Last updated: 31 August 2026
Pic2Plan is a mobile app that helps you turn letters, documents, emails, screenshots and messages into calendar events using AI. This Privacy Policy explains how we use your personal data when you use our app or visit pic2plan.io.
If you have any questions, please contact us at support@pic2plan.io.
Pic2Plan is owned and operated by The Contract Studio UK Ltd, a company registered in England and Wales.
Company name: The Contract Studio UK Ltd
Registered number: 17020140
Registered office: c/o Bonsai Law, The Business Terrace, Maidstone House, King Street, Maidstone, Kent ME15 6JQ, United Kingdom
Email: support@pic2plan.io
Website: pic2plan.io
For data protection purposes, The Contract Studio UK Ltd is the data controller of your personal data.
We are registered with the Information Commissioner's Office (ICO) under registration number ZC108982.
We are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We collect the following categories of information when you use Pic2Plan:
We only use your personal data when we have a lawful basis under UK GDPR.
Lawful basis: performance of a contract (our Terms of Service) and legitimate interests in running our app.
Lawful basis: performance of a contract and legitimate interests in providing an accurate, automated service.
Lawful basis: performance of a contract (at your request) and legitimate interests in enabling you to share events.
Lawful basis: consent and performance of a contract.
Lawful basis: consent and performance of a contract.
Lawful basis: performance of a contract and legitimate interests in operating a sustainable business model.
Lawful basis: legitimate interests in maintaining and improving our service.
Lawful basis: legal obligation and legitimate interests.
We rely on trusted third-party providers to deliver the app:
These third parties act as processors or independent controllers depending on the service. We only share the minimum data needed for them to perform their functions, and we have appropriate agreements in place where required.
Pic2Plan's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If you choose to connect Google Calendar, we ask for one Google Calendar permission and nothing else:
We do not ask for the broader Google Calendar permission that would allow an app to see, edit, share or permanently delete all of your calendars. Pic2Plan does not read, list, edit or delete your existing Google Calendar events, and it does not touch any calendar other than your primary one.
Signing in with Google is separate from connecting Google Calendar. Signing in gives us only your name, email address and a Google account identifier. If you never use calendar sync, we never ask for the calendar permission.
Google Calendar data and Google authorisation tokens are not stored on Pic2Plan servers. The short-lived Google access token is held only in the app's own storage on your device, and we do not request or hold a Google refresh token, so the token simply expires and you are asked to reconnect. Events flow one way only, from Pic2Plan to your Google Calendar, so no Google Calendar content ever reaches our database.
Information received from Google APIs is used only to provide the calendar sync feature described above. We do not sell it, we do not use it for advertising or profiling, we do not use it to train AI or machine learning models, and we do not transfer it to any other app or third party. The AI extraction described in section 4 runs on the image you upload, before any contact with Google, so our AI provider never receives Google Calendar data.
You can disconnect Google Calendar at any time in the app under Settings, Calendar Sync. Disconnecting revokes Pic2Plan's access with Google and deletes the token from your device. You can also remove Pic2Plan's access at any time at myaccount.google.com/permissions. Events that have already been added to your Google Calendar belong to your calendar and will stay there unless you delete them yourself.
Connecting Outlook Calendar is optional and separate from signing in. If you never connect it, none of this applies to you.
When you connect Outlook Calendar, Microsoft issues Pic2Plan an access token and a refresh token. Unlike the Google Calendar connection, these are held on our servers so that events can be written to your calendar reliably. We store:
We do not store a copy of your Outlook mailbox, contacts or existing calendar entries.
Both tokens are encrypted at rest using AES-256-GCM, with the encryption key held separately from the database as a server environment variable, so the stored values are not readable from a database copy alone.
The connection is used only to add or update an event you have chosen to sync. Pic2Plan does not read, list or delete your existing Outlook calendar entries, does not read your mailbox, and does not use Microsoft data for AI training, advertising or profiling. Events flow one way only, from Pic2Plan to your Outlook calendar, so no Outlook calendar content reaches our AI provider.
You can disconnect Outlook at any time in the app under Settings, Calendar Sync. Disconnecting asks Microsoft to revoke the tokens and deletes them from our database, whether or not Microsoft confirms the revocation. Deleting your Pic2Plan account does the same before the account is removed. You can also remove Pic2Plan yourself at any time at myaccount.microsoft.com/permissions. Events already added to your Outlook calendar belong to your calendar and will stay there unless you delete them.
Some of our service providers may process your data outside the UK and the European Economic Area (EEA). Where this happens, we make sure that appropriate safeguards are in place, such as adequacy regulations or standard contractual clauses approved by the UK Government or European Commission.
We do not sell your personal data.
We will share your data only with:
You have a number of rights over your personal data, subject to certain exemptions:
You can exercise these rights by contacting support@pic2plan.io. We may need to verify your identity before acting on your request.
If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk, but we would appreciate the chance to resolve your concerns first.
Pic2Plan is not directed at children and is intended for users aged 13 and over.
Under UK GDPR, children aged 13 or over can generally consent to online services themselves. We do not knowingly collect personal data from children under 13, and if we become aware that a child under 13 has provided us with personal data, we will delete it.
We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access. Data is transmitted over encrypted connections, your account is identified by a signed session token, and the third-party calendar tokens described in section 6 are encrypted at rest. No system can be completely secure, but we work to keep your data as safe as reasonably possible given the nature of our service.
When you visit pic2plan.io, we may use cookies or similar technologies to make the site work and to understand how it is used.
We may update this Privacy Policy from time to time, for example to reflect changes to the app or to the law. We will post the updated version on pic2plan.io and, where appropriate, notify you in the app or by email. Your continued use of Pic2Plan after any changes means you accept the updated policy.