Privacy Policy
This Privacy Policy explains what information we (UP UGC Planner LLC, a Pennsylvania limited liability company, "UGC Planner", "we", "us", or "our") collect when you use the UGC Planner mobile application and our websites at ugcplanner.com and ugcplanner.app (collectively, the "Service"), how we use it, and the choices you have. We also describe the rights you have under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other applicable privacy laws.
Plain-English summary. UGC Planner is built so your business records (brand deals, invoices, notes, files) live on your device first. You choose during onboarding whether to keep a backup copy on our servers. If you turn backup on, your data travels over an encrypted connection and is stored encrypted on our servers. We do not read your content and we do not share it with third parties. Our systems process it only to run the Service for you, for example to return your backup when you sign in on a new device. If you keep everything on your device, we never receive a copy of your business records; we still receive the basic crash and usage diagnostics described in Section 2.9. We do not sell your personal information, we do not show you ads, and we do not use your business records to train AI models.
1. Who we are & how to contact us
Data controller (GDPR) / Business (CCPA): UP UGC Planner LLC, a Pennsylvania limited liability company.
Postal address: 1500 Chestnut Street, Suite 2 PMB 1081, Philadelphia, PA 19102, United States.
Email: support@ugcplanner.app for privacy questions, data-subject requests, or to exercise any of the rights described below. Please put "Privacy" in the subject line for the fastest routing.
UGC Planner is a productivity app for content creators to manage brand deals, invoices, delivery, calendar events, expenses, and related business tasks. It is available on iOS and Android.
2. What we collect & why
2.1 Account data
When you sign in with Apple, Google, or a one-time email code, we receive your sign-in identifier and email address, plus the name, optional avatar, language, country, state, tax rate, and filing status you choose to enter in Settings. We use this only to identify your account and to send transactional messages (sign-in codes, security alerts, receipts). Legal basis (GDPR): performance of the contract you enter into with us.
2.2 Authentication tokens
Refresh tokens are stored in your device's secure storage (iOS Keychain or Android Keystore). Short-lived access tokens are held in memory only and are never written to disk. Legal basis: performance of the contract.
2.3 Business records you enter
Brand deals, invoices, expenses, ideas, calendar items, notes, and files you create or upload. By default these live on your device only. If you turn on cloud backup, a copy is sent to our servers over an encrypted connection and stored encrypted (see Section 13). We process your business records solely to provide the Service to you and on your instructions: storing and returning your backup, delivering the share links you create (Section 15), and running the AI features you trigger (Section 7). We do not read your records for any other purpose, we do not use them for advertising or profiling, and we do not share or sell them. Legal basis: performance of the contract.
2.4 Instagram (optional)
If you connect Instagram, we receive only what the Instagram Login API returns under the instagram_business_basic scope: your Instagram user ID, username, display name, profile picture URL, follower/following counts, and the metadata of your recent posts (caption, like/comment counts, media URLs). We store this so the in-app Instagram screens load quickly; we never store your Instagram password, we have no access to your DMs, and we cannot post on your behalf without your explicit action. Legal basis: consent, which you give by connecting the account and can revoke at any time by disconnecting it in the app.
2.5 Subscription & receipt data
Subscriptions are sold and processed by the Apple App Store and Google Play. We never receive your payment-card details. We receive only the receipt metadata Apple/Google share with us (transaction ID, product ID, expiration date, renewal status) so we can unlock the right tier on your account. Legal basis: performance of the contract.
2.6 Files in share links (the "exchanger")
When you send a brand a share link to deliver files, those files are uploaded to our object storage (Cloudflare R2) so your recipient can view and download them. We retain them until you revoke the link, until it reaches an expiry date you chose to set, or until you delete your account; expired and revoked links are purged automatically together with their files. Recipients do not need an account: from them we collect only view and download events (timestamp and requesting IP address, used for delivery status and abuse prevention) and any feedback they choose to leave. Section 15 describes the full mechanics. Legal basis: performance of the contract.
2.7 Push notifications
If you allow notifications, we store the push token your device gives us (an APNS token on iOS, an FCM token on Android) so we can deliver deal-deadline reminders, share-opened and share-downloaded events, and other transactional notifications. Legal basis: consent, which you give in the OS-level permission prompt and can revoke at any time.
2.8 Product analytics
We collect first-party, anonymous event counts (screen views, feature use) tied to a random install identifier we generate on first launch. This identifier is not linked to your name or email. No third-party advertising SDK is embedded, there is no cross-app tracking, and we never request the IDFA or Google Advertising ID. Legal basis: our legitimate interest in understanding and improving the app.
2.9 Device & usage diagnostics
We log app crashes and basic technical telemetry (app version, OS version, device model, anonymous installation ID) so we can fix bugs. We use Sentry for crash reporting. We do not link this telemetry to your business records. Legal basis: our legitimate interest in keeping the app stable. You can object at any time (Section 11).
2.10 Email delivery metadata
Transactional emails sent through SendGrid carry standard delivery/open/click metadata so we can confirm delivery and detect outages. We do not use this for marketing profiling. Legal basis: legitimate interest in service reliability.
2.11 Support correspondence
If you email us, we keep the thread so we can respond and maintain a record of the issue. Legal basis: legitimate interest in providing support.
3. What we do not collect
- We do not collect your payment-card data — Apple and Google process payments and remit net payouts to us.
- We do not collect your contacts.
- We do not collect precise location or any sensor data.
- We do not access your photo library beyond the specific files you pick, or your microphone outside the moment you actively record; both only after you grant the OS permission.
- We do not embed any third-party advertising SDK, do not track you across other apps, and never request the IDFA or Google Advertising ID.
- We do not buy, sell, or rent personal data, and we do not use your content to train any third-party AI model.
4. Sensitive personal information (CCPA / CPRA)
We do not intentionally collect "sensitive personal information" as defined by California law (e.g., precise geolocation, government IDs, racial/ethnic origin, religion, union membership, health, sex life, contents of mail/email/text). If you voluntarily attach such content to a deal note or invoice, it inherits whatever storage mode you chose (local-only or encrypted cloud backup); in either mode we do not read it or use it for any purpose other than operating the Service. The tax-rate and filing-status fields you may enter in Settings are used only to compute your tax-savings estimate inside the app and are stored according to the backup mode you choose.
5. Your two storage choices
UGC Planner offers a clear, informed choice during onboarding and at any time in Settings → Backup & sync:
- On this device only. Your business records are stored only on your device and are not backed up to our servers; we hold no copy and cannot recover them for you. If you delete the app or change devices without exporting, that data is permanently lost. Choosing this mode does not switch off the features you actively use: files you place in a share link are still uploaded so your recipient can view them (Section 15), content you submit to an AI feature is processed as described in Section 7, and the diagnostics in Sections 2.8 and 2.9 apply in either mode.
- Encrypted cloud backup. A copy of your business records is sent to our servers over an encrypted connection (TLS) and stored encrypted: we apply an additional layer of application-level encryption (AES-256-GCM) before the backup is written to our database, on top of our providers' encryption at rest. To restore, sign in to your account on any device; no separate password or recovery phrase is needed. We do not read your backup and we do not share it: our systems decrypt it only to deliver it back to you, and access is restricted as described in Section 13.
Your content is yours. Whichever mode you choose, we process your business records solely to provide the Service to you and on your instructions. We do not read them for any other purpose, we do not use them for advertising, profiling, or model training, we do not sell them, and we disclose them to no one except the sub-processors listed in Section 8, acting on our behalf, and the recipients you yourself nominate through share links.
Account data (email, sign-in identifiers, refresh tokens), Instagram connection metadata, push tokens, and any files you placed in a share link are handled separately from this choice and are described in Section 2.
6. Purposes of processing & legal basis (GDPR)
For users in the EU, EEA, UK, and Switzerland, our legal basis under GDPR Article 6 for each processing activity:
- Providing the Service to you (account, sign-in, showing your data on your devices, storing and returning your backup, delivering share links to recipients you nominate, processing subscription state) — performance of a contract (Art. 6(1)(b)).
- Transactional notifications (deal-deadline reminders you scheduled, share-opened / share-downloaded events you opted into, receipts) — performance of a contract and your opt-in consent for the notification channel (Art. 6(1)(a) and 6(1)(b)).
- Instagram integration — your explicit consent when you tap "Connect Instagram" (Art. 6(1)(a)).
- AI features (Voice Fill, parsing, captions) — your explicit consent when you trigger the action (Art. 6(1)(a)).
- Diagnostics and product analytics — legitimate interest in keeping the app stable and improving it (Art. 6(1)(f)). You may object at any time (Section 11).
- Fraud prevention, security, abuse detection — legitimate interest (Art. 6(1)(f)) and legal obligation where applicable (Art. 6(1)(c)).
- Compliance with legal obligations (responding to lawful requests, tax record retention, App Store / Play Store policy compliance) — legal obligation (Art. 6(1)(c)).
We do not engage in solely-automated decision-making that produces legal or similarly significant effects on you (GDPR Art. 22).
7. AI features
Some features you trigger (Voice Fill, contract / brief parsing, caption drafting) send the specific content you submit to AI sub-processors (OpenAI and Anthropic) to return a result. We send only what is necessary for the request, the providers do not retain your prompt or output beyond the short windows required for abuse monitoring under their enterprise terms, and your content is not used to train any third-party model. AI features are opt-in by action: if you don't use them, no content is sent to them.
8. Sub-processors & disclosures
We use the following sub-processors strictly to operate the Service. Each is bound by a written data-processing agreement (or equivalent) that limits how they may use the data:
- Vercel — application hosting (United States)
- Neon — managed PostgreSQL database (United States, EU)
- Cloudflare R2 — object storage for backups and exchanger files (global edge)
- Apple Push Notification service — iOS push (United States)
- Firebase Cloud Messaging — Android push (Google, United States)
- SendGrid (Twilio) — transactional email (United States)
- Sentry — crash reporting and error monitoring (United States, EU)
- OpenAI, Anthropic — AI features you trigger (United States)
- logo.dev — brand logo lookup by domain
- Stripe — only if and when we sell anything outside the App Store / Google Play
- Apple App Store, Google Play — subscription billing and receipt validation
- Meta (Instagram Graph API) — only if you connect your Instagram account
We do not sell or share your personal information with third parties for cross-context behavioural advertising, and we do not show third-party advertising inside the app.
We disclose your data to a third party that is not listed above only when (i) you direct us to (for example, by sending a share link to a recipient), (ii) we are legally compelled to do so after a good-faith review of the request, or (iii) it is necessary to investigate or protect against fraud, abuse, or threats to the security or integrity of the Service.
9. International transfers
UGC Planner is operated from the United States; most sub-processors are US-based. When personal data of EU, EEA, UK, or Swiss residents is transferred outside their region, we rely on the EU Commission's Standard Contractual Clauses (SCCs) and equivalent UK/Swiss safeguards, together with the supplementary measures required by relevant data-protection authorities. We additionally apply technical safeguards (TLS in transit, encryption at rest, and application-level encryption of cloud backups as described in Section 13) to limit the data accessible to any party outside the EU/EEA/UK.
10. How long we keep things (retention)
- Account record: while your account exists. Deleted within 30 days of account deletion.
- Cloud backups: until you switch backup off or delete your account. Deleted within 30 days of deletion or switch-off.
- Exchanger files: until you revoke the link, it reaches an expiry you set, or you delete your account. An automated cleanup job runs hourly and permanently purges expired and revoked links together with their files.
- Instagram cached profile / posts snapshot: while your Instagram connection is active. Deleted on disconnect or account deletion.
- Subscription receipts (transaction IDs, plan, expiry): kept for the lifetime of the subscription plus 7 years to satisfy tax / accounting / audit obligations, in anonymised form where possible.
- Server logs: 90 days, then automatic purge.
- Push tokens: until your device unregisters or you disable notifications.
- Crash reports: 90 days in Sentry, then automatic purge.
- Support emails: 2 years from the last reply, unless we are required to keep them longer.
11. Your rights under GDPR (EU/EEA/UK)
If GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data (most fields are directly editable in the app);
- Erase your data (the "right to be forgotten"), via in-app account deletion or by email;
- Restrict processing in specified circumstances;
- Object to processing based on legitimate interests;
- Receive your data in a portable, machine-readable format;
- Withdraw consent at any time, where consent is the legal basis; withdrawal does not affect prior lawful processing;
- Lodge a complaint with your local supervisory authority. A list is available at edpb.europa.eu. We would also appreciate the chance to address your concern first.
To exercise any right, email support@ugcplanner.app from the address on your account. We respond within 30 days (extendable by a further 60 days for complex requests, with notice).
12. Your rights under CCPA / CPRA (California)
If you are a California resident, you have the right to:
- Know what categories of personal information we collect, the sources, the purposes, and the categories of third parties we share it with (this notice describes all of these);
- Access the specific pieces of personal information we have about you;
- Delete your personal information, subject to limited legal exceptions;
- Correct inaccurate personal information;
- Limit the use and disclosure of sensitive personal information — we do not use sensitive personal information for any purpose that triggers this right;
- Opt out of sale or sharing of personal information.
We do not sell or share your personal information as those terms are defined under California law, and there is therefore nothing to opt out of. We have not done so in the preceding 12 months.
You have the right to be free from retaliation for exercising any of these rights. You may use an authorized agent; we may require reasonable verification of authority. To submit a request, email support@ugcplanner.app with the subject "CCPA Request". We verify the request via the email on your account before fulfilling it.
Shine the Light (Cal. Civ. Code § 1798.83): California residents may request information regarding any disclosure of personal information to third parties for direct-marketing purposes. We do not engage in this disclosure, so the answer for the prior calendar year is "none."
13. How we protect your data
- TLS 1.3 for all network transport.
- Encryption at rest on Neon (managed Postgres) and Cloudflare R2.
- Application-level encryption (AES-256-GCM) for cloud backups before they are written to our database, with encryption keys stored separately from the data they protect and never exposed to client applications.
- Refresh tokens kept in the OS-level secure store (iOS Keychain, Android Keystore); short-lived access tokens live in memory only. We do not log sensitive values such as tokens or banking details.
- Access to production systems is restricted to what is strictly required to operate the Service, granted on the principle of least privilege, protected by scoped API tokens, and audit-logged.
- Sentry alerting on unusual error patterns; automated dependency-vulnerability monitoring.
When you use cloud backup, our systems decrypt your backup only to deliver it back to you when you sign in and restore. We do not read your business records and we do not share them.
Other data we hold (your email, sign-in tokens, push tokens, cached Instagram profile snapshot) is encrypted at rest by our infrastructure providers but is, by necessity, readable by our systems to operate the Service.
No system is perfectly secure. We notify affected users without undue delay if a personal-data breach is likely to result in a risk to your rights (GDPR Art. 33–34, and analogous US state laws).
14. Children
The Service is not directed to children under 13 (in the United States, under COPPA) or under 16 (in the EU / EEA, under GDPR). We do not knowingly collect personal information from children under those ages. If you believe a child has provided us personal information, email support@ugcplanner.app and we will delete it promptly.
15. Share links in detail (the exchanger)
When you generate a share link to deliver files to a brand:
- The files you placed in the link are uploaded to our Cloudflare R2 storage. The recipient sees only what you put in the link.
- Anyone with the link can open it until you revoke it or it reaches an expiry date you chose to set. You can password-protect the link, disable downloads, and revoke it at any time.
- We log view and download events (timestamp, file ID, requesting IP address, used for de-duplication and abuse prevention) and notify you via push and/or email if you opted in.
- Recipients are not registered users of UGC Planner; we collect from them only the technical metadata above plus any optional feedback they choose to leave. We do not require recipients to create an account.
- When the link expires or you revoke it, the files are permanently purged from storage by an automated job that runs hourly.
16. Changes to this policy
We may update this Privacy Policy as the Service evolves. Material changes will be announced in-app at least 14 days before they take effect. The "Last revised" date at the top reflects the most recent change.
17. Contact
Privacy questions, data-subject requests, or anything else: support@ugcplanner.app.
UP UGC Planner LLC · 1500 Chestnut Street, Suite 2 PMB 1081, Philadelphia, PA 19102, United States.