It’s a Plan
Legal

Privacy Policy

Last updated: 21 July 2026

1. Who we are

It's a Plan is an issue tracker for software teams. The hosted service at itsaplan.dev is operated by VIBE DEV SPACE LLC, 5830 E 2nd St, Ste 7000 #28620, Casper, Wyoming 82609, US. This policy explains what data the hosted service collects, why, how long it is kept, and who it is shared with.

The software is also open source and can be self-hosted. When you use an instance run by someone else, that operator controls your data and publishes its own policy. This policy covers only the hosted service.

2. Google user data we access

When you choose “Continue with Google”, Google asks for your consent and then returns a limited profile to us. We request only these scopes:

  • openidA stable Google account identifier, used to recognise you on later sign-ins.
  • emailYour email address and whether Google has verified it.
  • profileYour name and the URL of your profile picture.

We do not request access to Gmail, Drive, Calendar, Contacts, Photos or any other Google service. We cannot read, send or modify your files or messages. Signing in with Google is optional: the service also supports email and password, a sign-in link sent by email, and passkeys.

3. How we use Google user data

  • The Google account identifier links your Google account to your It's a Plan account so that you sign in to the same account each time.
  • Your email address identifies your account, matches invitations addressed to you, and delivers the notifications you have turned on.
  • Your name and profile picture are shown to other members of the projects you belong to, next to your issues, comments and activity.

We use this data only to operate the service. We do not use it for advertising, profiling, credit decisions or automated decision-making, and no human at VIBE DEV SPACE LLC reads it except where you ask us for support or where the law requires it.

4. Other data we collect

  • Content you create: projects, issues, comments, attachments, custom fields and the settings of your workspace.
  • Account and security data: password hashes for password sign-in, passkey public keys, session records, and the API keys you generate.
  • Operational logs: IP address, browser user agent and request timestamps, kept to run the service and investigate abuse.

5. Storage and retention

Data is stored in a PostgreSQL database on servers we rent from our hosting provider. It is encrypted in transit with TLS. Credentials and third-party secrets stored by the application are encrypted at rest with AES-256-GCM.

We keep your data while your account exists. When your account is deleted, your profile data, including everything received from Google, is erased within 30 days. Content you created inside a project may remain in that project for the other members, with your authorship shown as a removed user, unless you ask us to delete it. Operational logs are kept for up to 90 days.

6. Sharing

We do not sell, rent or trade your data, and we do not transfer Google user data to advertising platforms, data brokers or information resellers.

We share data only with the providers that run the service on our behalf: our hosting provider, and the email provider that delivers sign-in links and notifications. Each processes the data under contract and only on our instructions. We may also disclose data where the law requires it.

Other members of a project you join can see your name, profile picture, email address and the work you record in that project.

7. Limited use of Google user data

It's a Plan’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Your choices and rights

  • You can view and edit your name, email address and picture in your account settings at any time.
  • To delete your account and the data attached to it, email us at [email protected] from the address on the account. We complete the deletion within 30 days.
  • You can revoke our access to your Google account at any time at myaccount.google.com/permissions. Doing so ends Google sign-in for your account; set a password first if you still want to sign in.
  • Depending on where you live, you can ask us for a copy of your data, ask us to correct or delete it, or object to how we use it. Write to the address below and we will answer within 30 days.

9. Cookies

We set a session cookie so you stay signed in, and store your theme and layout preferences in your browser. These are required for the service to work. We do not use advertising or cross-site tracking cookies.

10. Security

Access to production data is limited to the people who operate the service and is logged. We use encryption in transit and at rest, and review dependencies for known vulnerabilities. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.

11. Children

The service is not directed to children under 16, and we do not knowingly collect their data.

12. Self-hosted deployments

The source code is available under AGPL-3.0. If you run your own instance, you are the controller of the data in it: you register your own Google OAuth client, publish your own privacy policy on your own domain, and VIBE DEV SPACE LLC receives no data from your instance.

13. Changes

We post changes on this page and update the date at the top. If a change materially affects how we use your data, we will tell you by email before it takes effect.

14. Contact

For any privacy question or request, write to [email protected].

VIBE DEV SPACE LLC
5830 E 2nd St, Ste 7000 #28620, Casper, Wyoming 82609, US