Privacy Policy
Effective Date: May 4, 2026 | Last Updated: May 4, 2026
Bone Dog Studios LLC ("we," "our," or "us") operates the Plan mobile application (the "App"). This Privacy Policy explains how we collect, use, and protect your information when you use our App.
By using Plan, you agree to the collection and use of information as described in this policy.
1. Information We Collect
Information You Provide
- Account Information: Email address, username, display name, and password (passwords are encrypted and never stored in plain text)
- Profile Information: Bio/description and profile avatar images
- Calendar Data: Event titles, notes, dates, times, and scheduling preferences
- Work Schedule Data: Schedule types, work days, start/end times, and day-level overrides
- Social Data: Connections with other users, groups, group memberships, event proposals, and shared events
Business Features (Subscription Required)
If you subscribe to Plan Business, we additionally collect:
- Business Profile: Business name, category, description, phone number, email, website, and address
- Location Data: Your business address is converted to geographic coordinates (latitude/longitude) to enable nearby business search for customers
- Services: Service names, descriptions, pricing, duration, and custom fields you define
- Client Information: Client notes, consultation preferences, and for clients not on Plan, optionally their name and phone number as provided by you
- Appointments: Appointment details including service, date/time, and messages between you and your customers
Information Collected Automatically
- Device Tokens: We collect push notification tokens to deliver notifications to your device. These tokens are associated with your account and device platform (Android or iOS).
- Device Location: When you use the business search feature, we request your device's GPS location to show nearby businesses. This location is used for the search query only and is not stored on our servers.
Information We Do NOT Collect
- We do not collect advertising identifiers
- We do not use analytics or tracking SDKs
- We do not access your contacts, phone book, or browsing history
- We do not collect health, fitness, or financial data
- We never see or store your payment card information (see Section 5)
2. How We Use Your Information
We use the information we collect to:
- Provide the App: Create and manage your account, display your calendar, manage connections and groups, and enable appointment booking
- Deliver Notifications: Send push notifications for connection requests, appointment updates, event proposals, and reminders you configure
- Enable Business Features: Display your business profile to potential customers, process appointment requests, and manage your client relationships
- Enable Search: Allow customers to find your business by name, category, or proximity (if you enable the searchable toggle)
- Improve the App: Fix bugs and improve performance based on error reports (we do not use third-party analytics services)
We do not use your information to:
- Serve advertisements
- Build advertising profiles
- Sell or share your data with data brokers, advertisers, or third parties for marketing purposes
3. How We Share Your Information
We share your information only in the following limited circumstances:
With Other Plan Users
- Connections: Users you connect with can see your display name, username, avatar, and (depending on your connection type) your calendar availability
- Groups: Group members can see your display name, avatar, and calendar availability within the group
- Business Profile: If you have a Plan Business subscription with the searchable toggle enabled, your business name, category, description, contact information, and services are visible to other authenticated Plan users
With Service Providers
We use the following third-party services to operate the App:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, file storage | All account and app data (encrypted in transit and at rest) |
| Firebase Cloud Messaging | Push notification delivery | Device tokens and notification content |
| RevenueCat | Subscription billing management | Your user ID and subscription status (RevenueCat does not receive your personal data) |
| Apple App Store / Google Play Store | Payment processing | Payment is handled entirely by Apple/Google; we never receive your payment details |
As Required by Law
We may disclose your information if required to do so by law, regulation, legal process, or governmental request.
4. Data Storage and Security
- All data is stored on Supabase infrastructure, which uses encrypted connections (TLS) and encrypts data at rest
- Passwords are hashed using Supabase Auth's built-in bcrypt hashing — we cannot read your password
- Biometric credentials (if enabled) are stored locally on your device using platform-secure storage (iOS Keychain / Android Keystore) and are never transmitted to our servers
- Avatar images are stored in Supabase Storage with access controlled by row-level security policies
- Database access is protected by row-level security — users can only access their own data and data explicitly shared with them
5. Payments and Subscriptions
Plan Business is available as a paid subscription. All payments are processed through Apple App Store (iOS) or Google Play Store (Android). We use RevenueCat to manage subscription state.
- We never receive, process, or store your credit card number, bank account, or other payment instrument details
- Apple and Google handle all payment processing, receipts, and refunds
- RevenueCat receives only your anonymous user ID and subscription status — not your name, email, or payment details
- Subscription management (cancellation, plan changes) is handled through your Apple ID or Google Play account settings
6. Your Choices and Rights
Account Data
- Access: You can view all your data within the App at any time
- Edit: You can update your profile, business information, and preferences at any time
- Delete: You can request account deletion by contacting us at admin@bonedogstudios.com. We will delete your account and all associated data within 30 days. Some data may be retained in encrypted backups for up to 90 days.
Notifications
- You can control which notifications you receive in the App's notification settings
- You can disable push notifications entirely through your device settings
- You can configure quiet hours to prevent notifications during specific times
Business Visibility
- You can toggle your business profile's searchable setting to control whether your business appears in search results
- If your subscription expires, your business is automatically hidden from search
Location
- Location access is requested only when you use the business search feature
- You can deny or revoke location permission at any time through your device settings
- The App functions fully without location access (search results will not include distance information)
7. Data Retention
- Active Accounts: We retain your data for as long as your account is active
- Calendar Events: Events older than 90 days are automatically cleaned up
- Expired Proposals and Shares: Automatically deleted 7 days after expiration
- Push Notification Queue: Processed notifications are deleted after 7 days
- Deleted Accounts: All data is deleted within 30 days of account deletion request, with encrypted backups retained for up to 90 days
8. Children's Privacy
Plan is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us at admin@bonedogstudios.com and we will promptly delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy in the App or sending a push notification. The "Last Updated" date at the top of this policy indicates when it was last revised.
Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: admin@bonedogstudios.com