Privacy Policy
How shadow-planner handles your data — planning data stays in a local database on your device; data is shared only when you actively use the optional AI providers or Stripe checkout. No analytics, no tracking.
Last updated: 7 September 2026
1. Data controller
The controller responsible for data processing within the meaning of the EU General Data Protection Regulation (GDPR) is:
Martin Grüner Kolbegasse 71A/8 1230 Vienna Austria Email: martin.midori@fileshiftr.app
2. Overview
shadow-planner is a project-planning application that runs locally on your device. All planning data you enter stays on your device and is not transmitted to the controller. Data is shared with third parties only in the cases expressly described below, and only when you actively use the relevant feature.
3. Data processed locally on your device
The following data is stored exclusively in a local database (SQLite) on the device where the application runs:
- Planning data — scenarios, projects, epics, tasks, employee records (including the name, email address, role and cost rate you enter for each person), assignments, resource-allocation and utilisation data, labels, and saved scenario snapshots and templates;
- Settings you configure, including any API keys you choose to store for AI services;
- The change history (audit log), which records write operations performed within the application, together with the originating chat-prompt excerpt where applicable;
- Chat history of the optional AI assistant, and any planning drafts you create.
This data is neither collected nor accessed by the controller. You are responsible for securing and protecting the device on which the data is stored.
Note on employee data: If you enter personal data of third parties (for example, employees) into the application, you are the controller for that data within the meaning of the GDPR and are responsible for processing it lawfully — including providing those individuals with any information they are entitled to.
4. Transfers to third parties
Data is transferred to third parties only in the cases below. Whenever the application connects to an external service, your IP address is necessarily transmitted to that provider for technical reasons.
4.1 AI assistant (optional)
The application includes an optional AI assistant. The default provider is Ollama, which runs entirely on your own device — when you use it, no data leaves your device.
If you instead choose a cloud-based provider, your chat input together with the project context required to answer your request (which may include employee and project data) is transmitted to the provider you select:
- Anthropic, PBC (United States) — Privacy Policy
- OpenAI, L.L.C. (United States) — Privacy Policy
- OpenRouter, Inc. (United States) — Privacy Policy
Using a cloud provider requires you to actively select it and to supply your own API key. The AI assistant is active only if you set it up and use it.
Your responsibility when using a cloud provider. Whether, when and which data is sent to a cloud-based AI provider is decided solely by you, by selecting that provider, supplying your own API key and submitting a request. The controller has no contract with these providers on your behalf, is neither their processor nor a joint controller with them, and has no access to or control over the data you transmit or over how, where and for how long the provider processes, stores or uses it. That processing takes place exclusively under the terms and privacy policy agreed between you and the provider. The controller accepts no responsibility or liability for it. Before enabling a cloud provider, make sure you are permitted to disclose the data concerned — in particular personal data of employees or other third parties and confidential business information — and, where required, obtain the necessary consent or conclude a data-processing agreement with the provider yourself. If in doubt, use Ollama on your own device.
4.2 Payment processing (optional)
The application can be used free of charge. Unlocking the paid tier is an optional one-time purchase, processed by the payment processor Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., United States). If you make the purchase, the payment and billing details you enter during checkout are processed directly by Stripe through its hosted checkout page; the application itself never receives or stores card details. Only an identifier of your Stripe customer account, an identifier of the payment, and the resulting license status are stored locally. The license is perpetual — it does not expire, and the application performs no recurring online license checks. If you reinstall the application and use the license-recovery feature, the email address you enter is transmitted to Stripe in order to locate your purchase and restore your license.
Further information: Stripe Privacy Policy.
5. No analytics, no tracking
The application contains no analytics, tracking or advertising services. No usage statistics are transmitted to the controller or to any third party. All program files, including the open-source libraries used to render the interface, are bundled with the application — the interface loads no resources from third-party servers. The application does not include an automatic update mechanism — updates are delivered solely through the Microsoft Store or Snap Store, whose own privacy terms govern that distribution.
The browser's local storage (localStorage) holds only functional settings, such as the selected theme (light/dark), the current scenario and chat-session identifiers, and view preferences for the Gantt and utilisation screens. This data remains on your device.
6. Legal bases
Where personal data is processed, this is based on the following legal bases:
- Art. 6(1)(b) GDPR — processing necessary to perform a contract (providing the application and, where made, the one-time purchase);
- Art. 6(1)(f) GDPR — legitimate interest in a functional and secure application;
- Art. 6(1)(a) GDPR — consent, where you actively use optional features such as the cloud-based AI assistant.
7. Retention
Data stored locally remains on your device until you delete it within the application or remove the application together with its data. The change history (audit log) can be given a retention period in the settings. For third parties (Anthropic, OpenAI, OpenRouter, Stripe), retention is governed by their respective privacy policies.
8. Your rights
Under the GDPR you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Because your planning data is stored locally on your device, you can exercise most of these rights directly within the application — by viewing, editing, exporting and deleting your data. For matters concerning the controller, please use the contact details in Section 1.
9. Right to lodge a complaint
You have the right to lodge a complaint with a data-protection supervisory authority about the processing of your personal data. The authority responsible for the controller is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde) Barichgasse 40–42, 1030 Vienna, Austria Email: dsb@dsb.gv.at Web: www.dsb.gv.at
10. Changes to this policy
This privacy policy may be amended if the features of the application or the applicable legal framework change. The version embedded in the application at the relevant time applies.