Legal · Privacy
Privacy Policy
How Planorial handles account information, floor-plan briefs, source images, generated results, payments, support requests, and technical data.
Maintained by Planorial product team

On this page
At a glance. Planorial processes the information needed to operate accounts, respond to support requests, and create or revise concept-stage floor-plan images. A floor-plan brief or source image submitted to the public AI workspace is sent through our server to the configured AI provider. Signed-out History stays in the current page session. Signed-in History keeps up to nine recent results for 30 days and may use account-scoped browser storage as a local fallback. This recent History is not presented as a permanent project library or a promise of cross-device access. Account uploads, such as profile images or support attachments, follow a separate storage path and may persist.
1. Scope and overview
This Privacy Policy explains how the online service branded as Planorial (the “Service,” “Site,” “we,” “us,” or “our”) handles personal information. It applies when you browse the Site, use the public floor-plan workspace, create an account, purchase a product through Stripe checkout, or contact support. It does not govern a third-party website or service that has its own privacy notice.
Planorial is currently a concept-stage product. Analytics, social sign-in, email, storage, and payment providers can be enabled or disabled, so this Policy describes them conditionally. The operator’s legal name, address, and jurisdiction must be added before commercial launch; “Planorial” is the service name.
2. Information you provide
We receive information that you choose to enter or upload. The categories depend on the feature you use:
- Account information: name, email address, password credential or social-sign-in identifier, email-verification status, profile image, and optional invite code.
- Floor-plan requests: plan type, dimensions or area, units, room counts, layout choices, custom briefs, revision instructions, and preferred visual style.
- Images: a source floor-plan image used for Edit or Render, a profile image, or an attachment included with a support request.
- Support content: ticket subject, message, replies, and attachment URLs.
- Transaction information: if checkout is enabled, selected product, amount, currency, billing interval, provider, order status, subscription identifiers, and invoice or transaction references.
- Feedback and correspondence: any comments, questions, or other material you send to us.
Avoid placing sensitive information in a brief or image. Do not upload identification documents, payment-card images, health records, access codes, or sensitive residential-security details.
3. Floor-plan briefs, source images, and results
When you ask Planorial to generate a concept image, the structured layout details and prompt are transmitted to our server and then to the configured AI provider. If you use Edit or Render, the source image is read in your browser, encoded for the request, and transmitted with the instructions. The current public workspace accepts PNG, JPEG, or WebP source images within the displayed size limit.
Generated images return to the browser for display and download. When signed out, up to nine recent results remain only in page memory and may disappear after refresh, navigation, or closing the page. When signed in, up to nine recent results, their request details, and storage references are kept in account History for 30 days. The browser may also keep an account-scoped IndexedDB copy as a local fallback; clearing browser data or using another device may make that fallback unavailable. Network infrastructure and the AI provider may still process metadata or content; an HTTP no-store response prevents normal response caching but does not prove every processor immediately deletes logs.

4. Technical data, sessions, and cookies
When your browser communicates with the Site, we may receive IP address, browser and device type, operating system, locale, requested URL, timestamps, referrer, errors, and interaction events. For signed-out AI requests, the trusted edge address is used transiently to derive a day-scoped, one-way HMAC budget identifier. The anonymous-credit tables do not store the raw address, and the identifier changes with the UTC day. Browsers on one shared network may therefore share an abuse-prevention ceiling even though each browser keeps its own visitor wallet.
Necessary cookies may maintain a session and interface state. A signed, HttpOnly visitor cookie also gives a signed-out browser a pseudonymous daily-credit wallet; when you later sign in, the current UTC-day usage is linked to the account so the free allowance is not issued twice. Deleting that cookie does not reset the separate network-level daily safety budget. Browser storage may remember limited operations such as a verification-email cooldown and may cache signed-in floor-plan History for up to 30 days as an account-scoped fallback. If configured, Google Analytics or Plausible may collect usage and device information under their notices. The Site does not yet provide a universal cookie panel or dedicated Global Privacy Control response. Browser controls can block or clear storage, but that may sign you out, remove the local History fallback, reset the browser-side identity used for interface continuity, or impair features.
5. How we use information
We use information to provide and secure the Service; authenticate accounts; generate, edit, and return images; maintain settings; deliver configured account emails; operate support; administer enabled orders, subscriptions, and credits; prevent misuse; diagnose failures; measure performance; enforce our Terms; comply with law; and communicate material changes.
Where required, the legal basis may be performance of a contract or requested step, legitimate interests such as security, a legal obligation, or consent for an optional activity. The basis depends on the feature and location; this Policy does not waive non-waivable rights.
6. AI processing and service providers
The current workspace uses one server-configured image-generation path. Planorial sends image prompts and structured requirements to configured third-party AI services; Edit and Render also send the source image, and prompt improvement sends the brief text. Returned images are delivered to your browser, so submitted content may be processed in those providers' systems and locations.
We do not promise that an AI provider never retains, reviews, or uses inputs to improve systems; those facts depend on its current terms. Remove unnecessary names, addresses, access information, and identifiers before submission. We may change providers and will update this Policy when a change materially affects processing.
Other processors may provide hosting, databases, object storage, email, authentication, payments, security, or analytics. They receive information reasonably needed for their function, subject to their terms and our arrangements.
7. Sharing and disclosures
We may disclose information to those service providers, a hosted-checkout provider, confidential professional advisers, or a successor in a corporate transaction. We may also disclose it to comply with law or valid process, investigate fraud or security incidents, enforce agreements, or protect users and the Service.
We do not sell personal information for money, and the product is not designed for cross-context behavioral advertising. If this changes, we will update the notice and add legally required controls first. Account image uploads may use publicly reachable object URLs, so generated images and support attachments should not be treated as a private-media vault.
8. Retention and deletion
Retention depends on data type and purpose. Session and verification records have expiration fields. Account, support, transaction, subscription, credit, and security records may remain while needed for operation, disputes, fraud prevention, accounting, or law. Profile images and support attachments may remain in object storage or a public upload directory; no automatic object-deletion schedule is currently exposed.
Signed-out workspace results remain in the page session. Signed-in History keeps up to nine recent results for 30 days in server-side account storage and may keep the same limited set in account-scoped browser storage as a fallback. Expired History entries are removed from the active list and local fallback during normal cleanup, but backups, logs, upstream infrastructure, or the AI provider may retain data longer. We aim to delete or de-identify information when no longer needed, subject to technical and legal constraints. History is not long-term project storage, and a complete account-deletion workflow must be established before permanent project storage is offered.

9. Security
Safeguards may include authenticated access, scoped administrator permissions, request validation, size limits, rate limiting, protected production secrets, webhook verification, and hosting transport security. No online system is perfectly secure, and we do not claim a certification, recurring penetration-test program, or universal encryption-at-rest guarantee. Use a strong unique password and report suspected unauthorized access.
10. Your choices and privacy rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or an explanation; object to certain uses; withdraw consent; opt out of a sale or legally defined sharing; or complain to a regulator. We will not unlawfully discriminate for a request. Exceptions may apply for security, law, accounting, or another person’s rights.
Account settings allow limited profile updates but not complete self-service access, export, or deletion. Use Support Tickets and identify the requested privacy action. We may verify your identity or an agent’s authority. Do not send a password, full card number, or unnecessary identity document in the first message.
Where a feature permits it, you may avoid creating an account, submitting a source image, or adding personal details to a prompt. Browser and provider controls may offer further choices.
11. International processing
Planorial and its providers may process information in other countries with different privacy laws. Where required, the operator should use an approved transfer safeguard. Because the operating entity, production regions, and provider agreements are not yet published, we do not claim a specific adequacy decision, contractual clause, or certification.
12. Children
The Service is for adults and is not directed to children under 13. Anyone below the local age for online-service consent should use Planorial only with appropriate authorization. Do not submit a child’s identity, photograph, security details, schedule, or precise home information. Contact support if you believe a child provided data without authorization.
13. Changes and contact
We may revise this Policy when the Service, providers, or law changes. The “Updated” date identifies the current version. When required, a material change will receive additional in-product or account notice.
For a question or privacy request, open Settings → Support Tickets while signed in. If you cannot access your account, use the public contact method displayed when available. Before commercial launch, this section must add the operator’s legal name, address, jurisdiction, and monitored privacy contact. Mandatory rights remain unaffected.
