Privacy Policy

Last Updated: August 19, 2026

This policy explains how Business Plane ("Business Plane", "we", "our", or "us") handles personal information across businessplane.com, the Business Plane application, its Model Context Protocol ("MCP") service, and related support and professional services. A customer agreement or data processing addendum may contain additional terms for workspace data and will control if it conflicts with this public policy.

1. Our role and the workspace model

Business Plane stores company knowledge in separate workspaces. The organization that controls a workspace decides what business content to add, who may join, which roles they receive, and which AI connections they may approve. Depending on the relationship and applicable law, Business Plane may act as a controller of account, website, and business operations data or as a processor/service provider for customer workspace content.

Workspace members can see and act on information according to their assigned role and any narrower operating permissions. Workspace owners and administrators can manage members and AI connections and can review workspace audit and operational records. Removing a member ends future workspace access but does not automatically erase records the person created where those records remain part of the company's history.

2. Information we collect

Account and team information

  • Name, email address, profile details, authentication identifiers, and sign-in events.
  • Workspace membership, role, permissions, invitations, and connection approvals.
  • Communications with Business Plane, including support, privacy, sales, and service requests.

Workspace and business content

  • Plans, narratives, drafts, citations, research cards, gaps, decisions, risks, milestones, controls, and review findings.
  • Uploaded documents, filenames, file contents, extracted searchable text, versions, checksums, source URLs, attachments, lifecycle status, confidentiality labels, parties, owners, signers, and counterparties.
  • Business, brand, project, client, contact, contract, invoice, financial-model, creator, content-rights, deployment, work-item, and operating records.
  • Personal information about employees, customers, prospects, creators, counterparties, or other people that an authorized user includes in workspace content.

AI, MCP, and audit information

  • Ask AI prompts, scoped context packets, model outputs, conversation history, sources, and proposed actions.
  • Approved AI client, selected workspace, OAuth scopes, connection dates, expiry and revocation state, and hashed authorization or token values.
  • Tool names, outcomes, request IDs, actor and client attribution, affected record identifiers, immutable versions, decisions, and other audit evidence.
  • Request status, duration, protocol version, and hashed rate-limit actor keys. Business Plane's MCP operational tables do not store raw IP addresses, bearer tokens, tool arguments, request bodies, or document content.

Technical and analytics information

  • IP address and approximate location, browser and device details, referrer, pages and features used, timestamps, errors, and performance information.
  • First-party session, security, preference, and analytics identifiers.
  • Feature and workflow events, which may include an account email identifier and limited business record metadata such as a record code, status, category, or amount.

3. How we collect information

We receive information directly from users and workspace administrators; automatically from browsers, devices, infrastructure, and application use; from records or files users upload or ask us to retrieve; from AI clients and other integrations a user authorizes; and from service providers that help us operate Business Plane. A person who supplies information about someone else is responsible for having the authority to do so.

4. How and why we use information

  • Provide, authenticate, secure, support, and improve Business Plane.
  • Keep workspaces isolated, enforce roles, fulfill tool calls, synchronize search indexes, and maintain version and audit history.
  • Run user-requested AI features, document extraction, notifications, exports, and connected services.
  • Respond to inquiries, deliver service and security messages, and administer customer relationships.
  • Measure product and website use, troubleshoot failures, prevent abuse, and enforce our agreements.
  • Comply with law, protect rights and safety, resolve disputes, and establish or defend legal claims.

Where required, our legal bases may include performing a contract, taking requested pre-contract steps, pursuing legitimate interests in operating and securing the service, complying with legal obligations, and consent. A user may withdraw consent where consent is the basis, without affecting earlier lawful processing.

5. AI features and connected AI platforms

In-app Ask AI

When a user invokes Ask AI, Business Plane assembles context limited to the selected workspace and screen scope and sends the user's prompt, system instructions, and that context to our configured OpenAI-compatible API provider. The response and conversation are saved in the workspace. The current default provider is OpenAI's API; OpenAI states that API inputs and outputs are not used to train its models by default. Provider abuse-monitoring or application-state retention is controlled by the applicable provider account and terms.

ChatGPT, Claude, and MCP clients

An AI platform receives Business Plane data through MCP only after the user signs in, selects one workspace, and approves specific scopes. The provider decides which approved tools to call and receives the results needed to answer or carry out the user's instruction. Write tools may create versioned documents, evidence, research, governance drafts, and Plan proposals; protected approval decisions remain in Business Plane.

ChatGPT, Claude, or another MCP client processes the information it receives under that provider's account, plan, settings, terms, and privacy policy. Business Plane does not control a provider's chat history, training choices, exports, shared links, or administrator access. Disconnecting or revoking Business Plane stops future MCP access, but it does not delete information the provider or user already copied into a conversation, file, output, or downstream system. Users should connect an organization-approved AI account and must not disclose workspace information they lack authority to share.

6. How we disclose information

We do not sell personal information or share it for cross-context behavioral advertising. We disclose information only as needed to provide requested services, at a user or customer's direction, within an authorized workspace, to professional advisers under appropriate duties, in a business transaction subject to appropriate safeguards, or when reasonably necessary to comply with law or protect rights, safety, and service integrity.

7. Service providers and subprocessors

Our current core providers are:

User-authorized ChatGPT, Claude, and other MCP services are user-directed recipients for that connection rather than general-purpose Business Plane subprocessors. Review the applicable OpenAI or Anthropic privacy terms before connecting. We may replace or add providers as the service changes and will update this policy when the change is material.

8. Cookies and analytics choices

Essential cookies keep users signed in, preserve workspace context, and protect the application. First-party analytics identifiers help us understand page and feature use and diagnose errors; analytics traffic is sent through a Business Plane path to PostHog. Browser settings can block or clear cookies, and content blockers may block analytics, but blocking essential storage can prevent sign-in or application features from working. We do not use the collected data to follow users across unrelated websites for behavioral advertising.

9. Retention

Retention depends on the record, the customer relationship, workspace instructions, security needs, and legal requirements:

  • Account and workspace content is generally retained while the account or workspace is active and afterward as needed for export, deletion processing, disputes, security, legal obligations, and backups.
  • Document versions, verification results, approval evidence, decisions, and audit records may be intentionally immutable so the company record cannot be silently rewritten. They may be archived, access-restricted, or de-identified instead of edited or immediately erased where retention remains necessary.
  • Ask AI prompts, outputs, and conversation records remain workspace data until the workspace is deleted or an authorized deletion request is completed, subject to the preceding integrity and legal limits.
  • MCP authorization codes expire after 5 minutes, access tokens after 1 hour, and refresh authorization after 30 days. Business Plane stores hashes, not reusable plaintext token values. Revoked/expired connection metadata and tool audits may remain with workspace security and operating history.
  • Signed document-download links expire after 5 minutes. Direct-upload authorizations expire after 2 hours. Invalid or expired temporary upload objects are removed when detected; reservation and finalized version records may remain for integrity and troubleshooting.
  • Distributed MCP rate-limit counters expire shortly after their window. Request IDs and safe operational events currently remain with workspace operations/audit history until a verified retention or deletion action applies.
  • Infrastructure logs, analytics events, email-delivery records, model-provider records, and backups follow the applicable provider's retention terms and our configured account controls.

10. Access, correction, export, deletion, and other rights

Depending on location and relationship, a person may have rights to know, access, correct, export, delete, restrict, or object to processing, withdraw consent, appeal a denied request, or complain to a data protection authority. Submit a request using the contact below. We may verify identity, workspace authority, and any agent's authorization before acting.

Workspace owners should make requests for company-controlled workspace content. Removing a member or revoking an MCP connection is the immediate way to end future access. Deletion may be limited where another person's rights, a customer instruction, immutable company history, security and fraud prevention, backup cycles, or a legal obligation requires retention. Where appropriate, we may restrict access or de-identify a record instead. A Business Plane deletion does not delete copies already transferred to a user-authorized AI provider; those requests must also be made to that provider.

11. Security

We use administrative, technical, and organizational safeguards designed for the nature of the service, including encrypted transport, private document storage, short-lived signed file access, row-level workspace controls, role and scope checks, token hashing, request limits, version history, and audit records. No system is completely secure. Users are responsible for protecting email and AI-provider accounts, reviewing team membership, limiting confidential data to people with a need to know, and promptly revoking unexpected connections.

12. Sensitive data and children

Business Plane is a business service and is not directed to children under 18. Do not submit payment-card numbers, government identity numbers, passwords, health information, or other regulated or special-category data unless a written agreement and properly configured service expressly cover it. A confidentiality label controls application access; it does not by itself make a record suitable for legally regulated data.

13. International processing

Business Plane and its providers may process information in the United States and other countries where they operate. Where required, providers use contractual or other recognized safeguards for international transfers. Contact us to discuss customer-specific data processing terms.

14. Changes to this policy

We may update this policy as Business Plane, its AI capabilities, providers, or legal obligations change. We will revise the date above and provide additional notice when required for a material change.

15. Contact

For privacy questions, requests, or complaints, email privacy@businessplane.com.