Privacy Policy

This Privacy Policy explains how pullplane processes your personal data when you use our service — a live, multiplayer Kanban board with collaborative card documents where your team and AI coding agents work on the same project. pullplane is currently in early access / beta. We process personal data in accordance with the EU General Data Protection Regulation (GDPR/DSGVO) and applicable German data-protection law.

Last updated: 18 June 2026

1. Controller & Contact

The controller responsible for processing your personal data within the meaning of Art. 4(7) GDPR is:

  • liebhardt.io UG (haftungsbeschränkt)
  • Nußbaumstr. 29, 66121 Saarbrücken, Germany
  • Managing Director: Arthur Liebhardt
  • Register: Local Court (Amtsgericht) Saarbrücken, HRB 106575
  • VAT ID: DE366044881
  • Email: support@pullplane.com

We are not legally required to appoint a Data Protection Officer (DPO) under Art. 37 GDPR / § 38 BDSG. For any questions or requests concerning data protection, please contact us at support@pullplane.com.

2. Overview & Scope

This policy covers the personal data we process when you visit, sign up for, and use pullplane, including its core features: real-time collaborative Kanban boards, Notion-like collaborative card documents, the AI coding agents you invoke by @mention (@claude, @codex, @research, @reviewer), the connected GitHub integration, the isolated cloud sandboxes in which agents run, and billing.

It applies to all users and to anyone whose data we process in the course of providing the service (for example, members invited to a workspace). It does not govern third-party websites or services we link to, nor the independent processing carried out by a model provider when you connect your own subscription or API key (see "AI Agents & Model Providers").

3. Categories of Personal Data We Process

Depending on how you use pullplane, we process the following categories of personal data:

  • Account / identity data: your name and email address and a hashed password; or, when you sign in with GitHub, your GitHub username, email, avatar and public profile.
  • Workspace / organization data: organization and board names, membership, roles, and invitations.
  • User content: boards, cards, collaborative documents, comments and feedback — which may contain source code and any other content you choose to add.
  • Repository data: GitHub access tokens and the repository content that is cloned into a sandbox during an agent run.
  • Model credentials: API keys and/or OAuth tokens for your connected Claude or Codex provider, stored so we can run agents on your behalf. These are sensitive credentials, kept confidential and transmitted only to the relevant model provider to perform a run.
  • Run & usage data: agent run records, sandbox logs, and runtime minutes / usage data used for billing and enforcing limits.
  • Payment data: handled by Polar.sh as merchant of record; we receive billing status and metadata, not your full payment-card number.
  • Technical data: IP address, browser / device information, and essential session and authentication cookies.

5. Account & Authentication

You can create an account with an email address and password, or sign in one-click with GitHub OAuth. Passwords are stored only in hashed form; we never store them in plain text. When you use GitHub sign-in, we receive your GitHub username, email, avatar and profile from GitHub to create and identify your account.

We keep you signed in using essential session cookies (see "Cookies"). The legal basis for this processing is Art. 6(1)(b) GDPR, as it is necessary to provide you with secure access to your account.

6. AI Agents & Model Providers

pullplane lets you invoke AI coding agents by @mentioning them inside a card — @claude (Anthropic Claude), @codex (OpenAI Codex/GPT), @research and @reviewer. When you do so, the relevant content needed to perform the task — the card brief, your prompts, and the connected repository content available in the run — is sent to the relevant model provider so it can produce the agent's output (for example, code changes, a pull request, research or a review). This transfer is necessary to provide the feature you requested (Art. 6(1)(b) GDPR).

If you connect your own model subscription or API key, the corresponding provider (Anthropic and/or OpenAI) processes the run under your own account and that provider's terms, as an independent controller for that processing. Where managed model access is provided by us during the test phase, the provider acts as our processor for that run. Please be mindful of what you place in cards and repositories, as this content may be sent to the model provider to perform a run.

7. GitHub Integration

pullplane integrates with GitHub via OAuth sign-in and a dedicated GitHub App. The GitHub App requests the permissions needed to do its work: reading and writing repositories, branches and pull requests for the repositories you connect.

We store GitHub access tokens to act on your behalf. During an agent run, the connected repository's content is cloned into a fresh, isolated sandbox; the agent makes changes on a branch and opens a pull request. Nothing is merged without a human reviewing and approving it. This processing is based on Art. 6(1)(b) GDPR, as it is necessary to provide the integration you enabled.

8. Sandboxes

Each agent run executes in its own fresh, isolated cloud sandbox provisioned by our infrastructure partner Daytona. The sandbox is created for the run, used to clone your repository and run the agent, and torn down when the run ends. Sandbox contents are ephemeral and are not retained beyond the run, except for the logs and git diffs that are surfaced back to you in the app. This processing is necessary to provide the service (Art. 6(1)(b) GDPR); isolation between runs and users also serves our legitimate interest in security (Art. 6(1)(f) GDPR).

9. Model Credentials & Secrets

If you connect your own model provider, we store the associated API keys and/or OAuth tokens so we can run agents for you. These credentials are treated as sensitive: they are kept confidential and are transmitted to the relevant model provider only to perform runs.

pullplane also lets you store per-repository environment variables — including secrets — that are injected into the sandbox during a run. You control which values you store; secret values can be marked as sensitive so they are handled with additional care. We process these on the basis of Art. 6(1)(b) GDPR to provide the runs you initiate.

10. Payments

Billing for our subscription and one-time plans is handled by Polar.sh, which acts as the merchant of record. Polar.sh processes your payment data (including card details) as a separate controller for that purpose. pullplane does not store full payment-card numbers; we receive only billing status and related metadata needed to manage your plan and usage limits.

pullplane is currently free to start with no credit card required to begin. Processing of billing data is based on Art. 6(1)(b) GDPR (performance of the contract) and, for the statutory retention of invoices, on Art. 6(1)(c) GDPR.

11. Cookies

We use only essential cookies that are necessary to operate the service — in particular session and authentication cookies that keep you signed in and remember your last active workspace. Because these cookies are strictly necessary to provide a service you have requested, they do not require consent.

We do not use third-party advertising cookies, and we do not use tracking or analytics cookies for profiling.

12. Recipients & Subprocessors

To provide pullplane, we use carefully selected service providers who process personal data on our behalf. Where they act as processors, they are bound by data-processing agreements under Art. 28 GDPR and may use the data only as instructed. Our main recipients and their purposes are:

  • Convex (Convex, Inc., USA) — backend application platform, database and real-time sync; stores account, workspace and content data.
  • Cloudflare R2 (Cloudflare, Inc., USA) — object / file storage for uploaded images and attachments.
  • Daytona — provisioning of the isolated cloud sandboxes in which agents run.
  • GitHub (GitHub, Inc. / Microsoft, USA) — OAuth sign-in and repository access (branches, pull requests).
  • Polar.sh (Polar Software, merchant of record) — payment processing and billing; handles card data. pullplane does not store full payment-card numbers.
  • Resend — sending transactional emails (verification, invitations, notifications).
  • Anthropic (Anthropic PBC, USA) — Claude AI agents process the card brief, prompts and repository content during a run.
  • OpenAI (OpenAI, USA) — Codex/GPT AI agents process the card brief, prompts and repository content during a run.

When you connect your own model subscription or API key, the corresponding provider processes that run under your own account and terms rather than as our processor (see "AI Agents & Model Providers").

13. International Transfers

Several of our recipients are established outside the EU/EEA, primarily in the USA (including Convex, Cloudflare, GitHub, Anthropic and OpenAI). Where personal data is transferred to such countries, we rely on the safeguards required by Art. 44 ff. GDPR — in particular the EU Standard Contractual Clauses and/or, where the recipient is certified, the EU-US Data Privacy Framework — to ensure an adequate level of protection. You can request further information about these safeguards via support@pullplane.com.

14. Retention

We keep personal data only as long as necessary for the purposes described above:

  • Account and content data: retained while your account is active and for a short grace period after deletion, unless a longer retention period is legally required.
  • Invoices and accounting data: retained for the statutory periods under German law — generally up to 10 years (§ 147 AO, § 257 HGB).
  • Sandboxes: ephemeral — created per run and torn down when the run ends; sandbox contents are not retained beyond the run, except for logs and git diffs surfaced in the app.

When data is no longer needed and no retention obligation applies, we delete or anonymise it.

15. Your Rights

Subject to the conditions of the GDPR, you have the following rights regarding your personal data:

  • Access — to obtain confirmation of and information about the data we process (Art. 15).
  • Rectification — to have inaccurate or incomplete data corrected (Art. 16).
  • Erasure — to have your data deleted (Art. 17).
  • Restriction — to have processing restricted in certain cases (Art. 18).
  • Data portability — to receive your data in a structured, machine-readable format (Art. 20).
  • Objection — to object to processing based on our legitimate interests (Art. 21).
  • Withdrawal of consent — to withdraw any consent you have given, at any time with effect for the future (Art. 7(3)).

To exercise any of these rights, contact us at support@pullplane.com. We will respond within the periods set out in the GDPR.

16. Right to Complain to a Supervisory Authority

If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is:

  • Unabhängiges Datenschutzzentrum Saarland — Die Landesbeauftragte für Datenschutz und Informationsfreiheit, Saarbrücken, Germany.

You may also lodge a complaint with the supervisory authority of your country of habitual residence or place of the alleged infringement.

17. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or misuse, taking into account the state of the art and the risks involved. These measures include encryption of data in transit (TLS), isolation of each agent run in its own dedicated sandbox, confidential handling of model credentials and secrets, hashed password storage, and access controls. No method of transmission or storage is completely secure, but we work continuously to maintain a level of protection appropriate to the risk.

18. Children

pullplane is a professional developer tool and is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@pullplane.com so we can delete it.

19. Changes to This Policy

As pullplane is in active development and currently in early access / beta, we may update this Privacy Policy from time to time to reflect changes to the service, our processing, or legal requirements. The current version published in the service governs. Where changes are significant, we will take reasonable steps to notify you.

20. Contact for Privacy Matters

For any questions, requests or concerns regarding this Privacy Policy or the processing of your personal data, please contact liebhardt.io UG (haftungsbeschränkt) at support@pullplane.com.