Privacy policy
Last updated: 2026-09-04
Controller under the GDPR: Balane GmbH · Balanstraße 84 · 81541 Munich · Germany Commercial register: HRB 301320, Amtsgericht München · VAT ID: DE455102718 Represented by its managing director Jonas David Höttler support@balane.tech
Balane Plan is not a local-first tool. It works with an account, and your work lives in a database on the provider's servers — otherwise the same plan could not be on your Mac, your Windows PC, your iPhone and your Android device. This policy says what is stored there, who can see it, and what the app sends out in which case.
1. Account
To sign in you need an email address and a password. The password is stored only as a cryptographic hash, never in clear text. The account carries a profile with display name, time zone and language; the app proposes the part of your email address before the @ as the display name, and you can change it.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
2. What is stored in your workspace
Everything you create in the app belongs to a workspace and is stored there:
- goals, projects, milestones, tasks, subtasks and the dependencies between them — including deadlines, estimates, priorities and assignments
- wiki pages, documents, decisions, meetings with notes, comments
- captured inbox entries, including photographed notes
- time tracking: work sessions, every state change within them, breaks and waiting periods
- what the app learns from that: your correction factor per type of task, productivity by weekday and hour, the cost of switching projects, recovery buffers after meetings
- day plans, reminders and the load calculation ("mental load")
- attachments: files and links you pin to a task or a page
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
One point stated plainly: time tracking records working behaviour. As long as you are measuring your own work, that is your business. If you use Balane Plan for employees, it is behavioural and performance monitoring with everything that entails (works council participation, informing the people concerned). That is your responsibility, not the provider's.
3. Where the data is held
Database, file storage, authentication and the server functions run on Supabase (Supabase, Inc., USA) on Amazon Web Services infrastructure. The instance used for Balane Plan is hosted in the EU region Frankfurt (eu-central-1).
- Traffic between app and server is TLS-encrypted throughout, and the volumes are encrypted at rest.
- Every access goes through row level security: the rows of a workspace are readable only by its members, enforced in the database rather than in the app.
The web interface — Balane Plan in the browser — is delivered by Vercel (Vercel Inc., USA), likewise from the Frankfurt region. In doing so, Vercel processes the connection data technically required for delivery in server logs (IP address, time, requested file, browser identification). The content of your workspace does not travel through Vercel: for that, your browser talks to Supabase directly.
On your device the app additionally keeps a copy of the most recently loaded data and a queue for changes made offline, inside the app's own folder. Both are deleted when you sign out. On top of that sits the session token, so you do not have to sign in on every launch.
4. Attachments
Files are held in a private storage bucket, separated by workspace. There are no public file URLs: to open a file the app creates a signed address that expires after ten minutes. How much storage is available depends on your plan.
5. Calendar
You can add a calendar to your account as an iCal subscription URL (ICS) — the private feed URL that Google Calendar, Outlook, iCloud and calendar servers hand out. The server reads that feed and stores the events from it (title, description, location, time span, whether they count as busy), in a window from 7 days back to 60 days ahead. The planner needs that to know when your day is already spoken for.
- Access is read-only. Nothing is ever written back to your calendar.
- The feed URL is a secret like a password. It is read server-side and not handed back to the app.
- There is no OAuth connection to Google or Microsoft, and therefore no access rights to your account there.
- Delete the calendar in the settings and the feed URL and the imported events are deleted with it.
6. AI features
Quick capture can have a captured sentence or a photographed note read by a language model and turned into a proposal. Nothing is written automatically; you confirm the proposal in the app. The planning itself — order, critical path, forecasts — is calculated and needs no model.
Which route is taken follows the order your workspace sets in the settings:
a) Model on the device. On Apple devices with a built-in system model, the operating system reads the note. The text never leaves the device, nothing is transmitted to the provider or to third parties, and nothing is metered.
b) The workspace's own key. If you configure your own API key, the request goes to the provider you chose (Anthropic or an OpenAI-compatible endpoint, self-hosted included). The key is stored encrypted in the database vault and is not handed back to the app. Billing is with your provider, not with the provider of this app.
c) The provider's key, within the allowance. Without your own key the request goes through the provider's key to its model provider (currently Anthropic PBC, USA). It consumes a monthly allowance.
In cases b) and c) what is transmitted is: the text of the note, any images, and an extract of the state of your workspace (open projects, areas and the task situation), so that the proposal connects to work that already exists. Model providers get no access to the database or the file storage; images travel as bytes, not as a link.
Every run is logged: the text of the note, the resulting proposal, provider and model, the time, the number of images (not the images themselves), and the tokens consumed with their cost. The log entry belongs to your workspace and is deleted with it.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) — the feature runs only when you trigger it.
7. Purchase and subscription
Balane Plan Pro can be bought on three routes; which data goes where depends on the route.
App Store (iPhone, iPad, Mac) and Google Play (Android): purchase and renewal run as an in-app purchase through Apple or Google, who act as controllers in their own right. The app sends the signed receipt to a server function that validates it with the respective store. Only transaction id, product, purchase date, expiry and state are stored — no payment data.
Direct purchase via balane.app (Windows — including the Microsoft Store build —, Mac outside the App Store, browser): the purchase is processed by Lemon Squeezy (Lemon Squeezy LLC, USA) as merchant of record. When the checkout opens, your email address and your profile id are passed to Lemon Squeezy so the payment can be tied to the right account. Name, billing address, payment data and VAT are processed by Lemon Squeezy as a controller in its own right; their privacy policy applies.
The unlock applies to your account, not to a device, and is always verified server-side.
8. If you work in a team
A workspace can have several members. What you create there is visible to the other members of that workspace — with your display name and email address as the author, with assignments, comments and the time you measured on a task. Anyone running a workspace with others shares responsibility under data protection law for their data; for business use the provider makes a data processing agreement available on request (support@balane.tech).
9. No analytics, no telemetry, no advertising
The app contains no analytics, tracking or crash-reporting libraries. There is no advertising, no profiling for advertising purposes, and no sharing or sale of data to third parties. There are no push notifications; the app requests no device token for them. Reminders are shown inside the app.
10. Retention, export and deletion
- Your content stays stored for as long as your account exists. How far back the app evaluates depends on your plan; nothing is deleted because of it.
- Export: in the settings you can output the full content of your workspace as JSON (Art. 15 and 20 GDPR).
- Deletion: also in the settings, you can delete your account. That removes your profile, your memberships and the workspaces that belong to you alone, with their content and files (Art. 17 GDPR). If you own a workspace that still has other members, deletion is refused — it would take their work with it; transfer it first or remove the members.
- Database backups expire after 30 days at the latest.
11. Recipients and transfers to third countries
- Supabase, Inc. (USA) — operation of the database, authentication, file storage and server functions; processing in the EU region, acting as a processor.
- Vercel Inc. (USA) — delivery of the web interface from the Frankfurt region; connection data in server logs, acting as a processor.
- Anthropic PBC (USA) or the model provider your workspace chose — only for the AI features, and only with the data named in section 6.
- Apple Inc., Google Ireland Ltd., Lemon Squeezy LLC (USA) — each only for the purchase, on the route you chose.
Where data reaches the USA in the process, it does so on the basis of the EU Commission's standard contractual clauses or, for certified recipients, the EU-US Data Privacy Framework.
12. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Access and portability are covered directly by the export in the settings; for anything else an email to support@balane.tech is enough. You may also lodge a complaint with a supervisory authority — the one responsible for the provider is the Bavarian Data Protection Authority (BayLDA), Ansbach.
13. Changes
If features or legal requirements change, this policy is adjusted. The current version is on this page; the date at the top says when it was last changed.
Questions: support@balane.tech