Privacy Policy

Version 1.0 · Effective 2026-08-20 · Last updated 2026-08-20

This policy explains what LobiSolutions does with personal information in LobiPlan (lobiplan.com and app.lobiplan.com). It binds LobiSolutions and covers everyone who uses the product — account holders, members of an organization workspace, members of a household workspace, children whose details are recorded in a household, and visitors to the marketing site.

Read section 2 first. For some information we decide what happens to it, and you come to us. For other information your employer decides, and we carry out their instructions. Which one applies changes who answers your request.


1. Who we are, and how to reach us

PublisherBenjamin Simba, carrying on business as LobiSolutions · Nova Scotia, Canada. LobiSolutions is a business name, not an incorporated company.
ProductLobiPlan — lobiplan.com, app at app.lobiplan.com
Accountable individual (Privacy Officer)Benjamin Simba, operator
Contact for anything in this policybsimba6@gmail.com
Postal addressWe do not publish one. Every request in this policy can be made by email and we will answer it. If your own process requires service by post, say so and we will make an arrangement.
Governing lawNova Scotia, Canada

PIPEDA requires that one named individual be accountable for privacy compliance. That individual is Benjamin Simba, and bsimba6@gmail.com is the address for every privacy question, access request, correction, erasure request, complaint or breach report. It is one address, read by one person. We do not run role addresses like privacy@ or dpo@; mail to those bounces.

We have not appointed a Data Protection Officer under GDPR Article 37 and are not required to. We have not appointed an EU representative under Article 27; the EU is not a market we sell into today, and we will appoint one if that changes.

Which laws apply. PIPEDA (Canada's federal private-sector law) governs everything we do, because Nova Scotia has no private-sector privacy statute of general application. Quebec's Law 25, Alberta's PIPA and BC's PIPA apply where we serve residents of those provinces. The GDPR applies where we hold information about people in the EU or EEA.


2. Who is responsible for your information

There are three answers and you are in one of them.

If you are…Who decides what happens to the dataWho answers your request
A member of an organization workspace (your employer or client set it up)Your organization. It decides who is assigned what, what the approval chain is, whether AI is on, whether meetings are recorded, and who can see what.Your organization. We will pass your request to your workspace administrator within 5 business days and tell you we have done so.
A member of a household workspace, and anyone recorded in one — including childrenLobiSolutions.Us. Write to bsimba6@gmail.com.
Anyone with a LobiPlan account, for your profile, sign-in, billing and our own operational recordsLobiSolutions.Us.

Two consequences worth stating plainly.

In an organization workspace we are a processor, not the owner of the record. If you ask us to delete an approval your employer relies on, we will not do it — we will route you to them. That is the correct allocation, not a brush-off.

In a household workspace we are the controller. We do not treat the parent or guardian as the controller and we do not treat this as joint control. The guardian makes real decisions inside a service we run, but the legal accountability for a child's name, birth date and whereabouts is ours. That means a child's rights are ours to serve, and section 8 says how.

Your profile — your name, email address, avatar, language, timezone, province and display preferences — is person-global. One person has one profile no matter how many workspaces they belong to. No customer organization can instruct us to delete it, because it is not held on their behalf. That is our record, and we are the controller of it.


3. What we collect, why, and on what basis

This is a per-workspace inventory, not one list. A free household user and a business administrator are using measurably different products, and the table below covers both. Retention is summarised here and set out in full in section 10.

3.1 Where LobiSolutions is the controller

DataWhy we have itLegal basisKept forWho receives it
Profile: name, email, avatar photo, language, timezone, province, theme, contrast, accentRun the service; identify you across workspacesPIPEDA: consent at signup · GDPR Art. 6(1)(b) contractLife of the account; scrubbed on erasureSupabase, Vercel
Sign-in credentials, sessions, refresh tokensAuthenticate you; protect the accountConsent · Art. 6(1)(b) and 6(1)(f) securityLife of the account; revoked on erasureSupabase
Professional details: job title, department, manager, start datePopulate the workspaces you joinConsent · Art. 6(1)(b)Life of the accountSupabase
Email address for notifications and digestsSend the alerts you configuredConsent, with a per-category opt-out · Art. 6(1)(b)Life of the accountResend (US)
Web Push subscription (endpoint and keys)Deliver push notifications you switched onThe browser's own permission prompt · Art. 6(1)(a)Until you revoke itNobody — the keys are self-hosted
Billing: name, address, subscription, invoicesTake payment; keep tax recordsConsent · Art. 6(1)(b) and 6(1)(c)6 years (CRA books-and-records)Stripe (US/IE)
Card number and CVCPaymentNever touches LobiPlan. Stripe collects it directlyStripe only
One-way hash of your email address (trial_grants)Stop one person minting unlimited free trialsReasonable purpose, PIPEDA s.5(3) · Art. 6(1)(f), Recital 47 fraud preventionIndefinite — see section 11Nobody
AI usage and cost records, LobiMeet usage minutesMeter usage, bill, enforce capsNecessary to the service · Art. 6(1)(b) and 6(1)(f)730 daysNobody
Platform activity metadata: which workspace did what kind of thing, whenOperate and support the platform. Metadata only — never item names, note text or chat contentArt. 6(1)(f)[TO CONFIRM: no retention class exists for this data yet]Nobody
Server and edge logs, including IP addressesSecurity, abuse prevention, availabilityArt. 6(1)(f)[TO CONFIRM: vendor default retention for Vercel and Supabase logs has not been established]Vercel, Supabase
Records that we did what we say: erasures performed, exports issued, retention deletionsProve our own complianceAccountability · Art. 6(1)(c) and 6(1)(f)IndefiniteNobody
Household: member and child records — name, optional birth date, activities, chore points, rewardsRun the household plan the family asked forExpress consent of the adult with parental authority · Art. 6(1)(b), and 6(1)(a) for photosLife of the household; erasable on request (section 8)Nobody
Household: a child's photographRecognisable person tilesSeparate express opt-in, off by default · Art. 6(1)(a)With the person recordNobody
Household: day-link tokens and the schedule they serveLet a helper see today's planExpress — a guardian mints it · Art. 6(1)(a)Until it expires, is regenerated, or the person is archived — see section 8Anyone holding the link
Household: bank connection, balances, transactions, merchant namesThe household money viewExpress consent; sensitive information · Art. 6(1)(a) and 6(1)(b)Unbounded today — see section 10Plaid (US), Anthropic (US, for document reading)
Household: uploaded bank and mortgage statement PDFsImport figures you confirm against an anchor you typeExpress consent · Art. 6(1)(a)~30 daysAnthropic (document reading), Supabase Storage

3.2 Where your organization is the controller and we are its processor

Your employer chooses the purpose and the basis. We show the basis they will normally be relying on so that this policy and our Data Processing Addendum agree with each other.

DataWhy it is thereThe customer's basis, normallyKept forWho receives it
Work items, notes, assignments, estimates, actuals, utilizationRun the workArt. 6(1)(f) legitimate interests of the employerLife of the workspaceAnthropic, when a user asks for AI help
The work_events audit trail, including note textProve who did what and whenArt. 6(1)(f); Art. 6(1)(c) where a sector rule appliesUnbounded — section 10Nobody
Approvals and approval historyVerified completionArt. 6(1)(f)Unbounded — section 10Nobody
HR employee recordsEmployment administrationArt. 6(1)(b) and 6(1)(c)Set by the customerNobody
Salary and loaded ratePayroll accrual and costingArt. 6(1)(b) and 6(1)(c)Survives member removal, because posted payroll depends on itNobody
Evaluations and self-review answersPerformance managementArt. 6(1)(f) — the customer runs its own balancing testSet by the customerNobody
Workforce Intelligence assessment and the profile derived from itMatch work to people; forecast capacityArt. 6(1)(a) — the product takes express consent on its own screenSet by the customerNobody
Time-off calendar entries, including "sick"Capacity planningThis is health information. GDPR needs an Art. 9(2) condition — normally 9(2)(b), employment and social security law — which the customer must haveSet by the customerNobody
Person-to-person messages, attachments, reactionsInternal correspondenceArt. 6(1)(f)Unbounded — section 10Resend, for external email
Meeting video, audio and transcriptsRecord and summarise a meetingArt. 6(1)(a) from participants90 days / 365 daysLiveKit, AWS S3, AssemblyAI, Anthropic
General ledger, receipt images, tax profile, supplier documentsBookkeepingArt. 6(1)(c)Six years or more — section 10Anthropic, for reading a receipt

Three things in that table we want you to notice rather than discover.

Sick-leave entries are health information. The calendar has a "sick" type. Other members of your workspace see only the word "Unavailable"; administrators see the real type. That masking is a real control and we are describing it as one. If you are a business customer, you are responsible for having a lawful condition for processing it.

Workforce Intelligence is profiling. It captures skills, working style and judgment, and it recalibrates from your actual work over time. Its consent screen says it is used for planning only, never for performance reviews or pay. That promise is true and we intend to keep it.

Separately from Workforce Intelligence, the product computes per-person performance signals — on-time rate, first-pass rate and estimate accuracy — and these are visible to administrators of your workspace. They are a different dataset from the Workforce Intelligence profile and are not covered by its promise. We would rather you learned that here than from a screenshot.

Nothing in LobiPlan makes a decision about you automatically. Every AI action is a proposal a human confirms. Assignment suggestions are arithmetic, are suggestions only, and are always confirmed by a person.

3.3 What we do not collect

No advertising identifiers. No cross-site tracking. No third-party analytics — there is no Google Analytics, Segment, Meta pixel or session-replay tool in this product. No data brokers, no enrichment, no purchased lists.

We do not sell personal information and we do not disclose it for advertising.


4. AI

Full detail is in How LobiPlan uses AI. The summary:

Your data is not training data. We do not train any model on your work, and we do not sell or rent your data to anyone. LobiPlan sends text and images to Anthropic's Claude API only to answer something you asked for; Anthropic's commercial terms say it does not train its models on that input. The other services we run on — listed with what each one receives at Subprocessors — are there to deliver the product, and none of them is paid for your data.


5. Meetings, recording and transcription

Recording and transcription are off unless someone turns them on for that specific meeting. When they are on:

The host decides to record, not us. Canadian criminal law is one-party consent, but privacy law is not — PIPEDA consent applies regardless, and a participant may be in a province or a country with stricter rules. If you host recorded meetings, that call is yours.


6. Household money

If you connect a bank account in a household workspace:


7. Who we share with

Subprocessors. We use eleven companies to deliver LobiPlan. Each is listed at Subprocessors with its legal entity name, what it does, what categories of personal data it receives, where it processes and stores them, the transfer mechanism, and the date the entry was last reviewed. In summary: Supabase (database, authentication, storage), Vercel (hosting and CDN), Anthropic (all AI), Resend (transactional email), Stripe (payments), Plaid (household bank feed), LiveKit (meeting media), AssemblyAI (transcription), AWS (recording storage), frankfurter.dev / ECB (a daily exchange rate lookup that receives no personal data), and Web Push, which is self-hosted and involves no vendor at all.

We give 30 days' advance notice before adding or changing a subprocessor, with a right to object. If we cannot resolve the objection you may terminate the affected service for the rest of your term with a pro-rata refund. We reserve an emergency replacement for security or continuity reasons, with notice as soon as practicable.

Three other ways your data can reach someone, which a subprocessor list does not cover:

  1. Your calendar provider. If you subscribe to your LobiPlan calendar feed, Google, Apple or Microsoft will download it to their own servers on their own schedule and keep the contents — your work items, and in a household your family's plan. They are outside Canada, and we have no contract with them, because you chose them and not us. What we send, they keep, under their privacy policy and not ours.
  2. Anyone holding a day link. See section 8.
  3. Lawful access. If we receive a legally valid demand we will comply with it, and we will tell the affected customer unless we are legally prohibited from doing so.

8. Children and households

We are the controller here. Not the parent, not the guardian, not the household administrator. If you have a question or a request about a child's information in LobiPlan, it comes to us at bsimba6@gmail.com.

What we hold about a child

A child does not need an account. You add them as a name and, if you want, a birthday. Nothing else. They never count toward the number of people your plan allows — the free tier is two adults with accounts and as many children as you have.

What builds up over time: chores they finished, the points those earned, a day streak, and rewards they asked for. This history is kept for as long as your household exists. Archiving someone takes them off the lists — it does not delete what is stored.

Photographs

Photos of children are off by default. Nobody in your household can add one until an administrator turns photos on for the whole household. When they are on, four things are true:

  1. Only administrators can add or change a photo.
  2. The image is resized in your own browser before upload, and that re-encoding destroys its embedded location and camera data.
  3. It is stored in a private bucket and served through short-lived signed links.
  4. A photo is never shown on a day link.

One thing the app's own wording did not previously make explicit and this policy does: every member of your household who has an account can see the photo, including a teenager.

Everyone in a household sees the same things

Chores, the calendar, children's records, lists, shopping and meals are visible to every adult with an account in that household. Money is the one exception — section 6.

"Who is using this device" and the simplified Chores view change what a screen shows. They do not lock anything and they hide nothing from anyone. They are per-device display settings. They are not a parental control and we will not describe them as one.

Day links — read this one carefully

A guardian can create a link so that someone helping out — a grandparent, a sitter — can see the day's plan without an account.

Anyone who opens that link sees the child's name, what they are doing, the time, the venue's street address and the venue's phone number. There is no account, no password and no sign-in. Photographs are never included.

Here is the honest state of it:

If your household changes

Any administrator of a household can add or remove any other adult, including another administrator, and that takes effect immediately. We cannot split a household, decide who keeps it, or move a child's record from one household to another. If a child is recorded in two families' households, those are two separate records and we have no way to merge or move them.

A child's access and erasure rights

The right of access belongs to the individual whose information it is. It does not depend on holding an account, and "they do not have a login" is not an answer to an access request. We will honour a request from a parent or guardian, and from the young person themselves once they are old enough to understand what they are asking for. Quebec sets that line at 14; elsewhere in Canada it is a question of the individual young person's capacity, so we do not publish a fixed age.

What exists today. Two functions were added to the product on 2026-08-20 for exactly this:

What it does
Access and portabilityReturns everything we hold about one person in a household — name, kind, birth date, whether a photo exists, chores and their status, points and streak, rewards requested and their outcome, commitments, and the fact of every day link with its dates. It deliberately excludes the day-link tokens themselves, because the link is the credential, and the photo file, whose existence is reported instead.
ErasureRemoves the child's name, birth date, photo, points, streak, rewards and every day link. The photograph is queued for real deletion from storage before the pointer to it is cleared, so the file is actually destroyed rather than merely unfindable. A scrubbed row remains so that ten years of household history keeps its shape — after erasure that row identifies nobody.

Both are exercised by an administrator of that household, and refuse to run anywhere else.

Being plain about the state of it: there is no button for this in the app yet. The mechanism is built and works; the screen that calls it is a separate change we have not shipped. Write to bsimba6@gmail.com and we will run it and send you the result within 30 days.

Erasure of a child in a shared household is different from access, because it is destructive and it affects another adult's use of a workspace they share. If one adult asks us to erase a child's record in a live household with other adult members, we will notify the other adults and wait 14 days. If they disagree, we will refuse and tell you why. A private company must not settle a custody dispute by deleting something, and PIPEDA lets us refuse a request that cannot be complied with without affecting another individual. We record the refusal and the reason.

Age and scope

LobiPlan is offered to adults. A child's information is entered by an adult with parental authority, and under Quebec's Law 25 consent for a person under 14 is given by the holder of parental authority. Children do not hold accounts.

We do not claim COPPA compliance. The service is not directed to children under 13, children hold no accounts, and we do not run a US children's-privacy programme. We would rather say that than claim a programme we do not operate.


9. Where your data lives, and what leaves Canada

At rest, your data is in Canada. The database, authentication and file storage are in Supabase's ca-central-1 region. Meeting recordings are in an AWS S3 bucket, also ca-central-1.

Content leaves Canada during ordinary use, and we are not going to hedge about it:

VendorCountryWhat it receives
AnthropicUnited StatesWork-item text, assistant conversations, meeting transcripts, images of financial documents — on every AI call
ResendUnited StatesRecipient addresses and the body of notifications and digests
StripeUnited States / IrelandBilling data
PlaidUnited StatesBank connection and transaction data (household workspaces only)
AssemblyAIUnited StatesMeeting audio
VercelGlobal edgeEvery request: IP address and headers
LiveKit[TO CONFIRM: LiveKit's media region has not been established. Live audio and video may transit outside Canada even though recordings are stored here. These are two different statements and we will not merge them until the first is verified.]Live meeting audio and video

Alberta residents: the countries above are the countries in which your information may be stored or accessed. The person who can answer questions about it is Benjamin Simba, at bsimba6@gmail.com.

What this means legally. Under PIPEDA, sending data to a service provider for processing is a use rather than a disclosure, so it does not need fresh consent — but it does need to be told to you, which is what this section is, and it needs contractual protection, which is what our vendor agreements are for. Foreign governments can compel data held in their jurisdiction, and no contract changes that.

For EU and EEA users: Canada holds a partial adequacy decision covering organizations subject to PIPEDA, so a transfer from the EU to LobiPlan needs no extra instrument. Our onward transfers to US vendors rely on the Standard Contractual Clauses incorporated in each vendor's data processing agreement, or on that vendor's certification under the EU-US Data Privacy Framework where it holds one. Which instrument applies to which vendor is recorded, vendor by vendor, at Subprocessors — we state it there rather than here so that it can be checked against the official Data Privacy Framework list rather than taken on trust.


10. How long we keep things

Retention is a policy table in the database, editable without a code change, with a written reason for every class. Here is the whole of it.

Classes with a period

ClassKept for
Meeting recordings90 days
Meeting transcripts365 days
AI assistant conversations180 days
Notifications90 days
Communication log365 days
Record of AI actions365 days
AI usage and cost records730 days
LobiMeet usage minutes730 days
Household statement PDFs~30 days

A recording is both a database row and a stored file. Our sweeper deletes the file first and only then clears the pointer to it, so a deleted recording is genuinely gone rather than merely unfindable and still costing us storage.

Classes we deliberately do not delete, and why

The function that sets retention periods refuses to accept one for these four, so switching auto-deletion on would take a migration and therefore a reason.

ClassWhy
The audit trail (work_events)It is the record of who did what and when. An audit trail with a timer on it is not an audit trail.
Approvals and approval historyOther people and other organizations rely on them to show that work was verified as complete.
The general ledgerA business has a six-year record-keeping duty under the Income Tax Act and the Excise Tax Act. That duty binds the taxpayer, not us — but auto-deleting our customer's books would make it impossible for them to meet it. So we do not.
Person-to-person messagesCorrespondence has two parties. A timer set by one of them erases the other person's record of their own conversation.

"Unbounded" means for the life of the workspace, not forever. On termination there is a 60-day window to export, after which Customer Data is deleted or anonymised within 90 days — except the ledger and the audit records, where a customer may instruct us to retain them for their own statutory period. Backups age out on their own cycle and are not edited to remove individual records. These are the same periods as Terms of Service §19.4 and §19.7, and if the two ever disagree the Terms govern.

Classes with no rule yet

We would rather list these than imply the schedule is complete. Each one is a class we have not yet made a decision about, and a class with no decision is an oversight rather than a policy:


11. Your rights, and how to use them

Write to bsimba6@gmail.com. We answer within 30 days, which is the PIPEDA deadline; if we need the extension the statute allows, we will tell you before the 30 days are up.

RightIs it built?How it works
AccessYes, self-serveMy Account → Security → export. One export per 24 hours, 21 sections, structured JSON.
PortabilityYes — the same fileStructured, machine-readable JSON.
CorrectionPartlyMost fields you can edit yourself. The audit trail cannot be edited — see below.
ErasurePartly — on request, not self-serveSee below.
Restriction of processingNoThere is no freeze state in the product. Ask us and we will handle it by hand.
ObjectionPartlyYou can turn AI off, disconnect a bank, revoke a link, and switch notification categories and channels individually.
Withdraw consentPartlyYou can withdraw from optional processing. You cannot withdraw from the processing that makes the product work while continuing to use it; the consequence of full withdrawal is the loss of the service.
Not be subject to an automated decisionNot applicable by designNothing here decides anything about you automatically.

What the export contains, and what it does not

It contains your profile, your work, the audit entries you wrote, your messages (with the other party shown by name), your calendar, your reminders, your assessment answers and much else, across 21 named sections.

It deliberately excludes two things:

The export does not include the accounting ledger. The books export separately, as a CSV per statement, from the Finance screens.

Correction, and the audit trail

The audit trail is immutable on purpose. If it could be edited it would not be evidence of anything. So we cannot rewrite an entry you disagree with. What PIPEDA provides instead — and what we will do — is record the substance of your unresolved challenge alongside the entry, and pass it to anyone we have given the information to where that is appropriate.

Erasure — read this before you ask

When you ask us to erase your account, we anonymise it. We do not delete it, and deletion was never technically available. Fifty-one references point into your profile from elsewhere in the database, and those references are the audit trail and the approval record. Removing the profile row would break them.

Here is exactly what happens:

Permanently deleted: your name, email address, photo, preferences, private notes to yourself, AI conversations, notifications, calendar entries — including sickness entries — assessment answers, and any compensation record we hold for you. Your ability to sign in is removed: the password is cleared, every session and refresh token is deleted, linked sign-in identities are removed, and the account is permanently barred.

Not deleted: the record of work you did. Approvals, the audit trail and the accounting ledger keep their shape, because other people and other organizations rely on them. In those records your name is replaced with "Former member" — everywhere at once, because every display name is resolved from your profile at the moment it is drawn rather than copied into the record.

Three honest caveats:

  1. There is no self-serve delete button. Erasure is performed by us, by hand, on your request. That is a gap and we are naming it as one; the underlying mechanism is built and tested, and the request route is bsimba6@gmail.com.
  2. A one-way hash of your email address survives, so that a free trial cannot be claimed twice by the same address. It is a hash and not the address. We are telling you it survives because a hashed email address is still, in law, information that relates to you — we keep it for fraud prevention and nothing else.
  3. Your account identifier survives on the historical records described above. Combined with point 2, the honest description is that we irreversibly sever the link between you and the historical record, not that the record becomes anonymous. A colleague who was there may still remember which "Former member" you were. We are not going to pretend otherwise.

Erasure takes effect immediately in the live service. Backups age out separately; [TO CONFIRM: the Supabase backup and point-in-time-recovery retention window has not been established, so the number of days cannot be stated here]. We keep a log of every erasure we perform, and if a backup is ever restored we re-apply that log to it.

Children

Section 8. In short: exercised by an administrator of the household, or by writing to us; the mechanism exists; there is no screen for it yet.


12. Cookies and local storage

LobiPlan sets no cookies. There are no third-party analytics, no advertising pixels, no cross-site trackers and no session-replay tools in this product.

And there is no cookie banner, deliberately. The law here is not about cookies — it is about storing anything on your device — and it exempts storage that is strictly necessary or that results from something you explicitly asked for. Every single item below is one or the other. A banner would offer you a choice that does not exist: a "reject" button would either do nothing or break your sign-in. We would rather tell you what is stored than perform a consent ritual over it.

What is storedMechanismWhat it is forLifetimeSurvives sign-out?
sb-…-auth-tokenlocalStorageYour sign-in session. Strictly necessary.Access token ~1 hour, refreshed; cleared on sign-outNo
~40 keys beginning ct. — plus theme, lang, cal-*localStoragePreferences you set: theme, contrast, accent colour, sidebar width, calendar view, language, which workspace you were in, tour progress, voice settings, meeting camera and microphone choices. Every one is the result of an explicit action you took.Until you clear itYes
ct.genDraft.*localStorageA draft you are writing, kept so a reload does not lose it. This can contain your own content.Until you save or discard the draftYes
ct.winHandoff.*localStorageCarries a draft message or meeting between two windows when you pop one out. This can briefly contain your own content, including a message body and recipients. It is read once and deleted, and expires after 5 minutes. It deliberately does not use the URL, because a message body in a query string would land in your browser history.≤ 5 minutes, one-shotEffectively no
sw.js / cache ct-shell-v5Service worker cacheThe offline shell of the app, so it loads when you install it as an app.Until the cache version changes or you clear itYes
Web Push subscriptionPush APIDelivering the notifications you switched on. Your browser asks you first — that prompt is the consent.Until you revoke itYes
previewLangsessionStoragePreviewing an unfinished language in one tab.That tabn/a
lp.guestNamelocalStorageRemembering the name you typed to join a meeting as a guest.Until clearedYes

None of this storage is shared with anyone. To clear it: sign out, then clear site data for app.lobiplan.com in your browser settings, and unregister the service worker if you installed LobiPlan as an app.

Separately from device storage, our servers and our CDN record IP addresses in their logs, for security and availability. That is processing, disclosed in section 3 and section 9. It is not something device storage settings affect.

A standing condition: if we ever add analytics, a heatmap, session replay or an advertising pixel, the consent obligation arrives with it and we will ask before switching it on. The absence of a banner today is a consequence of how the product is built, not a permanent exemption.


13. Security

Full detail, including what we do not have, is in Security. The short version:

What protects your data. Every table in the database has row-level security, so authorisation is enforced by the database and not only by application code. The most sensitive tables — salary, the platform ledger, bank credentials, feed tokens — are deny-all with the grant revoked, meaning two independent barriers, and are reachable only through specific, authorisation-checked functions. Files live in private buckets and are served through short-lived signed links. Everything is encrypted in transit, and encrypted at rest by our hosting provider using provider-managed keys.

What we do not have, stated because you would find out anyway:

In July 2026 we ran an adversarial security review of the whole product against itself. Tenant isolation held: no path was found by which one customer could read or write another customer's data, and none by which an anonymous stranger could read anything. What it did find were places where the platform trusted its own callers, and those were fixed. We will share that assessment with a prospective customer under NDA.


14. If there is a breach

If we become aware of a breach of security safeguards affecting your personal information, we will record it, assess it, and — where there is a real risk of significant harm — notify you and the Office of the Privacy Commissioner of Canada as soon as feasible. Where Quebec residents are affected we will notify the Commission d'accès à l'information. Where the GDPR applies we will notify the relevant supervisory authority within 72 hours.

If you are a business customer, we will notify you without undue delay and in any event within 48 hours of confirming a breach affecting your workspace, with what we know, what we are doing about it, and what we recommend you do.

We keep a record of every breach of security safeguards for at least 24 months, whether or not it meets the threshold for notifying anyone, and we provide that record to the Privacy Commissioner on request.

Forty-eight hours is a promise we can keep from confirmation. Some vendors offer 24. We will not, because a solo operation that promises 24 will miss it once, and a missed notification promise is a broken contract on top of a breach.


15. Changes to this document

We will give you at least 30 days' notice by email and in the app before a material change takes effect, with a note saying what changed. Non-material changes — a clearer sentence, a corrected typo, a new subprocessor already announced through the 30-day subprocessor process — are recorded in the version history without separate notice.

Every version carries a version number and an effective date at the top. Previous versions are available on request at bsimba6@gmail.com.


16. Complaints

Come to us first. Write to Benjamin Simba at bsimba6@gmail.com. We will acknowledge your complaint, investigate it, and tell you what we found and what we did.

If you are not satisfied, you can complain to a regulator, and you do not need our permission to do so:

If you are in…Regulator
Anywhere in CanadaOffice of the Privacy Commissioner of Canada — priv.gc.ca
QuebecCommission d'accès à l'information du Québec — cai.gouv.qc.ca
AlbertaOffice of the Information and Privacy Commissioner of Alberta
British ColumbiaOffice of the Information and Privacy Commissioner for BC
The EU or EEAYour national data protection supervisory authority

If you are a member of an organization workspace and your complaint is about your work data, your employer is the controller and the regulator will normally expect you to raise it with them. We will help you do that and we will tell you we have.


Related documents: Terms of Service · Subprocessors · Security · How LobiPlan uses AI · Data Processing Addendum · Acceptable Use Policy · Accessibility

Changes to this document

This is Version 1.0, effective 2026-08-20.

When we change something that affects what we collect, why we collect it, who receives it, or how long we keep it, we will raise the version number, change the effective date, and tell account holders by email before the new version takes effect. Corrections that do not change any of those things — a clearer sentence, a fixed typo, a link that moved — are made in place and noted below.

Previous versions are available on request from bsimba6@gmail.com.

VersionDateWhat changed
1.02026-08-20First published. Before this date LobiPlan had no privacy policy.