Legal
Privacy Policy
Last updated: 16 August 2026 · polylane.app
Polylane is operated by Kreativish AI Powered by SMAT Solutions Pvt Ltd("we", "us"), the data controller for the personal data described here. This policy explains what we collect, why, and your choices.
Who we are
- Registered name
- Kreativish AI Powered by SMAT Solutions Pvt Ltd
- Registered address
- NSL East County, Near Uppal Stadium Uppal, Hyderabad 500039 Telangana, India
- GSTIN
- 36ABOCS7049B1Z4
- Phone
- +91 89191 20060
Every third party that processes data on our behalf is listed on our subprocessors page. Business customers are covered by our data processing agreement.
What we collect
- Account data — email, name (if provided), authentication identifiers via Supabase Auth.
- Planner data — projects, channels, tasks, calendar events, and settings you create in the app.
- Billing data — subscription status and payment metadata processed by Stripe (we do not store full card numbers).
- Usage analytics — page views and product events via PostHog (when enabled), to improve the product.
- Waitlist data — your email address, the pursuits you choose for your Polymath Passport, signup source, referral relationship and counts, reward eligibility, consent record, and confirmation, unsubscribe, and delivery timestamps.
How we use data
- Provide, sync, and secure your planner workspace.
- Process subscriptions and send transactional email.
- Operate the Polymath Passport and Studio waitlists, confirm your address, attribute referrals, provide earned template or discount rewards, and send launch updates you requested.
- Improve reliability, support, and product decisions.
Waitlist email & consent
We send Polymath Passport confirmation, referral-reward, and Polylane launch emails based on the consent you give when joining. Joining a waitlist does not create a paid subscription. Every waitlist marketing or launch email includes an unsubscribe option. Unsubscribing stops those emails and does not affect essential messages for a separate product account you may hold.
Processors & storage
We use Supabase (database & auth), Stripe (payments), Vercel (hosting), PostHog (analytics), and Resend (email delivery). Resend receives the email address and message content needed to deliver confirmation, referral-reward, and launch emails. We process unsubscribe choices so those campaign messages stop. Data may be processed in the US or other regions where these providers operate.
Retention
Your planner data — projects, channels, tasks, notes and scheduled events — is kept for as long as your account exists. You can export all of it at any time from your account page, without asking us.
When you delete your account, those records are removed from the live database immediately. Encrypted database backups may still contain them for up to 30 days, after which they are overwritten and unrecoverable. We do not restore a deleted account from a backup.
Billing records — invoices, tax records and the fact that a payment occurred — are retained for 8 years after the relevant financial year, as Indian tax law requires. This is a legal obligation and applies even after you delete your account. It does not include card details, which we never receive.
Waitlist records are kept while the campaign runs and for up to 12 months after launch, so we can deliver requested access, resolve support issues, and measure the campaign. We may keep a minimal unsubscribe record for longer where that is what honours your choice. You can ask us to delete waitlist data sooner.
Error and analytics records are retained by our processors on their own schedules — see the subprocessor list. Analytics only exist at all if you accepted analytics cookies.
Google user data
Connecting a Google Calendar is optional. Polylane works fully without it, and you can disconnect at any time from Account settings. If you do connect one, we request only these scopes:
https://www.googleapis.com/auth/calendar.events— to read the events on the day you are planning, so existing commitments appear as shaded busy time behind your plan, and to write the blocks you choose to push to a calendar. Writing is off by default and happens only for a connection you have explicitly marked writable, and only for blocks you schedule.https://www.googleapis.com/auth/userinfo.email— to show which Google account a connection belongs to. Two connections both labelled "Google" are indistinguishable at exactly the moment it matters.
We read your events at the moment you view a day and do not keep a copy of them. Your Google access and refresh tokens are encrypted at rest and never leave our servers. Disconnecting a calendar, or deleting your account, deletes those tokens.
Polylane's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it to train generalised artificial intelligence or machine learning models. We do not transfer it to third parties except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition, and no human reads it except with your explicit consent for a support request you have raised, or where required by law.
The same applies to a connected Microsoft Outlook calendar, which uses the equivalent Microsoft permissions for the same two purposes.
Your rights
You may withdraw waitlist consent or request access, correction, export, or deletion of your account and waitlist data by emailing kreativish.ai@gmail.com, by using the unsubscribe link in a waitlist email, or by deleting your product account from Account settings in the app.
Changes
We may update this policy. Material changes will be posted on this page with an updated date.