Last updated: February 2026
The short version: Your content is encrypted in your browser before it ever reaches our server. We cannot read your documents. The encryption key lives only in the link you share — we never see it.
WhatPlan uses AES-256-GCM encryption, performed entirely in your browser using the Web Crypto API. When you create or edit a document:
Our server stores only:
We do not store encryption keys, document titles, task names, photos in readable form, or any other plaintext content.
WhatPlan uses your browser's localStorage to:
This data stays on your device and is never sent to our server.
WhatPlan does not use cookies, analytics services, advertising trackers, or any third-party tracking tools. We do not collect usage data, browsing behaviour, or personal information.
Photos added to tasks are resized on your device for efficiency, then encrypted alongside the rest of your document content before being stored. We cannot view or access your photos.
Documents remain stored on our server until they are naturally cleared. Since we cannot read document content, we cannot identify or target specific documents for removal. If you lose the link (and its encryption key), the document becomes permanently unreadable.
If you have questions about this privacy policy, you can reach us through the WhatPlan project page.