Skip to content
Pluna
How it worksFeaturesPricing
See check-in
How it worksFeaturesPricing
← Back to Pluna

Privacy Policy

Last updated: 28 July 2026

This Privacy Policy explains how Eryndor AI (“Eryndor AI”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the Pluna mobile application and related services (the “Service”).

We are the data controller for the personal data described below.

  • Controller: Eryndor AI (a sole proprietorship / eenmanszaak registered in the Netherlands)
  • KVK (Chamber of Commerce) number: 94350248
  • Privacy contact: support@eryndorai.com

By using Pluna you agree to this Privacy Policy. If you do not agree, please do not use the Service.


1. Who this policy is for

Pluna is intended for users who are 18 years of age or older. The Service is not directed to, and we do not knowingly collect personal data from, anyone under 18. See Section 11 (Children).


2. What data we collect

We collect only the data needed to run Pluna as a proactive goal-accountability coach.

2.1 Data you provide

CategoryExamples
Account & identityEmail address and the authentication identifier from our sign-in provider (including when you sign in with Apple or Google).
Goals & planning contentYour goals, milestones, commitments, weekly focus items, and related notes you create.
Check-in conversationsThe messages you exchange with the AI coach during morning check-ins, evening reflections, weekly reviews, onboarding, and ad-hoc chats.
AI response reportsThe reason, optional note, reported AI response, preceding visible prompt, and message/conversation identifiers when you report a response.
Preferences & settingsYour time zone and your chosen check-in and weekly-review times.

2.2 Data we generate about you

To provide continuity and coaching, Pluna derives and stores:

  • Rolling summaries of your recent check-ins.
  • A “user model” — observations about your patterns, preferences, and behaviours (for example, tendencies such as consistency or avoidance) inferred from your conversations and activity, used to make coaching more relevant.
  • Progress and outcome records — whether commitments were completed, missed, or re-planned.

2.3 Data from connected services (only if you connect them)

  • Google Calendar (optional). If you connect Google Calendar, we access event titles, start and end times, Google event identifiers, and recurring-event identifiers from your primary calendar, limited to calendars you own. We use this information to understand your availability, detect scheduling conflicts, and, at your direction, create, update, or delete time-blocked events. Event titles and times may be included in the context provided to the AI coach. We store your Google authorization tokens in encrypted form, along with limited metadata for events Pluna creates and for calendar changes awaiting your confirmation. See Section 7 (Google user data).

2.4 Technical data

  • Push notification tokens (via the Expo push service) so we can deliver check-in notifications.
  • Basic operational/log data (such as request timestamps and error diagnostics) generated by our infrastructure to keep the Service secure and reliable.
  • Crash and error diagnostics processed through Sentry in preview and production environments. These diagnostics are limited to exception type and stack location, app/release and runtime versions, operating system and device model, deployment environment, and Expo Update identifiers. We configure Pluna not to send Sentry your account identifiers, email, goals, conversations, Calendar content, request bodies, authorization data, screenshots, session replay, or free-form exception messages. Internet services necessarily process an IP address while routing a report, but Sentry is configured not to retain it.
  • Product interaction analytics processed through PostHog Cloud EU, such as which fixed app screen or onboarding step was viewed and whether onboarding, a goal, a check-in, a commitment outcome, or a purchase step occurred. These events use Pluna’s internal account identifier and coarse categories (for example, check-in type and duration range). We do not send PostHog your email, name, goals, commitment text, conversations, Calendar content, notification content, user-entered text, dynamic page identifiers, precise location, or IP address for storage. Session replay and touch recording are disabled.

2.5 Payment data

Subscriptions are purchased through the Apple App Store or Google Play. Those platforms process your payment. We do not receive or store your full payment card details. We may receive limited transaction status information (for example, whether a subscription is active) from the applicable store.


3. How we use your data

We use your personal data to:

  1. Provide the Service — run check-ins, maintain your goals and plan, and generate coach responses.
  2. Personalize coaching — assemble your goals, history, user model, and, if you connect Google Calendar, relevant event titles and times so the coach can understand your availability and maintain continuity across sessions.
  3. Send notifications — deliver the check-in and reminder push notifications that are the core of the product.
  4. Maintain, secure, and improve the Service — debugging, crash diagnosis, preventing abuse, and ensuring reliability.
  5. Communicate with you — service-related messages and responses to your requests.
  6. Comply with law — meet legal obligations and enforce our Terms.

We do not sell your personal data, and we do not use your check-in conversations to train third-party AI models for others’ benefit.

When you report an AI response, we review it to investigate safety concerns and use confirmed reports to improve prompts, content filters, model safeguards, and moderation. Where the GDPR applies, this review and improvement processing is based on our legitimate interests in securing and improving the Service and preventing abuse, balanced against your rights.


4. Legal bases (EU/EEA – GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to provide the Service you sign up for, including check-ins, planning, and calendar features you enable.
  • Legitimate interests (Art. 6(1)(f)) — to secure, maintain, debug, and improve the Service, and to prevent abuse. We balance these against your rights.
  • Consent (Art. 6(1)(a)) — for optional integrations you choose to connect (such as Google Calendar) and, where required, push notifications. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — where we must process data to comply with law.

Your goals and conversations may reveal personal information about your life. We treat this content as sensitive and handle it with care. We do not ask you to share special- category data (such as health or religious information), and we ask that you avoid entering it; if you choose to, you consent to our processing it as part of your content.


5. How we share data (service providers / subprocessors)

We share data only with providers that help us operate Pluna, under contracts that require them to protect it and use it only on our instructions. Current categories:

Provider categoryPurposeData involved
Authentication providerSign-in and identityEmail, auth identifier
Fireworks AI (LLM inference provider)Generate the coach’s responsesYour check-in conversation content and relevant context (goals, summaries, and, if Calendar is connected, event titles and times)
Push notification provider (Expo/FCM/APNs)Deliver notificationsPush tokens, notification content
Google (Calendar API)Read/write your calendar (if connected)Event titles, start/end times, Google event identifiers, and authorization tokens
Cloud hosting & database providersRun the backend and store dataAll stored data, encrypted in transit
Sentry (error monitoring)Diagnose crashes and service errorsMinimized technical diagnostics described in Section 2.4; no Pluna account identity or user content
PostHog Cloud EU (product analytics)Measure product use and retentionInternal account identifier and minimized interaction events described in Section 2.4; no user content
App stores (Apple, Google)Process subscriptionsTransaction/subscription status

About Fireworks AI. Pluna currently uses Fireworks AI as its third-party LLM inference provider. To generate coaching responses, we may send relevant conversation content and context to Fireworks AI. If you connect Google Calendar, that context may include relevant event titles and start/end times. Fireworks AI processes this information to provide inference responses to Pluna. Under our current configuration, Fireworks AI does not log or store prompt or generated data. Neither Eryndor AI nor Fireworks AI uses Google Calendar data to train AI models.

About Sentry. Pluna uses separate Sentry projects for the mobile application and backend. Sentry receives only the minimized error diagnostics described in Section 2.4. We disable performance tracing, profiling, session replay, screenshots, request-body capture, application logs, and user identification. Sentry event data and backups are hosted in its EU region in Frankfurt, Germany.

About PostHog. Pluna uses PostHog Cloud EU to understand activation, check-in engagement, retention, and subscription conversion. Mobile and backend events use the same internal Pluna account identifier. We restrict event names and properties, disable automatic interaction capture, session replay, precise location enrichment, and IP retention, and do not send the user content listed in Section 2.4.

We may also disclose data (a) to comply with law, legal process, or lawful government requests; (b) to protect the rights, safety, and security of users, the public, or Eryndor AI; and (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you of any change in control or use of your personal data.


6. International data transfers

We are based in the Netherlands, and some of our providers (including AI and infrastructure providers) may process data in the United States or other countries outside the EU/EEA. Where we transfer personal data internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and/or providers certified under an applicable data-transfer framework. You may request more information using the contact details above.

Sentry error event data and backups are stored in the EU. Sentry is operated by a US-based company and limited account, billing, support, security, or subprocessor processing may still involve countries outside the EU/EEA. We apply the contractual and transfer safeguards described above.


7. Google user data and Limited Use

If you connect Google Calendar, Pluna’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We access event titles, start and end times, and Google event identifiers from your primary calendar, limited to calendars you own.
  • We use this data only to provide and improve Pluna’s user-facing Calendar and coaching features: understanding availability, detecting scheduling conflicts, and, at your direction, creating, updating, or deleting time-blocked events.
  • We may send relevant event titles and times to our contracted AI providers solely to generate Pluna’s coaching responses and provide these features. Neither we nor our AI providers use Google Calendar data to train AI models.
  • We do not sell Google Calendar data, use it for advertising, or use it for purposes unrelated to providing these user-facing features.
  • We do not allow humans to read this data unless we have your consent for specific messages, it is necessary for security or to comply with law, or the data is aggregated and anonymized.
  • Submitting an AI response report asks our authorized reviewers to inspect the reported response, your optional note, and the immediately preceding visible prompt. This context may include Calendar information that appeared in the conversation.
  • You can disconnect Google Calendar at any time in the app. Disconnecting deletes your stored Google authorization credentials and stops future Calendar API access. You can also revoke access through your Google Account permissions.

8. Data retention

  • We keep your account data and content for as long as your account is active.
  • When you request account deletion in the app or at getpluna.com/account-deletion, we mark your account for deletion and begin a 30-day grace period. During those 30 days, you can cancel the request by signing back in to Pluna and choosing to reactivate your account. Reactivation restores access and cancels the scheduled deletion.
  • After the 30-day grace period, we permanently erase your Pluna account and its associated goals, milestones, commitments, conversations and messages, observations and summaries, push tokens, Google Calendar connection and encrypted authorization credentials, and Pluna-managed Calendar metadata from our primary systems. We also request deletion of your Kinde sign-in identity and profile data.
  • At the same time, we request deletion of the PostHog person linked to your internal account identifier and their associated product analytics events. PostHog processes historical event deletion asynchronously; Pluna keeps a deletion request in a retry queue until PostHog accepts it. Aggregated statistics that no longer identify you may be retained.
  • Encrypted calendar authorization tokens are deleted when you disconnect the integration or delete your account. Disconnecting stops future access to your Google Calendar.
  • Limited Calendar event metadata described in Section 2.3 is retained under the same rules as your other account content and is deleted when your account is deleted, subject to the grace period, backup rotation, and legally required retention described in this section.
  • AI response reports are retained for 90 days after submission, including if you delete the reported conversation. If your account is deleted before that period ends, we immediately remove the reporter link, source identifiers, preceding prompt, and optional note. We retain only the reported AI response, reason, and moderation outcome until the original 90-day expiry so we can complete safety review and improve safeguards.
  • Sentry crash and error events are retained for no more than 30 days. They are not linked to your Pluna account, so deleting an account does not identify a separate Sentry record for account-specific deletion; the minimized diagnostics expire automatically within that period. If we discover that personal content was included accidentally, we delete the affected event or issue and handle it under our incident-response process.
  • We may retain limited records where necessary to comply with legal obligations, resolve disputes, or enforce our agreements; such records are kept only as long as required.
  • Backups are rotated on a regular cycle; residual copies in backups are overwritten in the ordinary course.

9. Security

We take reasonable technical and organizational measures to protect your data, including:

  • Encryption in transit (HTTPS/TLS) for data moving between the app, our backend, and our providers.
  • Encryption at rest for sensitive credentials such as Google Calendar tokens, using envelope encryption (a per-record data key wrapped by a managed key).
  • Access controls limiting who and what can access personal data, and authorization checks that scope every request to your own account.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.


10. Your rights

10.1 EU/EEA, UK, and similar (GDPR)

You have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”).
  • Restrict or object to certain processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time (without affecting prior processing).
  • Object to crash and error diagnostic processing based on our legitimate interests by contacting us. We will assess and respond to the objection as required by law.
  • Lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may also contact the authority in your country of residence.

10.2 United States (California – CCPA/CPRA, and similar state laws)

If you are a California resident (or a resident of a US state with comparable law), you have the right to:

  • Know / access the categories and specific pieces of personal information we have collected.
  • Delete personal information we hold about you.
  • Correct inaccurate personal information.
  • Opt out of the “sale” or “sharing” of personal information — note: we do not sell or share your personal information as those terms are defined under the CCPA/CPRA.
  • Non-discrimination for exercising your rights.

We do not use or disclose sensitive personal information for purposes that require an opt-out under the CPRA.

10.3 How to exercise your rights

You can access most data directly in the app. You can request account deletion in the app or through our public account-deletion page. For any other request, contact us at support@eryndorai.com. We will respond within the timeframe required by applicable law (generally within 30 days for GDPR and 45 days for CCPA). We may need to verify your identity before acting on a request.


11. Children

Pluna is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.


12. Third-party services

Pluna relies on and links to third-party services, including:

  • Fireworks AI, which provides the LLM inference used to generate Pluna’s coaching responses. See the Fireworks AI Privacy Policy.
  • Google, which provides sign-in and Google Calendar services when you choose to use them.
  • Apple and Google app stores, which distribute the app and process subscriptions.
  • Expo, Firebase Cloud Messaging, and Apple Push Notification service, which help us deliver push notifications.
  • Sentry, which provides privacy-configured crash and error monitoring from its EU data region. See the Sentry Privacy Policy.
  • PostHog, which provides privacy-configured product analytics from PostHog Cloud EU. See the PostHog Privacy Policy.

These providers’ own handling of data is governed by their respective privacy policies. We encourage you to review them.


13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you in the app or by email. Your continued use of the Service after changes take effect constitutes acceptance.


14. Contact us

Eryndor AI (eenmanszaak, the Netherlands) KVK: 94350248 Email: support@eryndorai.com


This document is provided as a starting point and does not constitute legal advice. You should have it reviewed by a qualified lawyer before publishing, particularly regarding your specific data flows, subprocessors, and obligations under EU and US law.

Pluna
How it worksFeaturesPricingDelete accountPrivacyTerms

© 2026 Pluna. A proactive accountability coach for your whole life. Plan sustainably; the coach does the upkeep.