Privacy Policy
Last updated: August 19, 2026
This policy describes how Midnight Plan collects, uses and protects your personal data.
This policy is published in French and English. In case of any discrepancy between the two versions, the French version prevails.
Who we are
Midnight Plan is a web application for planning plans as a group. It lets you propose dates, collect participants' availability, and collectively choose the best time slot.
The service is run by an individual based in Quebec, reachable at the contact address given at the end of this document. That same person answers for the personal information described here.
Data collected
Email address, display name, Google ID, language preference, avatar data (style, seed, color palette), account creation date. Your plan and its status are also stored, along with the end date of a gifted period where applicable. No payment data is collected: no paid plan is open at this time.
Plans created or joined, availability responses per date, associated notes, a global decline ("none of these dates work for me"), participation timestamps. Direct invitations you send or receive keep the inviter-invitee pair and the state of the response.
Local pseudonym per plan, hashed password (optional). This data is scoped to the plan and your session.
When you accept the Terms of Service and this policy, we keep the version accepted and the timestamp, tied to your account. The law requires us to be able to demonstrate that consent was given.
A log records actions with lasting effect: creating, editing, closing or deleting a plan, joining, leaving, adding or removing a date, sending and answering an invitation, removing a participant, exporting your data, deleting your account. Each entry holds identifiers and a timestamp, never a name or an email address. We also note, once a day, that the account was active, without keeping the time of day or the pages visited.
If you report an error from within the application, we keep the correlation code shown on screen, the description you write, and the technical logs of the error once personal information has been redacted. The report is tied to your account so we can tell you when the problem is fixed.
Notifications shown in the bell keep an event type, non-identifying parameters (counts, chosen date), the participation behind the event, and read or unread state. A message from a platform administrator also keeps its text. Your notification settings per event family are kept for as long as you leave them set.
Failed login attempts (type, key, timestamp), kept temporarily to protect against brute-force attacks.
IP address (encrypted at rest, never readable in a backup), request method and path, correlation identifier, timestamp. Written only when a request is rate-limited, an authentication attempt fails, or an authorization check is refused.
The User-Agent header sent by your browser (truncated to 300 characters), from which we derive the browser family and operating system shown in your active sessions. A hashed fingerprint of your IP address, never stored in the clear. Sign-in timestamp.
If you turn on system notifications, your browser creates a subscription specific to that device. We store the endpoint provided by the push service (Google, Mozilla or Apple depending on your browser), encrypted at rest, the two keys used to encrypt message content, a generic label such as "Chrome · Android" so you can recognise the device in your settings, and the creation and last-successful-send dates. We do not store the full User-Agent header. Notification content is end-to-end encrypted: the push service cannot read it. You can withdraw a subscription in three equivalent ways: revoke the permission in your browser settings, turn off system notifications in your profile, or sign out on that device.
How we use your data
Your data is used exclusively to: run the application and coordinate participants, ensure service security and availability, remember your preferences (language, avatar) between sessions.
Session technical data powers the active sessions list on your Profile page, so you can spot a sign-in you don't recognize and revoke it. It is not used for profiling.
We also keep a count of the kind of environment invitation links are opened in (a messaging app's built-in browser, or a standalone browser), to know where the application is actually used and fix the flows that break there. That count is a plain per-day counter, with no identifier and no IP address, and cannot be traced back to anyone.
Other counters of the same kind measure the health of the service: accounts and plans created or deleted per day, successful sign-ins, request volume per route and response times. None of them carries an identifier. We run no advertising, no third-party audience measurement and no data resale, and your data is never used to train a model.
What other participants see
A plan is a shared space. The people taking part in it see your display name or local pseudonym, your avatar, your availability date by date, your notes and your decline if you posted one. The organizer sees the same and can remove you from the plan. If you hold the Plus plan, the matching badge is visible in the participant list.
Access to a plan comes from the invitation link. Anyone holding that link can join the plan and see the above, unless the organizer set a plan password. Treat the link as the key to the door.
A direct invitation goes by email address: an organizer who knows yours can invite you, and your display name then appears in their plan. We never disclose your email address to other participants.
What this processing rests on
Each category of data answers to a specific ground:
- Performance of the service you asked for: account, plans, availability, notes, invitations, notifications shown inside the application.
- Legitimate interest in protecting the service and its users: security log, failed attempts, anti-bot challenge, action log, aggregate counters.
- Your consent, withdrawable at any time with no effect on the rest: system notifications on your devices.
- Legal obligation of demonstrability: keeping proof that the terms and this policy were accepted.
Data retention
- A plan expires automatically. Its expiry date is derived from the last proposed date, never entered by hand.
- The countdown starts from that last date: 30 days for an account-only plan, 7 days for a plan open without an account. When it runs out, the plan, its dates, its time slots, its availability, its notes and its participations are permanently deleted, with no further grace period. Only the anonymous snapshot described in the last point remains.
- Account data (email, profile, avatar) is kept until you delete your account.
- Failed login attempt data is automatically deleted at the end of its analysis window, one hour later at most.
- Session technical data disappears with the session, at most 7 days after sign-in, and immediately if you sign out or revoke the session from your profile.
- Security log entries are kept for 90 days. Reports attached to a resolved issue are deleted 90 days after it is resolved; only an anonymous count remains.
- A notification subscription is deleted as soon as the push service reports the device no longer exists, after 180 days without a successful send, when you sign out on that device, and together with your account.
- Account usage records (action log, daily presence) have no fixed term: they serve to reconstruct the history of a plan, and are deleted along with your account.
- A notification shown in the bell is deleted shortly after you acknowledge it. A message sent by a platform administrator is deleted 24 hours after it is read, or 90 days after it was sent if it stays unread.
- Proof that the terms were accepted is kept without a time limit, because the law asks us to be able to produce it. When you delete your account, it is detached from your identity: what remains is the trace that a consent existed, without knowing whose.
- A statistical snapshot is written at the moment a plan disappears, whatever the cause. It holds no identifier, no text anyone typed and no timestamp finer than the day, only counts and durations. It cannot be tied back to anyone, so it is not subject to a retention period.
- Deleting your account deletes the plans you administer. Your responses in other people's plans are anonymized: the link to your account is cut and your name is replaced by a generic label.
Your rights
At any time, you can:
- View and edit your profile (display name, language, avatar) on the Profile page.
- Download your data as a structured, machine-readable file from the Profile page, without having to write to us. This is the right to portability under section 27 of Quebec's Law 25.
- Delete your account. Plans you administer are deleted, your responses in other plans are anonymized.
- Withdraw a consent, in particular the one given for system notifications, without the rest of the service suffering for it.
- Request access to your information, its correction or erasure, or object to a processing operation and ask for it to be restricted.
- Ask for the dissemination of information about you to stop, or for it to be de-indexed, where the conditions of section 28.1 of Law 25 are met.
- File a complaint, following the procedure described below.
For anything that cannot be done from within the application, write to us at the address at the end of this document. You will receive an answer within 30 days of your request being received.
Complaints and recourse
A complaint is filed by email to the address at the end of this document, with "complaint" in the subject line. We acknowledge receipt, review it, and answer you in writing within 30 days, stating what was done about it. If the complaint concerns a decision we made, the answer sets out the reasons for it.
If our answer does not satisfy you, or if access or correction is refused, you may turn to the Commission d'accès à l'information du Québec. Someone living elsewhere in Canada may contact the Office of the Privacy Commissioner of Canada, and someone living in the European Union, the supervisory authority of their country.
Third-party services
Authentication: Midnight Plan uses Google OAuth 2.0. No passwords are stored on our servers. Data received from Google is limited to your email address and Google ID.
Anti-bot: Google reCAPTCHA v2 may activate during repeated login attempts to verify you are not a robot.
Hosting: the application and its database are hosted by Hostinger, on servers located in the United States.
Network relay and backups: all site traffic goes through Cloudflare, which terminates the encrypted connection ahead of our servers and therefore sees the IP address and the content of every request. Database backup copies are stored there too. Cloudflare acts as a processor, on infrastructure located in the United States.
Delivery of system notifications: your browser's push service (Google, Mozilla or Apple). Message content is end-to-end encrypted and stays unreadable to them, but those services know that a message was sent and when.
Cross-border data transfers
Our servers are located in the United States. All the data described above therefore resides there, as do the backup copies and the traffic passing through Cloudflare. In addition, technical data is sent to Google LLC when you sign in or when an anti-bot challenge is triggered (identifiers, IP address, verification signals), and to your browser's push service if you turn on system notifications. All of these communications leave Quebec, Canada and the European Union.
Legal basis for the transfer: these transfers rely on the Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented where applicable by technical measures implemented by the providers to ensure an equivalent level of protection.
Privacy impact assessment (PIA): in accordance with section 17 of Quebec's Act respecting the protection of personal information in the private sector, a PIA documenting these communications outside Quebec (hosting, network relay, backups, Google services and push services) is maintained internally and available on reasoned request.
Who has access to your data
Inside the service, one category of people has access to personal information: platform administrators. They have an admin panel that reaches the list of accounts, the content of a plan, the security logs, the IP addresses those contain once decrypted, and error reports. Administrator access is not granted from within the application: it is assigned by hand, directly in the database.
That access is limited to what technical support, security and legal compliance require. Every consultation and every administrator action is written to a log the interface cannot alter. No administrator can read a plan password or a local password: they are hashed and never returned, to anyone.
Outside the service, only the processors named above are involved (host, network relay, authentication, anti-bot and push services), solely to run the service. No data is sold, rented, traded or disclosed to a third party for commercial purposes.
Cookies and local storage
Midnight Plan sets a single cookie of its own: the secure session cookie (HttpOnly, SameSite) that keeps you signed in. It is strictly necessary for the service to function.
The reCAPTCHA anti-bot challenge, triggered only after several failed sign-in attempts, sets third-party Google cookies. It is treated as strictly necessary to the sign-in action you initiated, and therefore loads even if you refused non-essential cookies: without it, sign-in cannot complete.
The application also keeps a few values in your browser's local storage, none of which are ever sent to our servers: your cookie choice, your theme, your language, the banners and release notes you have already seen, and the state of the prompt offering system notifications. They stay on your device and are cleared with your browsing data. This public site keeps only one, your theme.
No advertising cookies, no audience trackers, no third-party traffic measurement.
Your choice can be changed through the "Cookie preferences" link in the application's footer, present on the sign-in, join and profile screens. It applies to this browser and can be revisited as often as you like.
Automated decisions
We make no decision about you based exclusively on automated processing, with one exception: the security measures that limit the number of attempts, trigger an anti-bot challenge, or temporarily refuse a request. They rest on technical thresholds, never on a profile of a person, and lift on their own. If one of them blocks you, write to us and we will explain what triggered it.
Confidentiality incidents
We keep a register of confidentiality incidents. If an incident presents a risk of serious injury, we notify the Commission d'accès à l'information and the people concerned without delay, describing the nature of the incident, the information involved and the steps to take to limit the consequences.
Minors
The service is intended for people aged 14 and over. Below that age, consent must come from the holder of parental authority. We do not ask for proof of age, and we collect no extra information to verify it. If you find that an account was opened for a child under 14 without your agreement, write to us and we will delete it.
Changes to this policy
This policy changes as the service does. The date it was last updated is shown at the top. For a substantial change, a new version number is published and your acceptance is requested at your next sign-in. A change of form or wording does not trigger a new acceptance.
Contact
For any questions about your personal data, contact us at:
Personal information protection officer: the person running the service, reachable at the address above. Any request for access, correction, portability, withdrawal of consent or deletion receives a response within 30 days of its receipt.