Privacy notice.
Written in plain language so you can read it. If anything is unclear, write to us at hello@planoptica.com.
Last updated May 2026.
The short version
- We collect what we need to run your account, bill you, and keep the service working. Nothing more.
- We don't sell or rent your data, run third-party ads, or place tracking pixels for ad networks.
- The Form 5500 data the product is built on is already public record. It is not personal data of yours.
- You can export, correct, or delete your account from your profile, or ask us to do it for you.
What we collect and why
Three categories of personal data flow through PlanOptica. We list each, the reason we hold it, and what we'd do with less.
- Account information. Your name, email, team membership, and password hash. Captured when you sign up or accept a team invitation. We use it to authenticate you, scope what you can see, and email you about the service. We can't run an account without it.
- Billing information. Subscription tier, plan history, and the last four digits of the card on file. The full card and the charge itself are handled by Stripe (see Subprocessors); we don't store full card numbers ourselves. We use it to bill you, send receipts, and resolve disputes.
- Operational logs.Server access logs of the form "account X requested URL Y at time Z," retained briefly for security, debugging, and abuse prevention. We don't mine logs for marketing.
We do not collect special-category data (health, biometric, political, religious, etc.). If you put any in a free-text field by accident, write to us and we will remove it.
What we don't do
- We don't sell or rent personal data to third parties.
- We don't run third-party advertising on the product and don't place ad-network tracking pixels.
- We don't share your usage with data brokers or enrichment vendors.
- We don't train machine-learning models on your saved searches, exports, or account activity.
About the Form 5500 data
The retirement and welfare plan data inside the product comes from public Form 5500 filings published by the U.S. Department of Labor. ERISA requires plan sponsors to file; the filings are public record once EFAST2 processes them.
That data is about plan sponsors and service providers, not about you as a logged-in user. It isn't covered by the rights described below; if you have questions about a specific filing, take them to the sponsor or to the Department of Labor directly.
When we share data
We share personal data in three narrow circumstances:
- With subprocessors we rely on to run the service (listed below). They are bound by contract to use it only on our instructions.
- With your team admin or members, for account information visible inside a team workspace you've joined.
- When required by law, in response to a valid legal process. We push back where the request is overbroad and notify you where we're permitted to.
We do not share data with affiliates, partners, or advertisers for marketing purposes. There are no such arrangements.
Subprocessors
A subprocessor is a third-party vendor we ask to handle personal data on our behalf. Our current list:
- Stripe - payment processing and card-on-file storage. Receives billing identifiers, card details, and charge events.
- Resend - transactional email (sign-in links, receipts, account notifications). Receives email address and message content.
- Cloud infrastructure provider - hosts the application, database, and authentication services. Receives whatever PlanOptica writes to disk and the network traffic that reaches it.
We update this list when it changes. If you're on a team plan and need a current copy with contracted terms for a vendor security review, write to us.
Security and storage
Personal data is encrypted in transit (TLS) and at rest. Application access is gated by single-tenant authentication; production database access is restricted to the engineers who operate the service. Backups are encrypted with the same scheme as live data.
No system is perfect. If you find a security issue, write to hello@planoptica.com with the words "security" in the subject line and we will reply within one business day.
Retention
We hold personal data only as long as we need it.
- Account information. Held while your account is active, plus 30 days after you delete it for recovery.
- Billing records. Held for seven years to meet US tax and accounting requirements.
- Operational logs. Held for up to 90 days, then automatically purged.
- Saved searches and exports. Held while your account is active. Deleted with your account unless you transfer them to a teammate first.
Your rights and choices
Wherever you sit, you have the same set of rights over your personal data:
- Access - ask for a copy of what we hold.
- Correct - update anything that's wrong, directly from your profile.
- Delete - close your account and have the underlying data removed.
- Export - download your saved searches, saved plans, and account information.
- Object or restrict - tell us not to process your data for a specific purpose.
Exercise any of these by emailing hello@planoptica.com or from your account profile. We respond within 30 days. We won't charge you for the request.
Residents of California (CCPA/CPRA), the European Economic Area, and the United Kingdom have these rights under their local privacy law; the rights above apply equally to you. You also have the right to lodge a complaint with your local supervisory authority.
Cookies and analytics
We use a small number of strictly necessary cookies to keep you signed in and to remember preferences (chart density, saved-view defaults). We do not use third-party advertising cookies, and we do not run third-party analytics scripts that track you across the web.
You can clear cookies in your browser at any time; you'll need to sign in again on your next visit.
International transfers
PlanOptica is operated from the United States and the data lives in the United States. If you're outside the US, using the product means your data will be transferred here. Where applicable, we rely on standard contractual clauses with our subprocessors to provide an adequate level of protection for transfers out of the EEA, UK, and Switzerland.
Children
The product is built for working professionals (advisors, brokers, consultants) and is not directed at children under 16. We don't knowingly collect data from children. If you believe we have, write to us and we will delete it.
Changes to this notice
We update this notice when the product or our practices change. Material changes are announced in the product or by email at least 14 days before they take effect; small clarifications are posted with a revised "Last updated" date. The current version is always at this URL.
Contact us
Questions, requests, or pushback on anything above: email hello@planoptica.com. We read everything that comes in.
For postal mail, write to PlanOptica, c/o the founder, via the contact email above to request the current mailing address.