cache signed-in floor-plan History for up to 30 days as an account-scoped fallback. If configured, Google Analytics or Plausible may collect usage and device information under their notices. The Site does not yet provide a universal cookie panel or dedicated Global Privacy Control response. Browser controls can block or clear storage, but that may sign you out, remove the local History fallback, reset the browser-side identity used for interface continuity, or impair features.

5. How we use information

We use information to provide and secure the Service; authenticate accounts; generate, edit, and return images; maintain settings; deliver configured account emails; operate support; administer enabled orders, subscriptions, and credits; prevent misuse; diagnose failures; measure performance; enforce our Terms; comply with law; and communicate material changes.

Where required, the legal basis may be performance of a contract or requested step, legitimate interests such as security, a legal obligation, or consent for an optional activity. The basis depends on the feature and location; this Policy does not waive non-waivable rights.

6. AI processing and service providers

The current workspace uses one server-configured image-generation path. Planorial sends image prompts and structured requirements to configured third-party AI services; Edit and Render also send the source image, and prompt improvement sends the brief text. Returned images are delivered to your browser, so submitted content may be processed in those providers' systems and locations.

We do not promise that an AI provider never retains, reviews, or uses inputs to improve systems; those facts depend on its current terms. Remove unnecessary names, addresses, access information, and identifiers before submission. We may change providers and will update this Policy when a change materially affects processing.

Other processors may provide hosting, databases, object storage, email, authentication, payments, security, or analytics. They receive information reasonably needed for their function, subject to their terms and our arrangements.

7. Sharing and disclosures

We may disclose information to those service providers, a hosted-checkout provider, confidential professional advisers, or a successor in a corporate transaction. We may also disclose it to comply with law or valid process, investigate fraud or security incidents, enforce agreements, or protect users and the Service.

We do not sell personal information for money, and the product is not designed for cross-context behavioral advertising. If this changes, we will update the notice and add legally required controls first. Account image uploads may use publicly reachable object URLs, so generated images and support attachments should not be treated as a private-media vault.

8. Retention and deletion

Retention depends on data type and purpose. Session and verification records have expiration fields. Account, support, transaction, subscription, credit, and security records may remain while needed for operation, disputes, fraud prevention, accounting, or law. Profile images and support attachments may remain in object storage or a public upload directory; no automatic object-deletion schedule is currently exposed.

Signed-out workspace results remain in the page session. Signed-in History keeps up to nine recent results for 30 days in server-side account storage and may keep the same limited set in account-scoped browser storage as a fallback. Expired History entries are removed from the active list and local fallback during normal cleanup, but backups, logs, upstream infrastructure, or the AI provider may retain data longer. We aim to delete or de-identify information when no longer needed, subject to technical and legal constraints. History is not long-term project storage, and a complete account-deletion workflow must be established before permanent project storage is offered.

Three architectural archive trays moving from an active floor plan to a temporary layer and a cleared frame
Conceptual illustration — retention differs by data category; an empty tray is not a promise of instant deletion.

9. Security

Safeguards may include authenticated access, scoped administrator permissions, request validation, size limits, rate limiting, protected production secrets, webhook verification, and hosting transport security. No online system is perfectly secure, and we do not claim a certification, recurring penetration-test program, or universal encryption-at-rest guarantee. Use a strong unique password and report suspected unauthorized access.

10. Your choices and privacy rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or an explanation; object to certain uses; withdraw consent; opt out of a sale or legally defined sharing; or complain to a regulator. We will not unlawfully discriminate for a request. Exceptions may apply for security, law, accounting, or another person’s rights.

Account settings allow limited profile updates but not complete self-service access, export, or deletion. Use Support Tickets and identify the requested privacy action. We may verify your identity or an agent’s authority. Do not send a password, full card number, or unnecessary identity document in the first message.

Where a feature permits it, you may avoid creating an account, submitting a source image, or adding personal details to a prompt. Browser and provider controls may offer further choices.

11. International processing

Planorial and its providers may process information in other countries with different privacy laws. Where required, the operator should use an approved transfer safeguard. Because the operating entity, production regions, and provider agreements are not yet published, we do not claim a specific adequacy decision, contractual clause, or certification.

12. Children

The Service is for adults and is not directed to children under 13. Anyone below the local age for online-service consent should use Planorial only with appropriate authorization. Do not submit a child’s identity, photograph, security details, schedule, or precise home information. Contact support if you believe a child provided data without authorization.

13. Changes and contact

We may revise this Policy when the Service, providers, or law changes. The “Updated” date identifies the current version. When required, a material change will receive additional in-product or account notice.

For a question or privacy request, open Settings → Support Tickets while signed in. If you cannot access your account, use the public contact method displayed when available. Before commercial launch, this section must add the operator’s legal name, address, jurisdiction, and monitored privacy contact. Mandatory rights remain unaffected.

Related legal document

Read the Terms of Service

Continue
Planorial

Create a floor plan from a brief, edit an existing plan, or draw one manually.

Generated images are planning concepts, not verified drawings.
CreateFloor Plan MakerFloor Plan GeneratorFloor Plan EditorFloor Plan Creator
LearnWorkspace controlsChoose a workflowCommon questions
CompanyAbout PlanorialContactPrivacy policyTerms of service
Check dimensions, structure, services, access, and local requirements before using a generated plan in a project.Open floor plan workspace