Planther Privacy Policy

Last updated: 11 September 2026

This Privacy Policy explains how Planther Ltd ("Planther", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Planther platform, websites, and related services (the "Service"), and tells you about your rights under UK data protection law.

This policy should be read alongside our Terms of Service.


1. Who we are

Planther Ltd is the data controller responsible for the personal data described in this policy.

  • Company: Planther Ltd, registered in England and Wales (company number 17249378)
  • Registered office: 1 Stocks Bridge Way, St. Ives, Cambridgeshire, England, PE27 5JL
  • ICO registration: Planther Ltd is registered with the UK Information Commissioner's Office, registration reference ZC221095
  • Privacy contact: privacy@planther.co.uk

We have not appointed a data protection officer, as we are not required to do so. The privacy contact above is responsible for overseeing questions about this policy.

2. Who this policy applies to, and our role

2.1. Planther is a professional tool for businesses. The individuals whose personal data we process are primarily our customers, their employees, and other authorised users of the Service.

2.2. Our role as controller. For the personal data we collect to operate the Service, manage accounts, communicate with you, and run our business, Planther is the data controller.

2.3. Our role as processor. You bring your own materials into the Service in two ways: by uploading or typing them in (for example project files or instructions), and by connecting a third-party system you already use so that the Service can read from it on your behalf (for example a work mailbox, described in clause 5.6). Where those materials contain personal data relating to your own clients, colleagues, or other third parties, you are the data controller for that personal data and Planther acts as your data processor, processing it on your instructions to provide the Service. You are responsible for ensuring you have a lawful basis to provide that personal data to us, or to give us access to it, and to have it processed through the Service. Where a separate written agreement between us includes data processing terms, those terms govern this processing.

2.4. People who never deal with us. Some features let you bring in material about people who have never used the Service and have not dealt with us directly, such as the senders and recipients of emails in a mailbox you connect. We process that personal data only to provide the Service to you and only on your instructions. As the controller, it is for you to make sure there is a lawful basis for it and to meet any duties you owe those people.

3. The personal data we collect

We collect and process the following categories of personal data:

  • Account and identity data: your name, email address, password (stored in hashed form by our authentication provider), and your organisation membership and role.
  • Business and contact data: the contact and company details we use to set up your account, correspond with you, and issue invoices.
  • Content data: the conversations, questions, instructions, and project files you submit to the Service, and the outputs generated for you. This content may itself contain personal data that you choose to include.
  • Connected mailbox data: where you connect a work mailbox (see clause 5.6), the messages, threads, senders, recipients, subjects, dates, and attachment names that the Service reads on your instruction, and the drafts it creates for you. We also hold the mailbox address and the encrypted credentials that keep the connection open.
  • Usage and analytics data: information about how you use the Service, including activity, requests, features used, and associated processing and cost metrics.
  • Technical data: your IP address, device and browser information, log data, and signals from our security and anti-abuse measures (such as rate limiting and account verification checks).
  • Support and correspondence data: the content of messages you send us and our responses.
  • Marketing data: your preferences for receiving marketing from us, and your subscription status if you join a mailing list.

We do not intentionally collect special category personal data. Please do not submit special category data through the Service unless it is necessary and you have a lawful basis to do so.

4. How we use personal data, and our lawful bases

We use personal data for the purposes below, relying on the following lawful bases under UK GDPR:

PurposeLawful basis
Creating and administering your account; providing the Service and its featuresPerformance of a contract
Communicating with you about the Service, including service and security noticesPerformance of a contract; legitimate interests (keeping you informed)
Securing the Service, preventing and investigating misuse, fraud, abuse, and breaches of our licence termsLegitimate interests (protecting our Service and users)
Providing support, investigating faults and bug reports, and checking the quality of outputsPerformance of a contract; legitimate interests (supporting and improving the Service)
Operating, analysing, maintaining, and improving the Service, including evaluating and improving our AI models and prompts using aggregated and anonymised dataLegitimate interests (improving and developing our Service)
Sending marketing communications to business contacts about our products and servicesLegitimate interests (B2B marketing), or consent where required
Issuing invoices and keeping accounting and tax recordsPerformance of a contract; legal obligation
Responding to legal requests and enforcing our TermsLegal obligation; legitimate interests (protecting our rights)

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights. You can ask us for more information about this assessment.

5. AI processing and your content

5.1. The Service uses artificial intelligence to process your inputs and generate outputs. To do this, your content is processed by us and by the third-party providers that power the Service (see section 8).

5.2. We do not use your content to train third-party AI models beyond what is necessary to provide the Service to you.

5.3. We may use aggregated and anonymised data derived from use of the Service to operate, analyse, and improve the Service, including to evaluate and improve our AI models and prompts. Aggregated and anonymised data does not identify you or any individual, and cannot be used to reconstruct your confidential content.

5.4. Opt out. You may opt out of the use of data derived from your use of the Service for the improvement and evaluation of AI models and prompts by contacting us at privacy@planther.co.uk.

5.5. Staff access to content. A small number of authorised Planther staff may view the content of conversations, projects, and support messages where this is needed to answer a support request, investigate a fault or bug report you have submitted, or check the quality and safety of the Service's outputs. Access is limited to the staff who need it, and they are bound by confidentiality obligations. Please do not include anything in the Service that you would not want an authorised member of our team to see in the course of supporting you.

5.6. Connected mailboxes. The Service can be connected to a work mailbox, so that you can ask it about an email and have it prepare a reply for you. No mailbox is connected as standard: connecting one is your choice and is off unless you turn it on, and your organisation's IT administrator controls whether anyone in your organisation may turn it on at all. In a standard Microsoft 365 setup that permission is blocked until the administrator approves Planther for your organisation, and they can withdraw it again at any time. Your organisation can also switch the feature off inside the Service for everyone in it. This is what it means:

  • What the Service can do. It can search your mailbox, read a message and the thread it belongs to, and put a draft reply in your Drafts folder for you to review and send yourself. It cannot send email: we never ask your provider for permission to send, so sending is not possible. Creating a draft requires a broader read-and-write permission from the provider, because a draft-only permission is not offered. We use it only to read messages and create drafts, and the Service has no feature that sends, deletes, moves, or forwards your mail.
  • Where the data comes from. The mailbox provider we support is Microsoft 365. We read your mailbox through the Microsoft Graph API, using the access that you, or your organisation's IT administrator, approve when the connection is made. Microsoft is your provider, not ours; see clause 8.5.
  • What that content contains. Email is your correspondence with your clients, colleagues, and other third parties, and it routinely contains personal data about people who have no relationship with us. You are the data controller for it and we are your processor, as set out in clauses 2.3 and 2.4.
  • Where it goes. When you use a feature that reads your mailbox, the email content the Service retrieves is handled like the rest of that conversation: it is sent to the AI providers described in section 8 so that an answer or a draft can be produced, and it may be stored with the conversation in your account. We do not copy, synchronise, or index your mailbox as a whole - we read only what is needed to answer what you have asked.
  • Turning it off. You can disconnect at any time in the Service's settings, which deletes the credentials we hold. You can also withdraw Planther's access from your own Microsoft account, and your IT administrator can withdraw it for your whole organisation, or ask us to switch the feature off for your organisation inside the Service.

6. Marketing

6.1. We may send you marketing communications about our products and services where we are permitted to do so, for example to existing business customers on the basis of our legitimate interests, or with your consent where required.

6.2. You can opt out of marketing at any time by using the unsubscribe link in our messages or by contacting us at privacy@planther.co.uk. Opting out of marketing does not stop service-related messages that we need to send you to operate your account.

7. Cookies and similar technologies

7.1. We use cookies and similar technologies on our websites and in the Service.

7.2. Essential cookies are necessary for the Service to function, including for authentication, session management, and security. These are always active and do not require your consent.

7.3. We intend to introduce analytics and marketing cookies to help us understand how our websites are used and to support our marketing. Where we do, we will only set non-essential cookies with your consent, and we will provide a cookie banner and controls so you can manage your preferences.

8. Who we share personal data with

8.1. We share personal data with trusted third-party service providers (sub-processors) who process it on our behalf to deliver the Service. These fall into the following categories:

  • Cloud hosting and infrastructure providers: for hosting the Service, storing data, authentication, and running our systems (including Google and Supabase).

  • AI and processing providers: for processing requests and powering the Service's features (including OpenRouter and the model providers it routes to, and other technology partners). Where you use a feature that reads a connected mailbox, email content forms part of what is sent to these providers.

  • Search and indexing providers: for storing and searching indexed extracts of your content so the Service can retrieve relevant material (including Pinecone).

  • Email and communications providers: for sending account, service, and notification emails (including Resend).

  • Mapping providers: for displaying maps and locations (including Google).

  • Security and anti-abuse providers: for protecting the Service against misuse, including account verification and rate limiting (including Google).

  • Monitoring providers: for diagnostics and error monitoring (when enabled).

    8.2. We require our providers to protect personal data and to process it only on our instructions and in line with applicable law.

    8.3. We may also share personal data: with our professional advisers (such as accountants and lawyers); with authorities or other parties where required by law or to protect our rights; and with a buyer or successor in the event of a merger, acquisition, or sale of our business assets.

    8.4. We do not sell your personal data.

    8.5. Connected third-party systems. Where you connect a third-party system to the Service, such as a Microsoft 365 mailbox, that system's provider is your provider rather than our sub-processor: we read from it on your instruction, using the access you or your IT administrator grants, and we have no relationship with it independent of you. Microsoft is the source of the email content described in clause 5.6. Once that content is in the Service, the sub-processors it reaches are OpenRouter and the model providers it routes to, together with the hosting and indexing providers listed above.

9. International transfers

9.1. Some of our service providers are based outside the United Kingdom, including in the United States. This means your personal data may be transferred to and processed outside the UK.

9.2. Where personal data is transferred outside the UK, we take steps to ensure it remains protected to a standard consistent with UK data protection law. We rely on appropriate safeguards recognised under UK GDPR, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the International Data Transfer Addendum to the EU Standard Contractual Clauses. You can contact us at privacy@planther.co.uk for more information about the safeguards we use.

10. How long we keep personal data

10.1. We keep personal data only for as long as we need it for the purposes set out in this policy.

10.2. In general:

  • Account and content data is kept for the life of your account, and for up to 30 days after your account is closed to allow for an orderly wind-down, after which it is deleted or anonymised, unless we are required to keep it for longer.

  • Invoicing and accounting records are kept for seven (7) years to meet UK tax and accounting requirements.

  • Connected account credentials are kept until you disconnect the account or your provider withdraws our access, and are deleted when you disconnect. Email content that has been brought into a conversation is kept with that conversation and follows the account and content data rule above.

  • Technical, security, and log data is kept for as long as needed for security and operational purposes.

    10.3. We may retain personal data for longer where required by law or to establish, exercise, or defend legal claims.

11. How we protect personal data

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration, including access controls, authentication, and the use of reputable infrastructure providers. No system is completely secure, and we cannot guarantee absolute security, but we work to protect your personal data and to respond appropriately to any security incident.

12. Your rights

12.1. Under UK data protection law, you have the right to:

  • access the personal data we hold about you;

  • request rectification of inaccurate or incomplete data;

  • request erasure of your data in certain circumstances;

  • request restriction of processing in certain circumstances;

  • object to processing based on our legitimate interests, and to direct marketing at any time;

  • request portability of certain data; and

  • where we rely on consent, withdraw that consent at any time.

    12.2. To exercise any of these rights, contact us at privacy@planther.co.uk. We may need to verify your identity before responding. We will respond within the time limits required by law.

    12.3. Where Planther processes personal data as a processor on behalf of a customer (see clause 2.3), requests from individuals relating to that data should be directed to the relevant customer as the controller, and we will assist that customer as required.

    12.4. You have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at ico.org.uk. We would, however, appreciate the chance to address your concerns first, so please consider contacting us before you do.

13. Children

The Service is intended for use by businesses and professionals and is not directed at children. You must be at least 18 years old to use the Service. We do not knowingly collect personal data relating to children.

14. Changes to this policy

We may update this policy from time to time. Where changes are material, we will take reasonable steps to notify you. The "Last updated" date at the top of this policy shows when it was last revised. Your continued use of the Service after an update constitutes acceptance of the revised policy.

15. Contact us

If you have any questions about this policy or how we handle personal data, please contact us:

Planther Ltd 1 Stocks Bridge Way, St. Ives, Cambridgeshire, England, PE27 5JL Privacy: privacy@planther.co.uk