Privacy Policy
This Privacy Policy explains what information we (UP UGC Planner LLC, a Pennsylvania limited liability company, "UGC Planner", "we", "us", or "our") collect when you use the UGC Planner mobile application and our websites at ugcplanner.com and ugcplanner.app (collectively, the "Service"), how we use it, and the choices you have. We also describe the rights you have under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other applicable privacy laws.
Plain-English summary. UGC Planner is device-first: your business records begin on your device, and you choose whether to enable Cloud Backup & Sync for supported structured records. Photos, receipts, portfolio files, and media-kit files stay on the device where you created them unless you choose to upload, publish, or share them through a feature. Cloud data is protected in transit and with server-side encryption at rest. We do not sell personal information, show third-party ads, use business records for advertising or profiling, or use them to train AI models. We process data only to provide features you request, maintain and protect the Service, support you, comply with law, and for the other limited purposes explained below.
1. Who we are & how to contact us
Data controller (GDPR) / Business (CCPA): UP UGC Planner LLC, a Pennsylvania limited liability company.
Postal address: 1500 Chestnut Street, Suite 2 PMB 1081, Philadelphia, PA 19102, United States.
Email: support@ugcplanner.app for privacy questions, data-subject requests, or to exercise any of the rights described below. Please put "Privacy" in the subject line for the fastest routing.
UGC Planner is a productivity app for content creators to manage brand deals, invoices, delivery, calendar events, expenses, and related business tasks. It is available on iOS and Android.
2. What we collect & why
2.1 Account data
When you sign in with Apple, Google, or a one-time email code, we receive a stable sign-in identifier and email address and, if available or supplied by you, a name and avatar. We also keep your subscription tier and standard account-security metadata such as session, device, sign-in timestamp, IP-address, and browser or app user-agent information. We use this data to operate and secure your account and to send transactional messages such as sign-in codes and security notices. Business settings you enter, including country, state, tax rate, and filing status, remain part of your business records and reach our servers only if you enable Cloud Backup & Sync or use a feature that requires them. Legal basis (GDPR): performance of the contract and our legitimate interest in account security.
2.2 Authentication tokens
Refresh tokens are stored in your device's secure storage (iOS Keychain or Android Keystore). Our server stores a one-way hash of a refresh token and related session metadata so it can validate and revoke sessions without storing the usable token itself. Short-lived access tokens are held by the app for the active session. Legal basis: performance of the contract and our legitimate interest in account security.
2.3 Business records you enter
Brand deals, invoices, expenses, rates, ideas, calendar items, notes, settings, and files you create or upload. These begin on your device. If you enable Cloud Backup & Sync, supported structured records are sent to our servers over an encrypted connection and stored encrypted (see Sections 5 and 13), so the same workspace can be restored and kept current across supported devices. Photos, receipts, portfolio files, and media-kit files remain local unless you select them for upload, publication, or sharing. We do not routinely review your business records and do not use them for advertising, profiling, or model training. We process them only as needed to provide features you request, maintain and protect the Service, provide support with your authorization, comply with law, and as otherwise described in this Policy. Legal basis: performance of the contract and, for security, our legitimate interest.
2.4 Instagram (optional)
If you connect Instagram, we receive only what the Instagram Login API returns under the instagram_business_basic scope: your Instagram user ID, username, display name, profile picture URL, follower/following counts, and the metadata of your recent posts (caption, like/comment counts, media URLs). We store this so the in-app Instagram screens load quickly; we never store your Instagram password, we have no access to your DMs, and we cannot post on your behalf without your explicit action. Legal basis: consent, which you give by connecting the account and can revoke at any time by disconnecting it in the app.
2.5 Subscription & receipt data
Subscriptions are sold and processed by the Apple App Store and Google Play. We never receive your payment-card details. We receive only the receipt metadata Apple/Google share with us (transaction ID, product ID, expiration date, renewal status) so we can unlock the right tier on your account. Legal basis: performance of the contract.
2.6 Content you upload, publish, or share
When you create a delivery link or publish a portfolio, media kit, rate card, or other public page, the content you select is uploaded to our object storage (Cloudflare R2) so the intended audience can access it. Feed Planner media you choose to store in the cloud is handled the same way. A link may remain available until you revoke it, delete the content or your account, or an optional expiry date you set is reached. Recipients generally do not need an account. We collect technical view and download events, such as timestamps and requesting IP addresses, to show delivery status and prevent abuse, plus feedback a recipient chooses to leave. Section 15 explains link controls and visibility. Legal basis: performance of the contract.
2.7 Push notifications
If you allow notifications, we store the push token your device gives us (an APNS token on iOS, an FCM token on Android) so we can deliver deal-deadline reminders, share-opened and share-downloaded events, and other transactional notifications. Legal basis: consent, which you give in the OS-level permission prompt and can revoke at any time.
2.8 Product analytics
We collect first-party product-usage events such as screen views, feature use, timestamps, platform, and app version, build, runtime, and update identifiers. Events use a random installation identifier and a rotating diagnostic-session identifier; while you are signed in they may also be associated internally with your account ID so we can investigate reliability and understand feature adoption. These identifiers are not your name or email, and analytics is not designed to include payment details or the contents of your business records. When you delete your account, we remove account, device, and session identifiers from retained events, leaving de-identified product statistics that are no longer linked to you. We embed no third-party advertising SDK, do not track you across apps, and never request the IDFA or Google Advertising ID. Legal basis: our legitimate interest in understanding and improving the app.
2.9 Device & usage diagnostics
We use Sentry to receive crash reports and technical diagnostics such as stack traces, device and OS information, app-delivery details (version, build, runtime, update ID, channel, and update time), and a rotating diagnostic-session identifier. We configure this reporting to remove names, email addresses, account IDs, authentication tokens, request bodies, and business-record contents. The diagnostic-session identifier may be matched internally to first-party analytics or an account when needed to investigate a support or reliability issue; it is not used for advertising or cross-app tracking. Legal basis: our legitimate interest in keeping the app stable and secure. You may object as described in Section 11.
2.10 Email delivery metadata
Transactional emails sent through SendGrid carry standard delivery/open/click metadata so we can confirm delivery and detect outages. We do not use this for marketing profiling. Legal basis: legitimate interest in service reliability.
2.11 Support correspondence
If you email us, we keep the thread so we can respond and maintain a record of the issue. Legal basis: legitimate interest in providing support.
3. What we do not collect
- We do not collect your payment-card data — Apple and Google process payments and remit net payouts to us.
- We do not collect your contacts.
- We do not collect precise location, motion, health, or other background sensor data.
- We do not access your photo library beyond the specific files you pick, or your microphone outside the moment you actively record; both only after you grant the OS permission.
- We do not embed any third-party advertising SDK, do not track you across other apps, and never request the IDFA or Google Advertising ID.
- We do not buy, sell, or rent personal data, and we do not use your business records to train our models or third-party AI models.
4. Sensitive personal information (CCPA / CPRA)
We do not intentionally request "sensitive personal information" as defined by California law (for example, precise geolocation, government IDs, racial or ethnic origin, religion, union membership, health, sex life, or the contents of private communications). If you voluntarily place such information in a deal note, invoice, file, or other business record, it follows the storage and sharing choices you make. We do not use it to infer characteristics, advertise, profile, or train models. Tax-rate and filing-status fields are used only for the calculations and business features you request.
5. Your storage choices
UGC Planner offers a clear, informed choice during onboarding and at any time in Settings → Backup & sync:
- On this device only. Your business records are stored only on your device and are not backed up to our servers; we hold no copy and cannot recover them for you. If you delete the app or change devices without exporting, that data is permanently lost. Choosing this mode does not switch off the features you actively use: files you place in a share link are still uploaded so your recipient can view them (Section 15), content you submit to an AI feature is processed as described in Section 7, and the diagnostics in Sections 2.8 and 2.9 apply in either mode.
- Cloud Backup & Sync. Supported structured business records are sent to our servers over an encrypted connection and protected with application-level AES-256-GCM encryption before they are written to our database, in addition to provider encryption at rest. Signing in to the same account lets supported devices restore and synchronize those records without a separate recovery key. Because the Service performs this restore and synchronization for you, this is server-managed encryption rather than zero-knowledge or end-to-end encryption: our systems can decrypt the data only as necessary to operate the feature, maintain security, provide support you request, or comply with law. Access is restricted as described in Section 13, and we do not routinely review your records.
Your content is yours. Whichever mode you choose, we use business records only for the limited purposes described in this Policy. We do not sell them or use them for advertising, profiling, or model training. We disclose them only to service providers acting on our behalf, recipients you choose, or where safety or law requires it.
Account data (email, sign-in identifiers, refresh tokens), Instagram connection metadata, push tokens, and any files you placed in a share link are handled separately from this choice and are described in Section 2.
6. Purposes of processing & legal basis (GDPR)
For users in the EU, EEA, UK, and Switzerland, our legal basis under GDPR Article 6 for each processing activity:
- Providing the Service to you (account, sign-in, synchronizing supported records, storing and returning backups, publishing content and delivering links to recipients you nominate, processing subscription state) — performance of a contract (Art. 6(1)(b)).
- Transactional notifications (deal-deadline reminders you scheduled, share-opened / share-downloaded events you opted into, receipts) — performance of a contract and your opt-in consent for the notification channel (Art. 6(1)(a) and 6(1)(b)).
- Instagram integration — your explicit consent when you tap "Connect Instagram" (Art. 6(1)(a)).
- AI features (Voice Fill, parsing, captions) — performance of a contract when you request the feature (Art. 6(1)(b)), and consent where applicable law requires it.
- Diagnostics and product analytics — legitimate interest in keeping the app stable and improving it (Art. 6(1)(f)). You may object at any time (Section 11).
- Fraud prevention, security, abuse detection — legitimate interest (Art. 6(1)(f)) and legal obligation where applicable (Art. 6(1)(c)).
- Compliance with legal obligations (responding to lawful requests, tax record retention, App Store / Play Store policy compliance) — legal obligation (Art. 6(1)(c)).
We do not engage in solely-automated decision-making that produces legal or similarly significant effects on you (GDPR Art. 22).
7. AI features
Some features you trigger (Voice Fill, contract or brief parsing, and caption drafting) send the specific content you submit to OpenAI or Anthropic so they can return the requested result. We send only what is needed for that request. Under our current commercial API arrangements, those providers do not use API inputs or outputs to train their models by default and may retain them for a limited period, generally up to 30 days, for safety and abuse monitoring, with longer retention only where their terms or law require it. UGC Planner does not separately keep an AI input merely because you invoked an AI feature; if you choose to save the result or underlying content, it becomes a business record governed by your storage choice. AI features are opt-in by action: if you do not use them, no content is sent to an AI provider.
8. Sub-processors & disclosures
We use the following service providers to operate the Service. They receive only the information reasonably necessary for their role and process it under their service terms and applicable data-protection commitments:
- Vercel — application hosting (United States)
- Neon — managed PostgreSQL database, including encrypted Cloud Backup & Sync records (United States, EU)
- Cloudflare R2 — object storage for exchanger files and media (global edge)
- Apple Push Notification service — iOS push (United States)
- Firebase Cloud Messaging — Android push (Google, United States)
- SendGrid (Twilio) — transactional email (United States)
- Sentry — crash reporting and error monitoring (United States, EU)
- OpenAI, Anthropic — AI features you trigger (United States)
- logo.dev — brand logo lookup by domain
- Apple App Store, Google Play — subscription billing and receipt validation
- Meta (Instagram Graph API) — only if you connect your Instagram account
We do not sell or share your personal information with third parties for cross-context behavioural advertising, and we do not show third-party advertising inside the app.
We disclose your data to a third party that is not listed above only when (i) you direct us to (for example, by sending a share link to a recipient), (ii) we are legally compelled to do so after a good-faith review of the request, or (iii) it is necessary to investigate or protect against fraud, abuse, or threats to the security or integrity of the Service.
9. International transfers
UGC Planner is operated from the United States; most service providers are US-based. When personal data of EU, EEA, UK, or Swiss residents is transferred outside their region, we rely on appropriate safeguards available under applicable law, such as adequacy decisions, the EU Commission's Standard Contractual Clauses, and UK or Swiss equivalents, as relevant. We also apply technical safeguards including encrypted transport and encryption at rest, with application-level encryption for Cloud Backup & Sync as described in Section 13.
10. How long we keep things (retention)
- Account record: while your account exists. Deleted within 30 days of account deletion.
- Cloud Backup & Sync records: while the feature is enabled or while needed to provide restore and synchronization. They are scheduled for deletion when you switch the feature off or delete your account and are deleted within the periods described in our data-deletion notice.
- Exchanger files: until you revoke the link, it reaches an expiry you set, or you delete your account. An automated cleanup job runs daily and permanently purges expired and revoked links together with their files.
- Instagram cached profile / posts snapshot: while your Instagram connection is active. Deleted on disconnect or account deletion.
- Subscription receipts (transaction IDs, plan, expiry): kept for the lifetime of the subscription plus 7 years to satisfy tax / accounting / audit obligations, in anonymised form where possible.
- Server logs: under configured provider retention periods, generally no longer than 90 days unless needed for a security investigation or legal obligation.
- Push tokens: until your device unregisters or you disable notifications.
- Product analytics: identifiable events while your account is active and as reasonably needed for product reliability; account, device, and session identifiers are removed on account deletion. De-identified aggregate and event counts may be retained to measure long-term reliability and adoption.
- Crash reports: according to our configured Sentry retention period and no longer than reasonably necessary to investigate reliability and security issues.
- Deletion-suppression record: a minimal one-way cryptographic pseudonym retained only to prevent later store billing messages from reattaching identifiers to a deleted account, as explained in our data-deletion notice.
- Support emails: 2 years from the last reply, unless we are required to keep them longer.
11. Your rights under GDPR (EU/EEA/UK)
If GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data (most fields are directly editable in the app);
- Erase your data (the "right to be forgotten"), via in-app account deletion or by email;
- Restrict processing in specified circumstances;
- Object to processing based on legitimate interests;
- Receive your data in a portable, machine-readable format;
- Withdraw consent at any time, where consent is the legal basis; withdrawal does not affect prior lawful processing;
- Lodge a complaint with your local supervisory authority. A list is available at edpb.europa.eu. We would also appreciate the chance to address your concern first.
To exercise any right, email support@ugcplanner.app from the address on your account. We respond within 30 days (extendable by a further 60 days for complex requests, with notice).
12. Your rights under CCPA / CPRA (California)
If you are a California resident, you have the right to:
- Know what categories of personal information we collect, the sources, the purposes, and the categories of third parties we share it with (this notice describes all of these);
- Access the specific pieces of personal information we have about you;
- Delete your personal information, subject to limited legal exceptions;
- Correct inaccurate personal information;
- Limit the use and disclosure of sensitive personal information — we do not use sensitive personal information for any purpose that triggers this right;
- Opt out of sale or sharing of personal information.
We do not sell or share your personal information as those terms are defined under California law, and there is therefore nothing to opt out of. We have not done so in the preceding 12 months.
You have the right to be free from retaliation for exercising any of these rights. You may use an authorized agent; we may require reasonable verification of authority. To submit a request, email support@ugcplanner.app with the subject "CCPA Request". We verify the request via the email on your account before fulfilling it.
Shine the Light (Cal. Civ. Code § 1798.83): California residents may request information regarding any disclosure of personal information to third parties for direct-marketing purposes. We do not engage in this disclosure, so the answer for the prior calendar year is "none."
13. How we protect your data
- Encrypted HTTPS/TLS connections for network transport.
- Encryption at rest on Neon (managed Postgres) and Cloudflare R2.
- Application-level AES-256-GCM encryption for Cloud Backup & Sync records before they are written to our database, with encryption keys stored separately from the data they protect and never exposed to client applications.
- Refresh tokens kept in the OS-level secure store (iOS Keychain, Android Keystore); short-lived access tokens live in memory only. We do not log sensitive values such as tokens or banking details.
- Access to production systems is limited to authorized personnel and service providers, protected by scoped credentials and provider access controls.
- Sentry alerting on unusual error patterns; automated dependency-vulnerability monitoring.
When you use Cloud Backup & Sync, our systems decrypt supported records only as needed to restore and synchronize them, maintain and secure the Service, provide support you request, or comply with law. We do not routinely review business records and do not use them for advertising, profiling, or model training.
Other data we hold (your email, sign-in tokens, push tokens, cached Instagram profile snapshot) is encrypted at rest by our infrastructure providers but is, by necessity, readable by our systems to operate the Service.
No system is perfectly secure. We notify affected users without undue delay if a personal-data breach is likely to result in a risk to your rights (GDPR Art. 33–34, and analogous US state laws).
14. Children
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from a person under 18. If you believe a minor has provided us personal information, email support@ugcplanner.app and we will investigate and delete it as appropriate.
15. Shared and public content
When you create a delivery link or publish a portfolio, media kit, rate card, Feed Planner item, or other public page:
- The content you select is uploaded to our Cloudflare R2 storage. A recipient sees only what you chose to include.
- Anyone with the applicable link may be able to open it until you revoke or delete it or an optional expiry date you set is reached. Where available, you can password-protect a delivery link, disable downloads, apply a watermark, and revoke access. Treat an unprotected link like a private link and share it only with intended recipients.
- We log view and download events (timestamp, file ID, requesting IP address, used for de-duplication and abuse prevention) and notify you via push and/or email if you opted in.
- Recipients are not registered users of UGC Planner; we collect from them only the technical metadata above plus any optional feedback they choose to leave. We do not require recipients to create an account.
- When content expires, is revoked, or is deleted, it is scheduled for permanent removal from storage by our automated cleanup process.
16. Changes to this policy
We may update this Privacy Policy as the Service evolves. If a change materially reduces your rights or introduces a significantly different use of personal data, we will provide notice before it takes effect when required by applicable law. The "Last revised" date at the top reflects the most recent change.
17. Contact
Privacy questions, data-subject requests, or anything else: support@ugcplanner.app.
UP UGC Planner LLC · 1500 Chestnut Street, Suite 2 PMB 1081, Philadelphia, PA 19102, United States.