The short version: CriaPlanner is a cloud-synced planner, so it works differently from our other apps — it does require an account (email & password, or Google sign-in), and the to-dos, notes, events, and budgets you create are stored on our servers so they can sync across your devices and be shared with people you invite. Everything is encrypted in transit (TLS) and at rest. We never sell your data, and you can request full deletion at any time by emailing support@alpaca-media.com.
To use CriaPlanner you need an account, created either with an email address and password, or by signing in with Google. Account authentication is handled by Supabase. If you sign up with email and password, your password is hashed and never stored or seen by us in plain text. If you sign in with Google, Google shares your name, email address, and profile picture with us so we can create your account — we don't receive your Google password or any other Google account data.
Because CriaPlanner syncs across your devices and lets you share plans with other people, the content you create is stored in our cloud database (hosted on Supabase, synced via PowerSync), not just on your device. This includes:
All of this is encrypted in transit between your device and our servers (TLS), and encrypted at rest on Supabase's infrastructure.
When you share a Plan or Budget, the people you add can see the items, events, or transactions inside it, along with your display name and avatar. If you invite someone by email who doesn't have an account yet, we send their email address to Resend, our email provider, purely to deliver the invite — that address isn't used for anything else.
If you grant notification permission, we store a device push token (linked to your account and platform) so we can deliver reminders for shared Plan items to other members' devices, even when their app isn't open. This token identifies your device for notification delivery only.
If you use the microphone to dictate a to-do, note, or event, CriaPlanner uses your device's built-in speech recognition (Apple's on iOS, Google's on Android) to convert your speech to text. We do not record or store the audio — only the resulting text is saved, the same as if you'd typed it.
Cria AI is an optional assistant (part of the paid tiers) that turns plain-language requests into tasks, events, notes, and plans. It is powered by Claude, a model made by Anthropic. Nothing is sent anywhere unless you actively use the assistant.
When you send Cria AI a message, the following goes to Anthropic to generate the reply:
We don't store your conversations on our servers — chat history lives only on your device, and our server keeps just a count of your requests (to enforce the daily limit). Under Anthropic's commercial terms, your messages are not used to train their models, and are retained by Anthropic only briefly for abuse prevention.
The free version of the mobile app shows banner ads served by Google AdMob; paid tiers show none. By default the ads are non-personalized — they're picked without using your advertising ID, though Google still processes basic device information and your IP address to serve the ad and prevent fraud.
Only if you switch on Advertising data (in the welcome walkthrough or Settings → Privacy) is your device's advertising ID used to personalize ads. You can turn this off again at any time in Settings → Privacy.
We use Google Analytics for Firebase to understand which features are used, and it is off by default — nothing is collected unless you switch on Analytics data in the welcome walkthrough or Settings → Privacy. When enabled, we receive anonymous usage events (e.g. which screens and features are used) along with app version, platform, OS version, and device model. These events are never linked to your name, email, or the content you create, and you can opt out again at any time in Settings → Privacy.
Here's exactly what each service we rely on does:
Supabase hosts our database and handles authentication. It stores your account credentials and all the app data described above.
PowerSync relays changes between your device and our Supabase database in real time, including while you're offline. It handles the same app content described above in transit; it doesn't independently retain a separate copy of your data.
When you invite someone to a Plan or Budget, we use Resend to send the invite email. Resend processes the recipient's email address and the plan/budget name to deliver that one message.
When you use the Cria AI assistant, your chat messages, your plan titles, and (when you ask about existing items) item titles, dates, and status are processed by Anthropic's Claude API to generate the response — see the Cria AI section above. Not used for model training; nothing is sent unless you use the assistant.
We use RevenueCat to manage the Pro/Family/Group subscriptions. RevenueCat identifies your purchase using an anonymous ID tied to your account, and verifies receipts through Google Play or the App Store.
We use Sentry to receive reports when the app crashes, so we can find and fix bugs. A crash report may include your device model, OS version, app version, and the error context at the time of the crash. Sentry may also log your IP address temporarily as part of the request. We don't deliberately attach personal information to crash reports.
AdMob serves the banner ads shown to free users, per Google's advertising privacy policy. Ads are non-personalized unless you explicitly opt in to advertising data — see the Ads section above.
Receives anonymous usage events only after you opt in — see the Analytics section above and Google's Firebase privacy documentation. Collects nothing while the toggle is off.
If you choose to sign in with Google instead of email/password, Google shares your name, email address, and profile picture with us, per Google's own privacy policy.
Because CriaPlanner is account-based, deleting the app from your phone does not delete your account or data — it's stored on our servers so it can sync back if you reinstall. To permanently delete your account and everything in it:
CriaPlanner does not knowingly collect data from children under the age of 13.
If we make material changes to this policy, we will update the date at the top of this page. We encourage you to review it occasionally.
If you have any questions about this privacy policy, or want to exercise your data rights, reach us at support@alpaca-media.com.