Terms · Privacy · Subprocessors · Security · AI · Acceptable use · Accessibility · DPA · Français
Privacy Policy
Version 1.0 · Effective 2026-08-20 · Last updated 2026-08-20
This policy explains what LobiSolutions does with personal information in LobiPlan (lobiplan.com and app.lobiplan.com). It binds LobiSolutions and covers everyone who uses the product — account holders, members of an organization workspace, members of a household workspace, children whose details are recorded in a household, and visitors to the marketing site.
Read section 2 first. For some information we decide what happens to it, and you come to us. For other information your employer decides, and we carry out their instructions. Which one applies changes who answers your request.
1. Who we are, and how to reach us
| Publisher | Benjamin Simba, carrying on business as LobiSolutions · Nova Scotia, Canada. LobiSolutions is a business name, not an incorporated company. |
| Product | LobiPlan — lobiplan.com, app at app.lobiplan.com |
| Accountable individual (Privacy Officer) | Benjamin Simba, operator |
| Contact for anything in this policy | bsimba6@gmail.com |
| Postal address | We do not publish one. Every request in this policy can be made by email and we will answer it. If your own process requires service by post, say so and we will make an arrangement. |
| Governing law | Nova Scotia, Canada |
PIPEDA requires that one named individual be accountable for privacy compliance. That individual is Benjamin Simba, and bsimba6@gmail.com is the address for every privacy question, access request, correction, erasure request, complaint or breach report. It is one address, read by one person. We do not run role addresses like privacy@ or dpo@; mail to those bounces.
We have not appointed a Data Protection Officer under GDPR Article 37 and are not required to. We have not appointed an EU representative under Article 27; the EU is not a market we sell into today, and we will appoint one if that changes.
Which laws apply. PIPEDA (Canada's federal private-sector law) governs everything we do, because Nova Scotia has no private-sector privacy statute of general application. Quebec's Law 25, Alberta's PIPA and BC's PIPA apply where we serve residents of those provinces. The GDPR applies where we hold information about people in the EU or EEA.
2. Who is responsible for your information
There are three answers and you are in one of them.
| If you are… | Who decides what happens to the data | Who answers your request |
|---|---|---|
| A member of an organization workspace (your employer or client set it up) | Your organization. It decides who is assigned what, what the approval chain is, whether AI is on, whether meetings are recorded, and who can see what. | Your organization. We will pass your request to your workspace administrator within 5 business days and tell you we have done so. |
| A member of a household workspace, and anyone recorded in one — including children | LobiSolutions. | Us. Write to bsimba6@gmail.com. |
| Anyone with a LobiPlan account, for your profile, sign-in, billing and our own operational records | LobiSolutions. | Us. |
Two consequences worth stating plainly.
In an organization workspace we are a processor, not the owner of the record. If you ask us to delete an approval your employer relies on, we will not do it — we will route you to them. That is the correct allocation, not a brush-off.
In a household workspace we are the controller. We do not treat the parent or guardian as the controller and we do not treat this as joint control. The guardian makes real decisions inside a service we run, but the legal accountability for a child's name, birth date and whereabouts is ours. That means a child's rights are ours to serve, and section 8 says how.
Your profile — your name, email address, avatar, language, timezone, province and display preferences — is person-global. One person has one profile no matter how many workspaces they belong to. No customer organization can instruct us to delete it, because it is not held on their behalf. That is our record, and we are the controller of it.
3. What we collect, why, and on what basis
This is a per-workspace inventory, not one list. A free household user and a business administrator are using measurably different products, and the table below covers both. Retention is summarised here and set out in full in section 10.
3.1 Where LobiSolutions is the controller
| Data | Why we have it | Legal basis | Kept for | Who receives it |
|---|---|---|---|---|
| Profile: name, email, avatar photo, language, timezone, province, theme, contrast, accent | Run the service; identify you across workspaces | PIPEDA: consent at signup · GDPR Art. 6(1)(b) contract | Life of the account; scrubbed on erasure | Supabase, Vercel |
| Sign-in credentials, sessions, refresh tokens | Authenticate you; protect the account | Consent · Art. 6(1)(b) and 6(1)(f) security | Life of the account; revoked on erasure | Supabase |
| Professional details: job title, department, manager, start date | Populate the workspaces you join | Consent · Art. 6(1)(b) | Life of the account | Supabase |
| Email address for notifications and digests | Send the alerts you configured | Consent, with a per-category opt-out · Art. 6(1)(b) | Life of the account | Resend (US) |
| Web Push subscription (endpoint and keys) | Deliver push notifications you switched on | The browser's own permission prompt · Art. 6(1)(a) | Until you revoke it | Nobody — the keys are self-hosted |
| Billing: name, address, subscription, invoices | Take payment; keep tax records | Consent · Art. 6(1)(b) and 6(1)(c) | 6 years (CRA books-and-records) | Stripe (US/IE) |
| Card number and CVC | Payment | — | Never touches LobiPlan. Stripe collects it directly | Stripe only |
One-way hash of your email address (trial_grants) | Stop one person minting unlimited free trials | Reasonable purpose, PIPEDA s.5(3) · Art. 6(1)(f), Recital 47 fraud prevention | Indefinite — see section 11 | Nobody |
| AI usage and cost records, LobiMeet usage minutes | Meter usage, bill, enforce caps | Necessary to the service · Art. 6(1)(b) and 6(1)(f) | 730 days | Nobody |
| Platform activity metadata: which workspace did what kind of thing, when | Operate and support the platform. Metadata only — never item names, note text or chat content | Art. 6(1)(f) | [TO CONFIRM: no retention class exists for this data yet] | Nobody |
| Server and edge logs, including IP addresses | Security, abuse prevention, availability | Art. 6(1)(f) | [TO CONFIRM: vendor default retention for Vercel and Supabase logs has not been established] | Vercel, Supabase |
| Records that we did what we say: erasures performed, exports issued, retention deletions | Prove our own compliance | Accountability · Art. 6(1)(c) and 6(1)(f) | Indefinite | Nobody |
| Household: member and child records — name, optional birth date, activities, chore points, rewards | Run the household plan the family asked for | Express consent of the adult with parental authority · Art. 6(1)(b), and 6(1)(a) for photos | Life of the household; erasable on request (section 8) | Nobody |
| Household: a child's photograph | Recognisable person tiles | Separate express opt-in, off by default · Art. 6(1)(a) | With the person record | Nobody |
| Household: day-link tokens and the schedule they serve | Let a helper see today's plan | Express — a guardian mints it · Art. 6(1)(a) | Until it expires, is regenerated, or the person is archived — see section 8 | Anyone holding the link |
| Household: bank connection, balances, transactions, merchant names | The household money view | Express consent; sensitive information · Art. 6(1)(a) and 6(1)(b) | Unbounded today — see section 10 | Plaid (US), Anthropic (US, for document reading) |
| Household: uploaded bank and mortgage statement PDFs | Import figures you confirm against an anchor you type | Express consent · Art. 6(1)(a) | ~30 days | Anthropic (document reading), Supabase Storage |
3.2 Where your organization is the controller and we are its processor
Your employer chooses the purpose and the basis. We show the basis they will normally be relying on so that this policy and our Data Processing Addendum agree with each other.
| Data | Why it is there | The customer's basis, normally | Kept for | Who receives it |
|---|---|---|---|---|
| Work items, notes, assignments, estimates, actuals, utilization | Run the work | Art. 6(1)(f) legitimate interests of the employer | Life of the workspace | Anthropic, when a user asks for AI help |
The work_events audit trail, including note text | Prove who did what and when | Art. 6(1)(f); Art. 6(1)(c) where a sector rule applies | Unbounded — section 10 | Nobody |
| Approvals and approval history | Verified completion | Art. 6(1)(f) | Unbounded — section 10 | Nobody |
| HR employee records | Employment administration | Art. 6(1)(b) and 6(1)(c) | Set by the customer | Nobody |
| Salary and loaded rate | Payroll accrual and costing | Art. 6(1)(b) and 6(1)(c) | Survives member removal, because posted payroll depends on it | Nobody |
| Evaluations and self-review answers | Performance management | Art. 6(1)(f) — the customer runs its own balancing test | Set by the customer | Nobody |
| Workforce Intelligence assessment and the profile derived from it | Match work to people; forecast capacity | Art. 6(1)(a) — the product takes express consent on its own screen | Set by the customer | Nobody |
| Time-off calendar entries, including "sick" | Capacity planning | This is health information. GDPR needs an Art. 9(2) condition — normally 9(2)(b), employment and social security law — which the customer must have | Set by the customer | Nobody |
| Person-to-person messages, attachments, reactions | Internal correspondence | Art. 6(1)(f) | Unbounded — section 10 | Resend, for external email |
| Meeting video, audio and transcripts | Record and summarise a meeting | Art. 6(1)(a) from participants | 90 days / 365 days | LiveKit, AWS S3, AssemblyAI, Anthropic |
| General ledger, receipt images, tax profile, supplier documents | Bookkeeping | Art. 6(1)(c) | Six years or more — section 10 | Anthropic, for reading a receipt |
Three things in that table we want you to notice rather than discover.
Sick-leave entries are health information. The calendar has a "sick" type. Other members of your workspace see only the word "Unavailable"; administrators see the real type. That masking is a real control and we are describing it as one. If you are a business customer, you are responsible for having a lawful condition for processing it.
Workforce Intelligence is profiling. It captures skills, working style and judgment, and it recalibrates from your actual work over time. Its consent screen says it is used for planning only, never for performance reviews or pay. That promise is true and we intend to keep it.
Separately from Workforce Intelligence, the product computes per-person performance signals — on-time rate, first-pass rate and estimate accuracy — and these are visible to administrators of your workspace. They are a different dataset from the Workforce Intelligence profile and are not covered by its promise. We would rather you learned that here than from a screenshot.
Nothing in LobiPlan makes a decision about you automatically. Every AI action is a proposal a human confirms. Assignment suggestions are arithmetic, are suggestions only, and are always confirmed by a person.
3.3 What we do not collect
No advertising identifiers. No cross-site tracking. No third-party analytics — there is no Google Analytics, Segment, Meta pixel or session-replay tool in this product. No data brokers, no enrichment, no purchased lists.
We do not sell personal information and we do not disclose it for advertising.
4. AI
Full detail is in How LobiPlan uses AI. The summary:
- One AI vendor: Anthropic (Claude), in the United States. It receives work-item text, assistant conversations, meeting transcripts, and images of receipts, statements, pantry shelves and recipes when you ask for one of those features.
- Images sent for reading are read and discarded — we do not store them. Uploaded bank and mortgage statement PDFs are the exception: those are stored, in their own private bucket, and deleted after about 30 days.
- Every AI write is a proposal a human confirms. Auto-apply is per user and off by default. External email is never sent automatically. Approvals are unreachable by AI at the database level — the function refuses.
- AI can be off. It is an entitlement your organization controls, and there are per-user controls on top.
Your data is not training data. We do not train any model on your work, and we do not sell or rent your data to anyone. LobiPlan sends text and images to Anthropic's Claude API only to answer something you asked for; Anthropic's commercial terms say it does not train its models on that input. The other services we run on — listed with what each one receives at Subprocessors — are there to deliver the product, and none of them is paid for your data.
5. Meetings, recording and transcription
Recording and transcription are off unless someone turns them on for that specific meeting. When they are on:
- Everyone sees a pre-join consent screen before entering, and a banner in the call.
- A known limitation, disclosed rather than hidden: the in-call banner is broadcast between participants. If the host's browser crashes, other participants can be left with no banner while the recording continues. We would rather tell you that than let you assume the banner is guaranteed.
- Recordings are kept 90 days. Transcripts are kept 365 days.
- The chain of companies involved is LiveKit → AWS S3 → AssemblyAI → Anthropic. See Subprocessors.
The host decides to record, not us. Canadian criminal law is one-party consent, but privacy law is not — PIPEDA consent applies regardless, and a participant may be in a province or a country with stricter rules. If you host recorded meetings, that call is yours.
6. Household money
If you connect a bank account in a household workspace:
- Plaid (United States) receives your bank credentials directly and returns account and transaction data. We never see the credentials. The access token Plaid gives us is written by a privileged server process, is never passed as a function argument, and is never returned by any function that reads data.
- Each connection belongs to the person who linked it. Nobody else in the household — including another administrator — sees the balances or the transactions unless that person chooses to share them. Merchant names are shared only if that person opts in, and opting back out reaches rows that were already shared.
- Uploaded statement PDFs are stored in their own private bucket with no administrator access at all. Only the person who uploaded it can read it. This is deliberate, and it is the design that makes the product usable by separated co-parents.
- Statement PDFs are deleted after about 30 days.
7. Who we share with
Subprocessors. We use eleven companies to deliver LobiPlan. Each is listed at Subprocessors with its legal entity name, what it does, what categories of personal data it receives, where it processes and stores them, the transfer mechanism, and the date the entry was last reviewed. In summary: Supabase (database, authentication, storage), Vercel (hosting and CDN), Anthropic (all AI), Resend (transactional email), Stripe (payments), Plaid (household bank feed), LiveKit (meeting media), AssemblyAI (transcription), AWS (recording storage), frankfurter.dev / ECB (a daily exchange rate lookup that receives no personal data), and Web Push, which is self-hosted and involves no vendor at all.
We give 30 days' advance notice before adding or changing a subprocessor, with a right to object. If we cannot resolve the objection you may terminate the affected service for the rest of your term with a pro-rata refund. We reserve an emergency replacement for security or continuity reasons, with notice as soon as practicable.
Three other ways your data can reach someone, which a subprocessor list does not cover:
- Your calendar provider. If you subscribe to your LobiPlan calendar feed, Google, Apple or Microsoft will download it to their own servers on their own schedule and keep the contents — your work items, and in a household your family's plan. They are outside Canada, and we have no contract with them, because you chose them and not us. What we send, they keep, under their privacy policy and not ours.
- Anyone holding a day link. See section 8.
- Lawful access. If we receive a legally valid demand we will comply with it, and we will tell the affected customer unless we are legally prohibited from doing so.
8. Children and households
We are the controller here. Not the parent, not the guardian, not the household administrator. If you have a question or a request about a child's information in LobiPlan, it comes to us at bsimba6@gmail.com.
What we hold about a child
A child does not need an account. You add them as a name and, if you want, a birthday. Nothing else. They never count toward the number of people your plan allows — the free tier is two adults with accounts and as many children as you have.
What builds up over time: chores they finished, the points those earned, a day streak, and rewards they asked for. This history is kept for as long as your household exists. Archiving someone takes them off the lists — it does not delete what is stored.
Photographs
Photos of children are off by default. Nobody in your household can add one until an administrator turns photos on for the whole household. When they are on, four things are true:
- Only administrators can add or change a photo.
- The image is resized in your own browser before upload, and that re-encoding destroys its embedded location and camera data.
- It is stored in a private bucket and served through short-lived signed links.
- A photo is never shown on a day link.
One thing the app's own wording did not previously make explicit and this policy does: every member of your household who has an account can see the photo, including a teenager.
Everyone in a household sees the same things
Chores, the calendar, children's records, lists, shopping and meals are visible to every adult with an account in that household. Money is the one exception — section 6.
"Who is using this device" and the simplified Chores view change what a screen shows. They do not lock anything and they hide nothing from anyone. They are per-device display settings. They are not a parental control and we will not describe them as one.
Day links — read this one carefully
A guardian can create a link so that someone helping out — a grandparent, a sitter — can see the day's plan without an account.
Anyone who opens that link sees the child's name, what they are doing, the time, the venue's street address and the venue's phone number. There is no account, no password and no sign-in. Photographs are never included.
Here is the honest state of it:
- A link can be given an expiry date, and by default it does not have one. The mechanism exists and works — you can set an end date when you create the link, and the server enforces it. But if you leave the date empty, the link keeps working every day, indefinitely, until you regenerate it or archive the person. We consider that the wrong default and we are changing it. Until we do: set an end date.
- Regenerating a link invalidates every copy of the old one.
- Archiving the person the link is for revokes it permanently. Un-archiving them creates a new link rather than reviving the old one.
- We cannot currently tell you who has used a link, or when. There is no access log. If that matters to you, treat a link as a key you have handed out rather than a message you have sent.
If your household changes
Any administrator of a household can add or remove any other adult, including another administrator, and that takes effect immediately. We cannot split a household, decide who keeps it, or move a child's record from one household to another. If a child is recorded in two families' households, those are two separate records and we have no way to merge or move them.
A child's access and erasure rights
The right of access belongs to the individual whose information it is. It does not depend on holding an account, and "they do not have a login" is not an answer to an access request. We will honour a request from a parent or guardian, and from the young person themselves once they are old enough to understand what they are asking for. Quebec sets that line at 14; elsewhere in Canada it is a question of the individual young person's capacity, so we do not publish a fixed age.
What exists today. Two functions were added to the product on 2026-08-20 for exactly this:
| What it does | |
|---|---|
| Access and portability | Returns everything we hold about one person in a household — name, kind, birth date, whether a photo exists, chores and their status, points and streak, rewards requested and their outcome, commitments, and the fact of every day link with its dates. It deliberately excludes the day-link tokens themselves, because the link is the credential, and the photo file, whose existence is reported instead. |
| Erasure | Removes the child's name, birth date, photo, points, streak, rewards and every day link. The photograph is queued for real deletion from storage before the pointer to it is cleared, so the file is actually destroyed rather than merely unfindable. A scrubbed row remains so that ten years of household history keeps its shape — after erasure that row identifies nobody. |
Both are exercised by an administrator of that household, and refuse to run anywhere else.
Being plain about the state of it: there is no button for this in the app yet. The mechanism is built and works; the screen that calls it is a separate change we have not shipped. Write to bsimba6@gmail.com and we will run it and send you the result within 30 days.
Erasure of a child in a shared household is different from access, because it is destructive and it affects another adult's use of a workspace they share. If one adult asks us to erase a child's record in a live household with other adult members, we will notify the other adults and wait 14 days. If they disagree, we will refuse and tell you why. A private company must not settle a custody dispute by deleting something, and PIPEDA lets us refuse a request that cannot be complied with without affecting another individual. We record the refusal and the reason.
Age and scope
LobiPlan is offered to adults. A child's information is entered by an adult with parental authority, and under Quebec's Law 25 consent for a person under 14 is given by the holder of parental authority. Children do not hold accounts.
We do not claim COPPA compliance. The service is not directed to children under 13, children hold no accounts, and we do not run a US children's-privacy programme. We would rather say that than claim a programme we do not operate.
9. Where your data lives, and what leaves Canada
At rest, your data is in Canada. The database, authentication and file storage are in Supabase's ca-central-1 region. Meeting recordings are in an AWS S3 bucket, also ca-central-1.
Content leaves Canada during ordinary use, and we are not going to hedge about it:
| Vendor | Country | What it receives |
|---|---|---|
| Anthropic | United States | Work-item text, assistant conversations, meeting transcripts, images of financial documents — on every AI call |
| Resend | United States | Recipient addresses and the body of notifications and digests |
| Stripe | United States / Ireland | Billing data |
| Plaid | United States | Bank connection and transaction data (household workspaces only) |
| AssemblyAI | United States | Meeting audio |
| Vercel | Global edge | Every request: IP address and headers |
| LiveKit | [TO CONFIRM: LiveKit's media region has not been established. Live audio and video may transit outside Canada even though recordings are stored here. These are two different statements and we will not merge them until the first is verified.] | Live meeting audio and video |
Alberta residents: the countries above are the countries in which your information may be stored or accessed. The person who can answer questions about it is Benjamin Simba, at bsimba6@gmail.com.
What this means legally. Under PIPEDA, sending data to a service provider for processing is a use rather than a disclosure, so it does not need fresh consent — but it does need to be told to you, which is what this section is, and it needs contractual protection, which is what our vendor agreements are for. Foreign governments can compel data held in their jurisdiction, and no contract changes that.
For EU and EEA users: Canada holds a partial adequacy decision covering organizations subject to PIPEDA, so a transfer from the EU to LobiPlan needs no extra instrument. Our onward transfers to US vendors rely on the Standard Contractual Clauses incorporated in each vendor's data processing agreement, or on that vendor's certification under the EU-US Data Privacy Framework where it holds one. Which instrument applies to which vendor is recorded, vendor by vendor, at Subprocessors — we state it there rather than here so that it can be checked against the official Data Privacy Framework list rather than taken on trust.
10. How long we keep things
Retention is a policy table in the database, editable without a code change, with a written reason for every class. Here is the whole of it.
Classes with a period
| Class | Kept for |
|---|---|
| Meeting recordings | 90 days |
| Meeting transcripts | 365 days |
| AI assistant conversations | 180 days |
| Notifications | 90 days |
| Communication log | 365 days |
| Record of AI actions | 365 days |
| AI usage and cost records | 730 days |
| LobiMeet usage minutes | 730 days |
| Household statement PDFs | ~30 days |
A recording is both a database row and a stored file. Our sweeper deletes the file first and only then clears the pointer to it, so a deleted recording is genuinely gone rather than merely unfindable and still costing us storage.
Classes we deliberately do not delete, and why
The function that sets retention periods refuses to accept one for these four, so switching auto-deletion on would take a migration and therefore a reason.
| Class | Why |
|---|---|
The audit trail (work_events) | It is the record of who did what and when. An audit trail with a timer on it is not an audit trail. |
| Approvals and approval history | Other people and other organizations rely on them to show that work was verified as complete. |
| The general ledger | A business has a six-year record-keeping duty under the Income Tax Act and the Excise Tax Act. That duty binds the taxpayer, not us — but auto-deleting our customer's books would make it impossible for them to meet it. So we do not. |
| Person-to-person messages | Correspondence has two parties. A timer set by one of them erases the other person's record of their own conversation. |
"Unbounded" means for the life of the workspace, not forever. On termination there is a 60-day window to export, after which Customer Data is deleted or anonymised within 90 days — except the ledger and the audit records, where a customer may instruct us to retain them for their own statutory period. Backups age out on their own cycle and are not edited to remove individual records. These are the same periods as Terms of Service §19.4 and §19.7, and if the two ever disagree the Terms govern.
Classes with no rule yet
We would rather list these than imply the schedule is complete. Each one is a class we have not yet made a decision about, and a class with no decision is an oversight rather than a policy:
- Children's records and their points (
household_people,household_person_scores) — kept for the life of the household today; erasable on request under section 8. - Lapsed day-link records (kept deliberately, so that "expired" and "never existed" remain distinguishable, but with no rule for when they finally go).
- Household bank transactions and merchant names. The source statement PDF is deleted after 30 days; the transaction rows it produced are not. That is the wrong way round and we know it.
- Evaluation answers.
- The contacts address book.
- Attachments, receipts and evidence images in storage.
- Avatar images.
- Platform activity metadata, and server and edge logs.
11. Your rights, and how to use them
Write to bsimba6@gmail.com. We answer within 30 days, which is the PIPEDA deadline; if we need the extension the statute allows, we will tell you before the 30 days are up.
| Right | Is it built? | How it works |
|---|---|---|
| Access | Yes, self-serve | My Account → Security → export. One export per 24 hours, 21 sections, structured JSON. |
| Portability | Yes — the same file | Structured, machine-readable JSON. |
| Correction | Partly | Most fields you can edit yourself. The audit trail cannot be edited — see below. |
| Erasure | Partly — on request, not self-serve | See below. |
| Restriction of processing | No | There is no freeze state in the product. Ask us and we will handle it by hand. |
| Objection | Partly | You can turn AI off, disconnect a bank, revoke a link, and switch notification categories and channels individually. |
| Withdraw consent | Partly | You can withdraw from optional processing. You cannot withdraw from the processing that makes the product work while continuing to use it; the consequence of full withdrawal is the loss of the service. |
| Not be subject to an automated decision | Not applicable by design | Nothing here decides anything about you automatically. |
What the export contains, and what it does not
It contains your profile, your work, the audit entries you wrote, your messages (with the other party shown by name), your calendar, your reminders, your assessment answers and much else, across 21 named sections.
It deliberately excludes two things:
- Credentials. Push notification keys, calendar-feed tokens, day-link tokens and email-alias verification tokens are not data about you, they are keys to your account. The export reports that a device or a feed exists; it never includes the secret. The file itself says so.
- Your organization's wider backlog, and audit entries written by other people about you. In an organization workspace those are your employer's records and may contain a third party's information; ask your employer for them. In a household workspace that exclusion does not apply, because we are the controller — ask us.
The export does not include the accounting ledger. The books export separately, as a CSV per statement, from the Finance screens.
Correction, and the audit trail
The audit trail is immutable on purpose. If it could be edited it would not be evidence of anything. So we cannot rewrite an entry you disagree with. What PIPEDA provides instead — and what we will do — is record the substance of your unresolved challenge alongside the entry, and pass it to anyone we have given the information to where that is appropriate.
Erasure — read this before you ask
When you ask us to erase your account, we anonymise it. We do not delete it, and deletion was never technically available. Fifty-one references point into your profile from elsewhere in the database, and those references are the audit trail and the approval record. Removing the profile row would break them.
Here is exactly what happens:
Permanently deleted: your name, email address, photo, preferences, private notes to yourself, AI conversations, notifications, calendar entries — including sickness entries — assessment answers, and any compensation record we hold for you. Your ability to sign in is removed: the password is cleared, every session and refresh token is deleted, linked sign-in identities are removed, and the account is permanently barred.
Not deleted: the record of work you did. Approvals, the audit trail and the accounting ledger keep their shape, because other people and other organizations rely on them. In those records your name is replaced with "Former member" — everywhere at once, because every display name is resolved from your profile at the moment it is drawn rather than copied into the record.
Three honest caveats:
- There is no self-serve delete button. Erasure is performed by us, by hand, on your request. That is a gap and we are naming it as one; the underlying mechanism is built and tested, and the request route is bsimba6@gmail.com.
- A one-way hash of your email address survives, so that a free trial cannot be claimed twice by the same address. It is a hash and not the address. We are telling you it survives because a hashed email address is still, in law, information that relates to you — we keep it for fraud prevention and nothing else.
- Your account identifier survives on the historical records described above. Combined with point 2, the honest description is that we irreversibly sever the link between you and the historical record, not that the record becomes anonymous. A colleague who was there may still remember which "Former member" you were. We are not going to pretend otherwise.
Erasure takes effect immediately in the live service. Backups age out separately; [TO CONFIRM: the Supabase backup and point-in-time-recovery retention window has not been established, so the number of days cannot be stated here]. We keep a log of every erasure we perform, and if a backup is ever restored we re-apply that log to it.
Children
Section 8. In short: exercised by an administrator of the household, or by writing to us; the mechanism exists; there is no screen for it yet.
12. Cookies and local storage
LobiPlan sets no cookies. There are no third-party analytics, no advertising pixels, no cross-site trackers and no session-replay tools in this product.
And there is no cookie banner, deliberately. The law here is not about cookies — it is about storing anything on your device — and it exempts storage that is strictly necessary or that results from something you explicitly asked for. Every single item below is one or the other. A banner would offer you a choice that does not exist: a "reject" button would either do nothing or break your sign-in. We would rather tell you what is stored than perform a consent ritual over it.
| What is stored | Mechanism | What it is for | Lifetime | Survives sign-out? |
|---|---|---|---|---|
sb-…-auth-token | localStorage | Your sign-in session. Strictly necessary. | Access token ~1 hour, refreshed; cleared on sign-out | No |
~40 keys beginning ct. — plus theme, lang, cal-* | localStorage | Preferences you set: theme, contrast, accent colour, sidebar width, calendar view, language, which workspace you were in, tour progress, voice settings, meeting camera and microphone choices. Every one is the result of an explicit action you took. | Until you clear it | Yes |
ct.genDraft.* | localStorage | A draft you are writing, kept so a reload does not lose it. This can contain your own content. | Until you save or discard the draft | Yes |
ct.winHandoff.* | localStorage | Carries a draft message or meeting between two windows when you pop one out. This can briefly contain your own content, including a message body and recipients. It is read once and deleted, and expires after 5 minutes. It deliberately does not use the URL, because a message body in a query string would land in your browser history. | ≤ 5 minutes, one-shot | Effectively no |
sw.js / cache ct-shell-v5 | Service worker cache | The offline shell of the app, so it loads when you install it as an app. | Until the cache version changes or you clear it | Yes |
| Web Push subscription | Push API | Delivering the notifications you switched on. Your browser asks you first — that prompt is the consent. | Until you revoke it | Yes |
previewLang | sessionStorage | Previewing an unfinished language in one tab. | That tab | n/a |
lp.guestName | localStorage | Remembering the name you typed to join a meeting as a guest. | Until cleared | Yes |
None of this storage is shared with anyone. To clear it: sign out, then clear site data for app.lobiplan.com in your browser settings, and unregister the service worker if you installed LobiPlan as an app.
Separately from device storage, our servers and our CDN record IP addresses in their logs, for security and availability. That is processing, disclosed in section 3 and section 9. It is not something device storage settings affect.
A standing condition: if we ever add analytics, a heatmap, session replay or an advertising pixel, the consent obligation arrives with it and we will ask before switching it on. The absence of a banner today is a consequence of how the product is built, not a permanent exemption.
13. Security
Full detail, including what we do not have, is in Security. The short version:
What protects your data. Every table in the database has row-level security, so authorisation is enforced by the database and not only by application code. The most sensitive tables — salary, the platform ledger, bank credentials, feed tokens — are deny-all with the grant revoked, meaning two independent barriers, and are reachable only through specific, authorisation-checked functions. Files live in private buckets and are served through short-lived signed links. Everything is encrypted in transit, and encrypted at rest by our hosting provider using provider-managed keys.
What we do not have, stated because you would find out anyway:
- There is no multi-factor authentication. Sign-in is email and password.
- There is no SOC 2 report, no ISO 27001 certificate, no third-party audit and no external penetration test. We will not imply otherwise.
- The app's content security policy restricts framing only; it does not restrict what the app may load or fetch.
- There is no published status page and no uptime commitment.
In July 2026 we ran an adversarial security review of the whole product against itself. Tenant isolation held: no path was found by which one customer could read or write another customer's data, and none by which an anonymous stranger could read anything. What it did find were places where the platform trusted its own callers, and those were fixed. We will share that assessment with a prospective customer under NDA.
14. If there is a breach
If we become aware of a breach of security safeguards affecting your personal information, we will record it, assess it, and — where there is a real risk of significant harm — notify you and the Office of the Privacy Commissioner of Canada as soon as feasible. Where Quebec residents are affected we will notify the Commission d'accès à l'information. Where the GDPR applies we will notify the relevant supervisory authority within 72 hours.
If you are a business customer, we will notify you without undue delay and in any event within 48 hours of confirming a breach affecting your workspace, with what we know, what we are doing about it, and what we recommend you do.
We keep a record of every breach of security safeguards for at least 24 months, whether or not it meets the threshold for notifying anyone, and we provide that record to the Privacy Commissioner on request.
Forty-eight hours is a promise we can keep from confirmation. Some vendors offer 24. We will not, because a solo operation that promises 24 will miss it once, and a missed notification promise is a broken contract on top of a breach.
15. Changes to this document
We will give you at least 30 days' notice by email and in the app before a material change takes effect, with a note saying what changed. Non-material changes — a clearer sentence, a corrected typo, a new subprocessor already announced through the 30-day subprocessor process — are recorded in the version history without separate notice.
Every version carries a version number and an effective date at the top. Previous versions are available on request at bsimba6@gmail.com.
16. Complaints
Come to us first. Write to Benjamin Simba at bsimba6@gmail.com. We will acknowledge your complaint, investigate it, and tell you what we found and what we did.
If you are not satisfied, you can complain to a regulator, and you do not need our permission to do so:
| If you are in… | Regulator |
|---|---|
| Anywhere in Canada | Office of the Privacy Commissioner of Canada — priv.gc.ca |
| Quebec | Commission d'accès à l'information du Québec — cai.gouv.qc.ca |
| Alberta | Office of the Information and Privacy Commissioner of Alberta |
| British Columbia | Office of the Information and Privacy Commissioner for BC |
| The EU or EEA | Your national data protection supervisory authority |
If you are a member of an organization workspace and your complaint is about your work data, your employer is the controller and the regulator will normally expect you to raise it with them. We will help you do that and we will tell you we have.
Related documents: Terms of Service · Subprocessors · Security · How LobiPlan uses AI · Data Processing Addendum · Acceptable Use Policy · Accessibility
Changes to this document
This is Version 1.0, effective 2026-08-20.
When we change something that affects what we collect, why we collect it, who receives it, or how long we keep it, we will raise the version number, change the effective date, and tell account holders by email before the new version takes effect. Corrections that do not change any of those things — a clearer sentence, a fixed typo, a link that moved — are made in place and noted below.
Previous versions are available on request from bsimba6@gmail.com.
| Version | Date | What changed |
|---|---|---|
| 1.0 | 2026-08-20 | First published. Before this date LobiPlan had no privacy policy. |
LobiPlan for organizations · LobiPlan for households · bsimba6@gmail.com