Last Updated: August 19, 2026
This policy explains how Business Plane ("Business Plane", "we", "our", or "us") handles personal information across businessplane.com, the Business Plane application, its Model Context Protocol ("MCP") service, and related support and professional services. A customer agreement or data processing addendum may contain additional terms for workspace data and will control if it conflicts with this public policy.
Business Plane stores company knowledge in separate workspaces. The organization that controls a workspace decides what business content to add, who may join, which roles they receive, and which AI connections they may approve. Depending on the relationship and applicable law, Business Plane may act as a controller of account, website, and business operations data or as a processor/service provider for customer workspace content.
Workspace members can see and act on information according to their assigned role and any narrower operating permissions. Workspace owners and administrators can manage members and AI connections and can review workspace audit and operational records. Removing a member ends future workspace access but does not automatically erase records the person created where those records remain part of the company's history.
We receive information directly from users and workspace administrators; automatically from browsers, devices, infrastructure, and application use; from records or files users upload or ask us to retrieve; from AI clients and other integrations a user authorizes; and from service providers that help us operate Business Plane. A person who supplies information about someone else is responsible for having the authority to do so.
Where required, our legal bases may include performing a contract, taking requested pre-contract steps, pursuing legitimate interests in operating and securing the service, complying with legal obligations, and consent. A user may withdraw consent where consent is the basis, without affecting earlier lawful processing.
When a user invokes Ask AI, Business Plane assembles context limited to the selected workspace and screen scope and sends the user's prompt, system instructions, and that context to our configured OpenAI-compatible API provider. The response and conversation are saved in the workspace. The current default provider is OpenAI's API; OpenAI states that API inputs and outputs are not used to train its models by default. Provider abuse-monitoring or application-state retention is controlled by the applicable provider account and terms.
An AI platform receives Business Plane data through MCP only after the user signs in, selects one workspace, and approves specific scopes. The provider decides which approved tools to call and receives the results needed to answer or carry out the user's instruction. Write tools may create versioned documents, evidence, research, governance drafts, and Plan proposals; protected approval decisions remain in Business Plane.
ChatGPT, Claude, or another MCP client processes the information it receives under that provider's account, plan, settings, terms, and privacy policy. Business Plane does not control a provider's chat history, training choices, exports, shared links, or administrator access. Disconnecting or revoking Business Plane stops future MCP access, but it does not delete information the provider or user already copied into a conversation, file, output, or downstream system. Users should connect an organization-approved AI account and must not disclose workspace information they lack authority to share.
We do not sell personal information or share it for cross-context behavioral advertising. We disclose information only as needed to provide requested services, at a user or customer's direction, within an authorized workspace, to professional advisers under appropriate duties, in a business transaction subject to appropriate safeguards, or when reasonably necessary to comply with law or protect rights, safety, and service integrity.
Our current core providers are:
User-authorized ChatGPT, Claude, and other MCP services are user-directed recipients for that connection rather than general-purpose Business Plane subprocessors. Review the applicable OpenAI or Anthropic privacy terms before connecting. We may replace or add providers as the service changes and will update this policy when the change is material.
Essential cookies keep users signed in, preserve workspace context, and protect the application. First-party analytics identifiers help us understand page and feature use and diagnose errors; analytics traffic is sent through a Business Plane path to PostHog. Browser settings can block or clear cookies, and content blockers may block analytics, but blocking essential storage can prevent sign-in or application features from working. We do not use the collected data to follow users across unrelated websites for behavioral advertising.
Retention depends on the record, the customer relationship, workspace instructions, security needs, and legal requirements:
Depending on location and relationship, a person may have rights to know, access, correct, export, delete, restrict, or object to processing, withdraw consent, appeal a denied request, or complain to a data protection authority. Submit a request using the contact below. We may verify identity, workspace authority, and any agent's authorization before acting.
Workspace owners should make requests for company-controlled workspace content. Removing a member or revoking an MCP connection is the immediate way to end future access. Deletion may be limited where another person's rights, a customer instruction, immutable company history, security and fraud prevention, backup cycles, or a legal obligation requires retention. Where appropriate, we may restrict access or de-identify a record instead. A Business Plane deletion does not delete copies already transferred to a user-authorized AI provider; those requests must also be made to that provider.
We use administrative, technical, and organizational safeguards designed for the nature of the service, including encrypted transport, private document storage, short-lived signed file access, row-level workspace controls, role and scope checks, token hashing, request limits, version history, and audit records. No system is completely secure. Users are responsible for protecting email and AI-provider accounts, reviewing team membership, limiting confidential data to people with a need to know, and promptly revoking unexpected connections.
Business Plane is a business service and is not directed to children under 18. Do not submit payment-card numbers, government identity numbers, passwords, health information, or other regulated or special-category data unless a written agreement and properly configured service expressly cover it. A confidentiality label controls application access; it does not by itself make a record suitable for legally regulated data.
Business Plane and its providers may process information in the United States and other countries where they operate. Where required, providers use contractual or other recognized safeguards for international transfers. Contact us to discuss customer-specific data processing terms.
We may update this policy as Business Plane, its AI capabilities, providers, or legal obligations change. We will revise the date above and provide additional notice when required for a material change.
For privacy questions, requests, or complaints, email privacy@businessplane.com.