PLAN MONSTER PRIVACY POLICY

Effective Date: May 1 2026

This Privacy Policy describes how Monster collects, uses, and shares Personal Data in connection with the Offerings

Personal Data Collected

Monster collects the following categories of Personal Data:

Purposes of Processing

Monster processes Personal Data to:

Sharing

Monster shares Personal Data with:

Monster does not sell Personal Data in the colloquial sense. Certain disclosures to service providers and partners may constitute a sale or share under the California Consumer Privacy Act. California residents may exercise opt out rights as described below. Monster does not sell or share Google API Data under any definition.

Retention

Monster retains Personal Data for as long as necessary to provide the Offerings, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention practices include:

Your Rights

Depending on your jurisdiction, you may have the right to:

To exercise these rights, contact hello@planmonster.com. Monster will verify your identity before fulfilling requests and will respond within the timeframes required by applicable law.

California Residents

California residents have specific rights under the California Consumer Privacy Act, including the rights listed above and the right to non discrimination for exercising those rights. Monster does not knowingly process Personal Data of California residents under sixteen for sale or sharing.

Children

The Offerings are not directed to individuals under eighteen. Monster does not knowingly collect Personal Data from individuals under eighteen. If you believe Monster has collected such data, contact hello@planmonster.com and Monster will delete it.

International Transfers

Monster operates from the United States. If you access the Offerings from outside the United States, your Personal Data will be transferred to and processed in the United States. By using the Offerings, you consent to this transfer. Where required by applicable law, Monster relies on appropriate transfer mechanisms, including Standard Contractual Clauses.

Security

Monster maintains administrative, technical, and physical safeguards designed to protect Personal Data. No system is fully secure. Monster does not warrant the security of Personal Data and is not liable for unauthorized access not caused by Monster's gross negligence or willful misconduct.

Cookies and Tracking

The Offerings use cookies and similar technologies for authentication, security, analytics, and feature delivery. You may control cookies through your browser settings. Some features will not function without cookies.

Changes to this Notice

Monster may update this Notice from time to time. Material changes will be communicated by email to registered users or by prominent notice within the Offerings.

Privacy Contact

Privacy questions and requests: hello@planmonster.com


GOOGLE API DATA

Plan Monster offers an optional feature that connects to your Google account to surface business intelligence from your existing project communications and project documents, and to assist with project execution by drafting changes to your existing documents and calendar events for your approval. This connection uses Google's gmail.readonly, drive, spreadsheets, calendar, and calendar.events permissions, which allow Plan Monster to read your email messages and metadata, read your project documents, write to user created documents you authorize Plan Monster to correct or enrich (compliance forms, proposals, supporting workbooks), read and write to spreadsheets including the dynamic per project accounting documents Plan Monster creates and maintains for you, and read and edit calendar events including site visit and inspection invites that Plan Monster enriches with project specific information. Plan Monster cannot send, delete, modify, or compose emails in your account.

If you choose to connect your Google account, we use your Google API Data to identify project details, surface potential unbilled work, track deadlines, retrieve project documents, draft document corrections for compliance forms and proposals, enrich calendar invites with project specific information, and provide other business intelligence relevant to your construction operations. We may store processed summaries and extracted information from your Google API Data on our servers to provide the service.

Plan Monster does not write to a user created document or calendar event without your explicit, contemporaneous approval of the specific change. Before any write to user content, Plan Monster surfaces a confirmation dialog showing the proposed change in diff form. The write occurs only after you approve that specific change. You can cancel any pending change before commit and revert any committed change through the Plan Monster audit log.

We process your Google API Data using artificial intelligence systems. This processing involves service providers that operate our AI infrastructure. These service providers process your data solely to provide the Plan Monster service, do not retain your data beyond the duration of the API call (zero retention API tier), and do not use your data to train their own models. The current list of subprocessors is published at https://planmonster.com/subprocessors.

You can disconnect your Google account at any time through your Plan Monster account settings or by contacting us at hello@planmonster.com. You can also revoke Plan Monster's access directly through your Google Account permissions page at https://myaccount.google.com/permissions. When you disconnect your Google account, we will delete the Google API Data we have stored within thirty days.


GOOGLE API SERVICES USER DATA POLICY COMPLIANCE

Plan Monster's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Specifically:

Plan Monster only uses access to Google user data to provide and improve the Plan Monster service for the user who granted access.

Plan Monster does not use Google user data to train, fine tune, evaluate, benchmark, or develop any artificial intelligence model, machine learning model, knowledge engine, or other product or feature beyond the user facing features delivered to the user who granted access.

Plan Monster does not transfer Google user data to third parties except as necessary to provide the service (through our AI processing infrastructure under data processing agreements that prohibit any other use), to comply with applicable laws, or as part of a merger, acquisition, or asset sale with notice to users.

Plan Monster does not use Google user data to serve advertisements.

Plan Monster does not permit humans to read Google user data unless the user has provided affirmative consent for specific messages, it is necessary for security purposes such as investigating abuse, it is necessary to comply with applicable law, or the data has been aggregated and anonymized and can no longer be associated with an individual user.

Plan Monster does not use Google user data for marketing, sales outreach, citation notifications, lead enrichment, public display, or any communication directed to any party other than the user who granted access. Plan Monster's outbound trade citation feature operates exclusively on publicly available web sources and does not access Google user data.

Plan Monster does not sell, license, or share Google user data with any third party for any purpose.