Privacy Policy
Version 1.3 · Updated 21 September 2026
This policy explains what Cmon collects, why it collects it, who else sees it, and what you can ask us to do about it. It covers the app and the service behind it.
1. In short
We collect what the app needs in order to work: who you are, what you track, and enough about your device to deliver the notifications you asked for. We do not sell your data, we do not use it for advertising, and we do not build profiles to pass on to anybody.
2. Who is responsible
Cmon, —. Write to destek@planokey.com about anything in this policy.
3. What we collect
Only these, and only as you give them to us:
- Account: username, first and last name, email address, a profile photo if you add one, and the identifier your sign-in provider gives us.
- What you keep in the app: challenges, plans, projects, tasks, notes, logs, timers, budget entries, photos you attach, and the settings you choose.
- Social: the posts and comments you write, who you follow and who follows you, the accounts you have blocked, and the reports you send us.
- Device: the push notification token, device and operating system type, app version and language.
- Server records: the time of a request, the address it came from, and error logs.
- Purchases: which plan you subscribed to, when it started, renews or ended, whether you are in the free trial, and the identifiers the store assigns to the transaction. We never see your card or payment details; Apple keeps those.
4. Why we use it
Each purpose, and the basis in law for it:
- To give you the service you asked for — your account, your data, your feed. (Performance of our contract with you.)
- To send the push notifications you chose. (Your consent, which you can withdraw at any time under Settings → Notifications or in your phone’s settings.)
- To keep the service safe: handling reports, acting on abuse, preventing fraud, fixing faults. (Our legitimate interest in a safe, working service.)
- To meet legal obligations and answer lawful requests from the authorities. (Legal obligation.)
- To run your subscription — to open the app to you while it lasts and close it when it ends. (Performance of our contract with you.)
5. Who else sees it
Nobody buys it. It reaches only the providers that run the service for us, and only so that they can run it:
- Google — Firebase Authentication for sign-in, Firebase Cloud Messaging for push notifications, and Cloud Vision, which checks each photo you upload for explicit content before it is shown to anyone. The photo is sent for that check and not kept by Google.
- Our hosting provider, which runs the servers and the database.
- Apple or Google when you sign in with their account: they tell us who you are, and we send them none of your content.
- RevenueCat, which keeps track of subscriptions for us: it receives the store’s receipt and transaction identifiers and the identifier of your account, and tells us whether your subscription is active. It processes this in the United States, under standard contractual clauses.
- Apple, which sells the subscription and takes the payment under its own terms.
We may also disclose data where the law requires it, or to protect the rights and safety of the people using the app. Other people see only what you share with them: your public posts, or — if your account is private — what your approved followers can see.
6. Where it is processed
Some of the providers above process data outside the country you live in. Where that happens we rely on the safeguards they offer, such as standard contractual clauses.
7. How long we keep it
Your account and your content stay for as long as your account does. When an account is deleted we delete or anonymise the profile, and anything that has to remain for other people — a comment in a thread, for instance — is detached from your identity. Server records are kept briefly and then discarded. Where the law makes us keep something longer, we keep only that.
Our own record of your subscription is deleted with your account, and we ask RevenueCat to delete its record of you at the same time. Apple keeps its own record of the sale for as long as its rules require.
8. Your rights
You can ask what data we hold, have it corrected or deleted, restrict or object to how we use it, or ask for a copy to take elsewhere. You can withdraw consent for notifications at any time.
Write to destek@planokey.com and we will answer within 30 days. In Türkiye these are your rights under Article 11 of the KVKK; in the EEA and the UK they are your rights under the GDPR, and you may also complain to your data protection authority.
9. Children
Cmon is not for children under 13. If we learn that an account belongs to one, we delete it. If you believe a child has given us their data, write to destek@planokey.com.
10. Security
Traffic between the app and the server is encrypted, and access to the production database is limited to the people who need it. No system is perfectly secure, so please use a strong password and keep your device locked.
11. Changes to this policy
When this policy changes we move the date at the top and, for a significant change, tell you in the app.
12. Contact
destek@planokey.com