Last updated 6 August 2026
Toplan suggests places to go — an evening out, an afternoon with friends — and checks every suggestion against a real venue on the map. This page says what the app collects to do that, who it goes to, and how to get rid of it.
The short version. There are no ads, no analytics SDK and no tracking across other apps or websites. Nothing is sold or shared with data brokers. What is stored is what a plan is made of, and you can delete all of it from inside the app.
Toplan is made by Burak Aybi, an individual developer. Contact: burakaybi@gmail.com.
You can sign in with Apple, sign in with Google, or continue as a guest.
Everything a plan is made of: the area you picked, the day and time, your budget, who you are going with, the interests you chose, any note you typed, and the stops that came back.
Location is asked for only while you are using the app, and only when you choose "use my location" instead of typing a place. The coordinates are sent to our server to search for venues nearby, and are kept on the plan they produced. No background location, no location history, no movement tracking. You can refuse — typing a place works exactly as well.
Places you keep for later, plus any note you write on them and any link you paste as a reminder of where you saw the place.
A room is a shared board for deciding with friends. Joining needs no account: your identity in a room is a random token generated on your device. Stored: the name you type when you join, the places added, the marks and votes given, and the days marked as available. Anyone with the room link can see these.
Only if you turn them on: a device token from Apple and the language to write the notification in. Turning notifications off deletes it.
Purchases go through Apple. We never see your card, your Apple ID password or your billing address. What we store is what Apple's signed receipt contains: a subscription identifier, which product, and when it expires — enough to know whether your subscription is live.
Toplan cannot do its job alone. These are the services involved, and what reaches each of them:
| Service | What it receives | Why |
|---|---|---|
| Supabase | Your account and everything above | Database and sign-in. Hosted in the EU (Frankfurt). |
| Render | Requests to the Toplan API | Runs the server. |
| Google Places | The search text and, if you allowed it, your coordinates | Finds real venues and their addresses, ratings and hours. No account information is sent. |
| DeepSeek | What you asked for: the area, day, budget, who with, your interests and any note you typed | Drafts the kinds of place to look for. It is never told who you are — no name, no email, no account id. |
| Ticketmaster | A city or coordinates and a date range | Finds concerts, theatre and exhibitions. |
| Apple | Payments, and notification delivery | Subscriptions and push notifications. |
The AI provider may change; if it does, this page is updated. Nothing is sold, rented, or given to advertisers or data brokers.
If you share a plan, anyone with the link can open it and vote on it. The page shows the plan, the stops, any note you wrote on it, and the names people type when they vote. It shows nothing about your account — not your email, not your name, not your other plans. Turning sharing off revokes the link and deletes the votes.
Plans, saved places and rooms stay until you delete them or delete your account. Venue details fetched from Google are cached for up to seven days. Rooms exist until the person who opened one deletes it.
In the app: Settings → Delete account. This deletes your plans, saved places, the rooms you opened, your seats in other people's rooms, your notification tokens, your subscription record, your usage counters, your profile, and the login itself. It cannot be undone.
Deleting your Toplan account does not cancel an App Store subscription — Apple owns that. Cancel it in your Apple ID settings.
You can also write to burakaybi@gmail.com and ask for a copy of your data, a correction, or deletion.
Toplan is not directed at children under 13, and accounts are not knowingly created for them.
Traffic between the app and the server is encrypted (HTTPS). API keys live on the server and are never shipped inside the app. Your sign-in session is kept in the device keychain.
If this policy changes, the date at the top changes with it, and a material change will be announced in the app.