Privacy Policy
Last updated 26 August 2026.
1. Who handles your data
Figplanner decides what happens to the data described below. Figplanner is operated by fseudo labs, a business registered in Malaysia. Write to hello@figplanner.com about anything on this page, including a request to see or to delete your data.
2. What Figplanner collects
When you sign in with Google, Figplanner receives your email address, your name and the address of your Google profile picture. It keeps the email address and the name. It does not keep the picture.
Figplanner also keeps the account identifier Google issues. It is what makes a later sign-in reach the same account, even after you change the address on your Google account. It is deleted with the account.
The rest is what you type. That is the titles, descriptions, colours and checklist items of your tasks, the days and times you place them at, your working hours, and your display settings.
Figplanner records some data you do not type.
- Your session is held in Redis, and it does not record an IP address or a browser user agent.
- Your IP address is used while you sign in, to count failed attempts from one address so they can be slowed down, and it is not written to your account or to the planner database.
- Your account holds a password hash, and a two-factor secret with recovery codes if you turned two-factor on.
- A passkey, if you registered one, is kept in a separate table and linked to your account.
- Your timezone is stored, because the planner cannot place a week without it.
- The time you last opened the planner is stored, so that Figplanner stops asking Google for the calendars of an account nobody is looking at.
If you connect a calendar, Figplanner also keeps what it reads from it. Nothing here exists until you connect one, and section 3 says what connecting asks for.
- The address of the Google account you connect, if Google gives one, so that the Calendars tab can show you which account is connected before you disconnect it. The account identifier Google issues is kept beside it, because the address can change and the identifier cannot.
- The name and the colour of each calendar on the account you connect, so you can choose which of them the planner should use.
- For each calendar you choose: the title of every event between the start of last month and three months ahead, its start and end, whether it lasts all day, whether it has been cancelled, whether it marks you busy or free, and whether you accepted it.
- Nothing else from the event is kept. Google's answer carries more than that — the guests, the description, the location, the attachments, the meeting link — and Figplanner writes none of it down. It reads the guest list only to find your own reply in it, and keeps the reply rather than the list.
- The access token and the refresh token Google issues, which are what let the planner keep reading the calendar you chose.
A meeting can be about other people, and its title can name them. Those people have no account here and no way to know this copy exists, so Figplanner keeps as little of it as a calendar can be read with: the title and the hours, never the guest list. The copy is used to draw your week and for nothing else, it is never shown to anybody but you, and it goes when you untick the calendar, disconnect it, or delete your account.
3. Google user data
Figplanner asks Google for two separate things, at two separate moments, and the second one is optional.
Signing in is the first. It requests three scopes: openid, profile and email. They identify you, and they are what lets Figplanner find the account that is yours or create one on your first visit. Signing in asks for nothing else.
Connecting a calendar is the second. It is a Pro feature, you start it yourself from the Calendars tab in settings, and it requests one further scope: https://www.googleapis.com/auth/calendar.readonly. That scope is read-only. Figplanner can read the calendars on your Google account and the events in them; it cannot create an event, change one, or delete one, and it never writes anything back to Google.
That consent also asks Google for offline access, so Figplanner receives a refresh token as well as an access token. It is what lets the planner keep your week up to date while you are not looking at it. Section 10 says how to take that access away.
Figplanner does not read your files or your mail, and asks Google for no permission that would let it. If that ever changes, this section changes with it.
4. Limited Use
Figplanner's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. How Figplanner uses your data
Figplanner uses your data to run the planner and to write to you about your account. It is not used for advertising. It is not sold, and it is not given to a data broker.
6. Why Figplanner may use it
Figplanner uses your data because it cannot give you the service without it. Your account, your tasks and your working hours are what the planner is made of, and with none of them there is nothing to show you.
Two things sit outside that. Your IP address is used while you sign in, to slow down repeated failed attempts, because a service open to the public has to defend its sign-in form. Messages are sent to you about the account itself — a verification link, a password reset — because the account does not work without them.
Where the law of your country asks for a legal basis by name, these are performance of a contract and legitimate interest.
Connecting a calendar is the one place you give a permission, and you give it to Google rather than to Figplanner. You can take it back at any time, and section 10 says how. Nothing else in this notice waits on a permission from you, so there is nothing else to take back.
7. Where data goes
Google holds the sign-in, because Google performs it, and holds the calendar itself if you connect one. Laravel Cloud holds the servers and the database the planner runs on, in its Singapore region. Paddle will hold the payment details once Pro goes on sale, because Paddle takes the payment and Figplanner never sees a card number.
Resend sends the messages. A verification link or a password reset passes through Resend with the address it is addressed to, and Resend holds nothing else about you.
Every company named above is outside Malaysia, so your data is processed outside Malaysia. Google and Paddle each choose where they process what they hold.
8. Cookies and browser storage
Figplanner sets these cookies.
- The session cookie keeps you signed in between requests.
- The XSRF-TOKEN cookie holds the token that protects forms against cross-site request forgery.
- The appearance cookie remembers whether you chose the light theme or the dark one, and it lasts a year.
- The backlog_state cookie remembers whether the backlog drawer was open, and it lasts a week.
Your theme choice is also written to browser storage, under the localStorage key appearance, so the planner can apply it before the page is drawn.
No advertising cookie and no analytics cookie is set, on this page or in the planner.
9. How data is protected
Your password is never stored in a form anybody can read. It is kept as a bcrypt hash, so a copy of the database does not hand over a password. Two-factor authentication and passkeys are both available, and turning either on is the strongest single thing you can do for your own account.
The site is served over HTTPS. Repeated failed sign-in attempts are slowed down.
No system is beyond reach, and this notice does not pretend otherwise. Figplanner does not promise that a breach cannot happen. It promises to tell you if one happens to your data, at the address on your account.
10. Retention and deletion
Your data is kept while the account exists. You can delete the account from the settings screen at any time, and deleting it deletes the tasks, the checklists and the working hours with it.
Deletion is immediate, and it is not a flag on a row that stays. The account record is removed, and the database removes the tasks, their checklists, the working hours and any passkey along with it. Nothing in the application can bring them back.
A backup can still hold a copy for a short time afterwards. The hosting provider keeps rolling database backups, and none is kept more than seven days, so a record you delete today is gone from the application at once and out of the last backup within a week.
A calendar you connected has its own rules. Unticking a calendar in settings deletes the events Figplanner stored from it, at once and for good. Deleting your account deletes the connection itself, along with every calendar, every stored event, and the tokens that allowed the reading.
You can also disconnect the calendar on its own, from the Calendars tab in settings. Figplanner tells Google to withdraw the permission, then deletes the connection, its calendars, its stored events and its tokens. If Google cannot be reached at that moment the connection is still removed here, and Figplanner tells you so, so that you can withdraw the permission yourself at your Google account's permissions page. That page is always open to you, whether or not you use the button.
A connection you stop using does not wait for ever. If you do not open the planner for 6 months, Figplanner withdraws the calendar permission at Google and deletes the connection, its calendars, its stored events and its tokens. Your account, your tasks and your working hours are not touched, and you can connect a calendar again whenever you come back. No message is sent before this happens.
11. Your rights
Two of these you do yourself, without asking. The Profile tab in settings has a button that downloads everything Figplanner holds about your account, as a file you can keep or take somewhere else, and another that deletes the account outright.
You can also ask to see the data held about you, to have it corrected, or to have it deleted. You can ask that a use of it be paused while a disagreement about it is settled. You can object to a use you disagree with. Write to hello@figplanner.com from the address on the account, and you will have an answer within 30 days.
Giving this data is part of having an account rather than a choice inside it. Without an email address there is nobody to verify, and without a timezone there is no week to draw, so an account cannot be created without them. Nothing else is asked of you.
No decision about you is made automatically. Figplanner does not profile you, score you, or sort you into a group, and nothing in the planner changes on its own because of what it has learnt about you.
If that answer does not satisfy you, you can complain to the data protection authority where you live. In Malaysia that is the Personal Data Protection Department.
12. Children
Figplanner is not for children. An account requires you to be at least 16, as the terms say. Figplanner does not knowingly collect data from anybody younger, and an account found to belong to somebody younger is deleted.
13. Changes to this notice
This notice can change. A material change is announced by email, to the address on your account. The date at the top of this page says when the document last changed.