Who is responsible
- The controller for the personal data described in this notice is Julien Ganichot, trading as Applane, a sole proprietorship (eenmanszaak, ZZP) under Dutch law, not a company.
- Address: Faas Wilkesstraat 149G, 1095 MD Amsterdam, Netherlands. VAT id: NL003642041B41.
- Questions about this notice go to hello@applane.dev.
What this notice covers
- This notice covers this website, the Applane Chrome extension and its MCP bridge, the admin console, and the backend that issues licences.
- It does not cover the apps your employees build with Applane. Those run in your own Google Workspace and Google Cloud project; your own policies apply to them.
Visitors and prospects
- When you send the demo form we receive what you typed: work email, company name, a seat range, and an optional sentence about what you would build. We use it to reply to you and to prepare a demo. Legal basis: our legitimate interest in answering a request you made, and your consent when you send the form.
- We do not add you to a newsletter and we do not share the submission with anyone except the processors in section 7.
- If you email us, we keep the correspondence for as long as the conversation is open, then for the period in section 8.
Customers and their employees
- To run the service for a customer company we process: the company name and verified domains; tenant configuration (OAuth client id, Google Cloud project id, admin group address, feature flags); the email addresses of the company’s admins; and a seat record for each employee who signs in to the builder, holding their email address, the first and last sign-in dates and the extension version. Legal basis: performance of the contract with the customer.
- Invoices and payment records are handled through Stripe. We keep the invoice; Stripe holds the billing contact and payment details. Legal basis: performance of the contract and our legal obligation to keep accounting records.
- For employee and admin email addresses, we act as a processor on the customer’s instructions: the customer decides who uses the product. For billing contacts we are the controller.
- We log admin actions in the console and seat activations and reclaims, with the acting email address, so the customer can answer “who changed this”.
What we never process
- Applane is built so that the apps, the model and the data stay inside the customer’s own Google Workspace and Google Cloud project. The extension calls Google directly with the employee’s own OAuth token; nothing is proxied through us.
- As a result we never receive, store or see: Google access or refresh tokens; app source code, files or versions; prompts, chat history or agent transcripts; the contents of any Sheet, Doc, Drive folder, BigQuery dataset or Firestore database; who opens or uses a deployed app; or usage telemetry. The backend’s API has no field to receive any of it.
The Applane extension
- When an employee signs in, the extension sends two things to Applane: the company’s email domain, and a Google ID token that proves which account signed in. We verify the token, record the seat described in section 4, and discard the token.
- Nothing else leaves the browser for Applane. The extension’s only other network destinations are Google’s own APIs, called with the employee’s own token, and the licence endpoint above.
- Chat history, drafts and cached configuration stay in the employee’s browser storage. Removing the extension removes them.
- The extension runs no remotely loaded code. Configuration and advisories are data; no script is fetched and executed.
Processors and data location
- We use the following processors. Each is bound by a data processing agreement.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database and backend functions (tenant config, seats, licenses) | Ireland (EU, eu-west-1) |
| Cloudflare | Network edge and static hosting for this site and the admin console | EU data localisation enabled |
| Stripe | Invoicing and payment processing | EU entity; Stripe holds the billing contact |
| PostHog | Product analytics on this website: page views and clicks on the sign-up and demo buttons. No session recording, no form contents, no identification of visitors | EU (eu.i.posthog.com) |
| Cloudflare Turnstile | Bot check on the demo form | Cloudflare, EU data localisation enabled |
| Email provider (to be named) | Transactional email (licence and admin notices) | EU |
- Personal data we process as a processor for customers stays in the European Union. We do not transfer it outside the EU.
- We will update this table and move the date at the top of this page before adding a processor. Customers with a DPA receive notice by email.
How long we keep data
| Data | Kept for |
|---|---|
| Demo and pilot form submissions | 12 months after the last contact |
| Tenant configuration and admin accounts | Life of the contract plus 30 days |
| Seat records (employee email, first and last sign-in) | 12 months after the seat is reclaimed |
| Admin actions and seat events | 12 months |
| Invoices and payment records | 7 years (Dutch tax law) |
| Server logs (request path, status, IP address) | 30 days |
- When a customer leaves, we delete all of its tenant rows within 30 days, except invoices and payment records, which the law requires us to keep.
Your rights
- You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable format, and object to processing based on legitimate interest. Write to hello@applane.dev; we answer within 30 days.
- If you are an employee of a customer, ask your company’s admin first. The admin console can export or delete your seat record. We help the admin where needed.
- You can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority in your own country.
Data processing agreement
- Customers get a data processing agreement based on the standard EU processor clauses (GDPR Article 28). It lists the data categories in section 4, the processors in section 7, EU hosting, breach notification within 72 hours, and the deletion timelines in section 8. Ask for it at the address in section 1.
Changes to this notice
- When we change this notice we update the date at the top of the page. Changes that reduce your rights or add a processor are announced to customers by email before they take effect.