Last updated: August 24, 2026
This Privacy Policy explains how PlanMinds Inc. (PlanMinds, we, us) collects, uses, discloses, and protects information when you use the PlanMinds platform, including IIVY and PlanCheck (the Service).
We use your information solely to operate, secure, and improve the Service, including to:
The Service uses artificial intelligence to read documents, draft communications, and produce plan-review findings.
PlanMinds runs its own custom models on Google’s AI infrastructure. Your project content and communications are transmitted to Google in order to be processed.
We do not use your project content, communications, or documents to train our models. Our custom models are tuned on our own non-customer material, never on your data. Our agreements with AI providers prohibit them from using your content to train their models, and we use paid commercial API tiers specifically because they carry those terms.
IIVY grounds its answers and actions in your project’s own record, and every action it takes is recorded in that record and attributable to the person or rule that authorized it.
We use the following third parties to provide the Service. Each processes data on our behalf under contractual confidentiality and security obligations. This list is current as of the date above; we will update it when it changes.
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Supabase | Primary database, authentication, and file storage | Account information, project content, communications, usage data |
| Microsoft Azure | Application hosting, compute, caching, and diagnostics | All categories, in transit and in process |
| Hosts and serves PlanMinds custom AI models | Project content, communications | |
| Telnyx | SMS, voice, and WhatsApp delivery | Phone numbers, message contents, call audio |
| ElevenLabs | Voice synthesis for phone calls | Call content and transcripts |
| Resend | Transactional and project email delivery | Email addresses and message contents |
| Stripe | Payment processing | Billing identity and payment records. PlanMinds does not receive or store your card details. |
Project data is siloed per project and private per principal. Each person sees only what they have been granted, enforced by fail-closed access controls in our database — access is denied by default and permitted only by explicit grant.
IIVY is always disclosed as an AI teammate on any communication and never impersonates a person.
We do not sell your information. We share it only:
We protect your data in transit using TLS on every connection, and at rest using the encryption provided by our infrastructure providers. Files are never publicly accessible; every file read and upload passes through a short-lived, expiring signed link.
Access to production systems requires multi-factor authentication. We maintain administrative, technical, and physical safeguards designed to protect your information.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
PlanMinds is a Canadian company. Our application infrastructure and primary data storage are hosted in Canada — application compute and caching in Microsoft Azure’s Canada Central region, and our primary database and file storage in Supabase’s Canada Central region.
Some sub-processors listed in Section 4, including AI, communications, and payment providers, process data in the United States and other jurisdictions. By using the Service, you understand that your information may be processed outside Canada, where it may be subject to the laws of those jurisdictions.
We retain your information for as long as your account is active and for as long as needed to provide the Service, resolve disputes, and meet our legal, tax, and audit obligations.
You may delete project content at any time through the Service. Deleting a project removes its stored files from our systems.
Backups are retained on a rolling basis for disaster recovery and are overwritten in the ordinary course. Content deleted from the live Service may persist in backups until those backups age out.
Subject to applicable law, you may:
If we become aware of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, as required by PIPEDA, and will tell you what happened, what information was involved, and what we are doing about it.
The Service uses essential cookies necessary for authentication and session management. We do not use cookies for advertising and we do not sell information collected through them.
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. We will post the updated policy on the Service and update the Last updated date above. For material changes we will provide additional notice. Your continued use of the Service after any change constitutes acceptance of the updated policy.
Questions about this document? Contact us: