Recordplane Privacy Policy
Effective date: September 10, 2026 Service operator: Record Plane, LLC Privacy contact: support@recordplane.com
This policy explains how Recordplane handles personal information when you visit our website, sign in, or use our hosted workspaces, APIs, and connected products, including Recordplane Closings. It does not describe how an independent operator handles information in a self-hosted installation.
Information we receive
Account information. When you sign in with Google, Google provides an account identifier, email address, verification status, and basic profile information permitted by the openid, email, and profile permissions. Our login integration maps your email and its verification status into Amazon Cognito and uses a stable account identifier to associate your access with Recordplane workspaces. Google manages your Google password; Recordplane does not receive it. These sign-in permissions do not grant access to Gmail messages, Google Drive files, or contacts.
Agent-owned email. Your AI assistant’s mailbox is connected in the platform where that assistant runs, not in Closings. Closings receives messages and attachments the assistant submits under the access you grant. That connection does not give Closings access to the rest of the mailbox or its mailbox credentials. Manage the assistant’s email permissions with its provider.
Previously enabled Google mailbox connections. Closings no longer offers this connection in its product setup. The following describes data handling for any separately enabled or retained Google mailbox connection. With the mailbox owner's consent, Google provides a verified account identifier and email address and authorizes Closings to send email through that mailbox. The initial connection requests openid, email, and gmail.send; it does not grant Closings permission to search or read the inbox, attachments, contacts, or Drive files. Additional access would require a separate explanation and consent.
Recordplane stores the connection's account identifier, email address, status and encrypted refresh token. The refresh token is retained for separately enabled, authorized sending. When approved sending is enabled, the dedicated sender uses it to obtain temporary access tokens without asking the mailbox owner to sign in for each authorized action. Mailbox credentials are not included in transaction exports or provided to connected AI assistants. We retain connection changes and bounded security/error information; provider credentials and authorization codes are excluded from routine logs. Connecting a mailbox alone does not enable reminder sending, approve a reminder plan or authorize arbitrary email.
Workspace information. You, your organization, invited participants, and authorized agents may submit business records, contacts, transaction details, documents, messages, signatures, approvals, and other content. We also record membership, permissions, changes, and activity needed to maintain the workspace's history. The information collected depends on the features you use.
Service and support information. We process requests, technical logs, device and network information such as IP addresses, security events, and communications you send to support. Where a paid plan is enabled, we receive billing identifiers, subscription status, and related payment events from Stripe. Stripe-hosted payment pages collect card details.
How we use information
We use this information to authenticate users; administer organizations and workspaces; execute authorized actions; deliver documents and communications; maintain audit history; provide export and support; manage billing; and investigate abuse, errors, and security incidents. We also use information where necessary to comply with applicable obligations and resolve disputes.
Google sign-in information is used for authentication and account administration. Data from an optional Closings mail connection is used to identify the connected mailbox and maintain its authorized connection. When approved sending is enabled, the service also uses this data to send approved transaction correspondence and record the outcome supported by the provider. Provider acceptance does not establish delivery or whether a recipient read the message.
Our use and transfer of information received through Google APIs follows the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements. Recordplane does not sell that information, use it for advertising, or use it to train generalized AI models. Workspace information that you separately authorize an AI assistant to access is also handled under that assistant provider's policies and your selected settings.
Who receives information
Workspace information is available to people and agents according to the access the workspace authorizes. Workspace administrators can manage membership and access; contact your organization about its own use and retention of information. An invitation, shared document, participant link, or authorized integration may disclose information to its intended recipient or provider.
We use service providers to operate the service, including Amazon Web Services for hosting, storage, and identity infrastructure; Google for Google sign-in and enabled Google Workspace correspondence; and Stripe for enabled billing features. Email and other integration providers receive information needed for the features you or your organization enable. Those providers may also handle information under their own policies.
We may disclose information when required by law, to protect people and the service against fraud or security threats, or in a business transfer subject to applicable protections and notice.
Cookies and browser storage
Recordplane uses session cookies and temporary sign-in cookies to authenticate requests and protect the login process. Browser storage may retain interface preferences. Blocking necessary cookies can prevent sign-in. Google and other providers may set their own cookies on their sites.
Retention and deletion
We retain information for service operation, workspace history, security, and applicable legal obligations. Retention can depend on workspace policies and legal holds. Account deletion, workspace deletion, and removal of a Google connection are different actions: removing Google access does not automatically remove workspace records.
A successful disconnect of the optional Closings mailbox removes its active refresh-token ciphertext from the live connection store and blocks new sends through that connection. An email already in flight may still complete. Disconnection does not delete messages from Gmail, transaction records, retained correspondence or audit history, and does not itself revoke every permission granted to the app in Google. Google Account connection controls can remove the provider grant. Backup copies follow the service's backup retention and restore controls; restoring a backup must not reactivate a disconnected mailbox or prior reminder approval.
Contact support@recordplane.com to request access, correction, export, or deletion. We may verify your identity and authority over the affected workspace. Hosted workspace deletion currently requires operator assistance. Export is available independently of plan limits and billing status. We explain any applicable retention or legal restriction when handling a request.
Security and location
We use access controls, encryption, and operational safeguards to protect information. No service can guarantee complete security. The current hosted deployment operates in AWS's US East (Ohio) region. Providers may process information in other locations under their applicable terms.
Your choices
You can manage workspace access through available administration controls and contact us about your information. You can also remove Recordplane's access in your Google Account's third-party connections settings. This can affect your ability to sign in and does not itself delete your Recordplane account or workspace content. Depending on where you live and applicable law, you may have additional rights to access, correct, delete, or obtain your information, object to or restrict processing, or complain to a privacy regulator.
Children
Recordplane is intended for adult business users and is not directed to children under 13. If you believe a child has provided information directly to us, contact the privacy address above.
Changes and contact
We will post updates with a revised effective date and provide additional notice of material changes where required. Send privacy questions to support@recordplane.com at Record Plane, LLC.