Privacy Policy
Last updated: 16 September 2026
What this policy covers
PeterPlan provides automated reviews of product plans. This policy explains how we handle the information you provide when you buy an audit, submit a plan, or receive a report.
Information we collect
- Contact information: your email address, used to deliver audit codes and reports and to help with a purchase-related support request.
- Plan content: the text in the document you upload for review. Uploaded document bytes are converted to text in memory; we do not keep uploaded files in object storage.
- Purchase information: the audit package you choose, a payment reference, and the audit codes issued for that purchase. Card payment details are handled by Stripe, not PeterPlan.
- Operational information: audit status, timestamps, token-usage counts, and package tier. These support delivery, reliability checks, and aggregate service metrics; they do not contain your original plan text.
How we use it
We use your information to take payment, issue audit codes, review the submitted plan, email the report, provide a time-limited report link, and operate and support PeterPlan. We do not sell your plan content or use it to build a public catalogue of ideas.
Who processes information
PeterPlan uses Stripe to process payments, Postmark to deliver transactional email, Anthropic to generate the audit report, and a managed PostgreSQL database to operate the service. Each provider processes only the information needed to provide its part of the service.
How long we keep it
Your submitted plan text is deleted as soon as the audit job reaches a terminal state: when a report is generated or when generation fails. There is no additional retention window for the original submitted text.
Your report text is kept for 30 days, then purged. This keeps the report link useful for a short period after delivery. We retain the non-content operational records described above as needed to run the service and maintain aggregate metrics.
You can request early deletion of a report at any time before the 30-day window closes — verify your email and purchase reference or audit code on the order lookup page and choose "Delete my report." This is permanent and cannot be undone.
An important note about reports
Deleting the original plan text does not make a retained report a completely separate copy. A report can quote or closely paraphrase relevant parts of the plan in order to explain a finding. For that reason, report text may still contain fragments of submitted content during its 30-day retention period.
Security
We use access controls and service-provider security measures appropriate to the product. No online service can guarantee absolute security, so please avoid including information in a plan that you would not want processed for the purpose of this review.
Changes to this policy
If PeterPlan changes how it handles submitted plans, reports, or personal information, this policy will be updated to reflect the new practice.