Privacy Policy

Date Last Revised: October 8, 2026


This Privacy Policy (“Policy”) governs the manner in which My Purpose Plan, Inc (“My Purpose Plan,” “the Company,” “we,” “our,” or “us”) collects, processes, maintains and discloses information collected from users (each, a “User,” “you,” or “your”) when Users visit, access, and use the My Purpose Plan’s My Purpose Plan (“MPP”) website, https://www.mypurposeplan.com/ (“MPP Website”), send emails, text, and other electronic messages to us via the MPP Website or electronically, and use the My Purpose Plan application (collectively, the “Services”). This Policy does not apply to information we may receive about you through any other means, including any website or application operated by any third party or any application or content (including advertising) that may link or be accessible from or on the Services. 


Please read this Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, you must not use the Services.


This Policy is part of My Purpose Plan’s Terms of Service. By accessing or using the Services, you consent to the collection, processing, use, retention, protection, and disclosure of your information by My Purpose Plan as described in this Policy and as governed by the Terms of Service. This Policy may change from time to time. Material changes to this Policy will be announced in the application and by email before taking effect, and the effective date above will be revised. Prior versions are available upon request.


Personal Information We Collect

My Purpose Plan may collect information from you in a variety of ways, such as:

  • Directly from you when you provide it to us, including by filling in forms on our Services; 

  • Automatically through cookies and similar tracking technologies; and

  • From records and copies of your correspondence (including email addresses), if you contact us. 


In the last twelve (12) months, we may have collected and disclosed the following information to third parties, including service providers, vendors, and our business partners:

  • Identifiers. When you create and use your user account in connection with your use of the Services, you may provide us with identifying information. This information includes your first and last name, email address, telephone number, location, job title, relationship status, and educational level;

  • User content. This includes your purpose statement and the inputs used to create it; purpose tiles, tasks, and plans; daily check-in and check-out entries, including written reflections; messages; feedback; and recognition (“shout-outs”) sent to colleagues.

  • Visual content. This includes images such as a profile photograph.

  • Employer-provided information. Where the Services are provided through your employer, this includes your job role and work area, as provided by you or your employer.

  • Volunteer applications. Applications submitted through Connect include your name, email address, and any file you attach.

  • Connected workspace information. Where your organization has connected a workspace to the Services, this includes task information from that workspace, including the email address identifying the assignee.

  • Calendar subscription information. Where you create a calendar subscription link, this includes the times the link was first and most recently fetched.

  • Internet or other Electronic Network Activity Information. We collect information automatically when you use the MPP Website such as information about your internet connection, your operating system, and browser type, the equipment you use to access the MPP Website, identifiers, interactions with the MPP Website, and information about how and when you access the MPP Website, such as the date and time of your visit, and other session statistics;

  • Device and Usage Information. We collect device type, application version, feature usage, and similar device and usage information through our analytics provider. This information is not used to identify you across third-party applications or websites.

  • Sensitive Personal Information. Content you author within the Services, including a purpose statement or written reflection, may reveal information that applicable state law classifies as sensitive personal information, including religious beliefs or mental or physical health. Precise geolocation may also be sensitive personal information; it is collected only when you request a volunteer search through Connect, used solely for that search, and not stored.

  • Communications Information. This includes information that you provide during communications and interactions with our Services and us, such as by filling in forms on our Services. This may also include information you provide when you report a problem with our Services; and

  • Geolocation Information. We collect device location information such as your IP address, if your device settings allow it. Precise location is collected only when you request a volunteer search through Connect, used solely to find nearby volunteer opportunities, and is not stored beyond the request.

Information We Do Not Collect

We do not collect contacts, biometric information, voice audio — dictation is performed by your device’s own speech recognition, and audio does not reach Company systems — and payment card numbers. Payment processing is performed by Stripe (web) and by the Apple App Store or Google Play for mobile in-app purchases; card details are not transmitted to or stored on Company systems.

Use of Automatic Data Collection Technologies

As you navigate through and interact with the Services, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns (collectively, “Automatic Data”). To collect Automatic Data, we use:


  • Online Analytical Tools. We use tools such as Google Analytics, Squarespace, and Hubspot, to collect information about your use of the Services, which help us track page content, click, touch, movement, scroll, and keystroke activity, and to provide you with information that is relevant to you and optimized for the devices that you use. 

  • Crash diagnostics. If the application stops unexpectedly, we may collect the device model, operating system version, and an installation identifier. No content you author is included in a crash report.

  • Cookies. We use cookies and other similar technologies, such as pixels and tags, to deliver our online tools. Cookies are small text files placed onto your device when you visit and interact with the Services. These technologies enable us to provide and enhance your experience using the Services. The categories of cookies and similar technologies includes: 

  • Necessary and Essential. These cookies enable essential functions of the Services, such as to facilitate logging you into the MPP application, protecting your security, and to help us fight spam, abuse, and violations of our Terms of Service.

  • Preferences. These cookies remember information about your browser and your preferences.

  • Performance, Analytics, and Research. These cookies help us understand and measure how you use the Services and how we can improve your experience using the Services. 


The application contains no advertising software and no cross-application tracking software. The marketing website carries no advertising cookies or cross-site tracking pixels.

Most browsers allow you to modify your settings to accept or deny all cookies or to request your permission each time a website attempts to place a cookie on your device. If you prevent our use of cookies, the Services may not function properly.

Your Consent 

Before your purpose statement is created, the Services present a consent request in plain language describing the storage and artificial-intelligence processing of the content you author. Creation of a purpose statement requires that consent because the described processing is necessary to provide that feature. Consent may be declined and revisited at any time.

Artificial Intelligence Processing

Content you author is transmitted to OpenAI and Google’s Gemini API to generate your purpose statement, translate content between English and Spanish, generate daily check-in content, and, where the Services are provided through your employer, produce the aggregated, role-level employer insight described in the Access to User Content section.

Generated output is produced for your account only. Your content is not used to generate output for other users, with one exception: where the Services are provided through your employer, a short AI-generated insight summarizing themes across employees’ daily reflections may be included in aggregated, role-attributed employer reporting only where at least three distinct employees contributed. This is an AI-written message about a group, never your own words shown to anyone else.

Your content is not used to train artificial-intelligence models, whether the Company’s or either provider’s. This is a contractual commitment of both providers under their paid-API terms.

A provider may retain submitted content for up to thirty (30) days solely to monitor misuse of its service, after which it is deleted except where the provider is required by law to retain it longer. It is not used for any other purpose during that period.

Access to User Content

Employer access. Where the Services are provided through your employer, your employer cannot read the personal content you author, except where you author it in a space shared with your team. This restriction is enforced at the database layer.

Reflections, check-in entries, and purpose statements are readable only by their author. Employer-facing reporting is aggregated and attributes reflections to job role only; it contains no names or direct identifiers, and a role’s data is included only where at least three distinct employees contributed in the reporting period.

Employers cannot view whether an individual has participated in check-ins or reflections, or with what frequency. This restriction does not extend to team recognition (“shout-outs”) and the task-completion leaderboard, which identify participants to their team or employer by design.

Tasks on a collaborative tile — a tile shared between you and colleagues — are visible to that tile’s team by design. Where your employer has connected a workspace integration, those tasks, including their notes, are copied into that workspace. Tasks on your own private tiles are not shared and are not copied.

Internal access. Within the Company, access to user content is restricted to a limited number of engineering personnel for support and fault diagnosis, under a dedicated access grant separate from general administrative access.

How We Use Your Information
We may use information that we collect about you or that you provide to us, including any Personal Information, in aggregated, anonymized, and/or non-personally identifiable form, for any of the lawful bases listed below (except to the extent prohibited by applicable law). We may use your Personal Information to:

  • Present our Services and their content to you including to personalize your experience;

  • Authenticate your identity in connection with use of our Services or respond to your requests;

  • Administer, support, improve, and develop our Services;

  • Improve customer service;

  • Comply with legal processes and safety requirements, including to maintain the security of our visitors, employees, and property, respond to court orders, lawsuits, subpoenas, and government requests, as well as to address legal and regulatory compliance purposes;

  • Share with contractors, service providers, and other third parties we use to support our business, who shall be required to maintain such Personal Information in confidence; and

  • In any other way we may describe when you provide the information and with your consent.

The Company does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising.

How We Protect Your Information

Personal Information is encrypted in transit and at rest. Internal access is restricted by role, and the most personal content receives the narrowest access. We have adopted commercially reasonable administrative, technical, organizational, and physical safeguards appropriate to the sensitivity of the information processed, update and test our security technology on an ongoing basis, restrict access to employees who need to know the information to provide benefits or Services, and train employees about confidentiality and privacy and security.

However, it is well known that transmission of data over the Internet and electronic data storage is not 100% safe. My Purpose Plan cannot and does not warrant the security of your Personal Information. My Purpose Plan is not responsible for the circumvention of any privacy settings or security measures used on our Services, the unauthorized acts of others, or for acts or omissions beyond our reasonable control. Email is not recognized as a secure medium of communication. For this reason, we request that you do not send sensitive information to us by email. However, doing so is allowed, but at your own risk.

Sharing Your Personal Information

Except as set forth in this Policy, My Purpose Plan does not share your Personal Information with unaffiliated third parties without first seeking your approval at the time of collection. My Purpose Plan discloses Personal Information to service providers that process it on our instructions under contract, as described below.

We may share anonymized, aggregated, or non-personally identifiable data with business partners and trusted affiliates for lawful purposes described in this Policy, including aggregated employer insights. Such data is not used for cross-context behavioral advertising.

Below list shows category of recipient and the information received:

  • Cloud hosting and infrastructure providers: Application data, as the platform on which the Services run

  • Artificial-intelligence providers — OpenAI and Google (Gemini API): Content you author, as described in Section 5

  • Payment processors — Stripe, and the Apple App Store or Google Play for mobile purchases: Billing information for paid accounts. Card details are collected by the processor and never reach Company systems

  • Mobile subscription management providers: Your account identifier and email address for every signed-in mobile user, whether or not a purchase is made, and purchase and subscription history

  • Email delivery providers: Email address and name

  • Mapping and location providers: Coordinates you supply at the moment of a volunteer search, which the Company does not store. In the browser version the mapping library loads on each page, which discloses your network address, browser type, and the page address to the provider whether or not you use that feature

    Service providers are prohibited from using Personal Information except to provide the contracted services to My Purpose Plan, and they are required to maintain the confidentiality of your information.

Customer-directed integrations

Where your organization connects a Notion workspace to the Services, the Company sends selected information to that workspace at your organization's direction. This is not a service provider relationship: the receiving workspace is your organization's own, governed by your organization's own agreement with Notion, and the Company acts on a credential your organization's administrator supplies.

For Notion, the company sends tasks on collaborative tiles (title, notes, schedule, completion status, points) authored by the administrator or by employees of that organization, the tiles those tasks belong to, and each such person's name, email address, role and organization identifier. Tasks on a user's own private tiles are not sent

The Company is not a party to that agreement, does not determine the workspace's retention, and cannot revoke the credential on your organization's behalf. Disconnecting the workspace stops any further transfer. That provider offers no permanent-delete capability; where a person leaves your organization, the Company archives their page and assigned task pages, and permanent removal is your organization's own action as controller of that workspace.

Disclosures you direct

Where you apply to a volunteer opportunity through Connect, the Company transmits your application at your request. This is likewise not a service provider relationship: you choose the recipient, and transmitting the application to that recipient is the purpose of the feature.

To Idealist, and through it the organization that posted the opportunity, the Company sends your first name, last name, email address, and any file you attach only at the moment you submit an application.


The recipient is responsible for your application once it is received, and its handling is governed by that organization's and that platform's own privacy practices rather than by this Policy. The Company does not retain a copy of your attachments. The Company retains only a record that you applied, and to which opportunity, for the period stated in Section 9. The Company may also disclose personal information where required by law, and in connection with a merger, acquisition, or sale of assets, in which case this Policy's protections continue to apply to the transferred information.

Data Location

Personal Information is stored on Google Cloud Platform in the United States, in (region us-central1). Every service provider that receives Personal Information is a United States company, and My Purpose Plan transmits Personal Information to no recipient outside the United States.


Children’s Data

Our Services are not intended for children under 16 years of age. We do not knowingly collect Personal Information from children under 16. If you are under 16, do not use or provide any information on the Services. If we learn we have collected or received Personal Information from a child under 16 without verification of parental consent, we will delete that information. Please contact us at privacy@mypurposeplan.com if you believe we might have any information from or about a child under 16.


Data Retention

My Purpose Plan retains each category of Personal Information only for the period stated below. These periods are enforced by automated deletion processes.

  • Account information (name, email address): Duration of the account

  • Content you create — your purpose statement, plans, tiles, tasks (including tasks synchronized from a connected workspace), and uploaded images: Duration of the account

  • Daily check-in and check-out entries, including reflections and the daily content generated from them: 24 months

  • Messages, and recognition sent to colleagues: 24 months. Where your account is deleted sooner, your identifying details are removed so that the other person keeps their copy

  • Feedback you submit, and workplace survey responses: 24 months. Where your account is deleted sooner, your identifying details are removed and the de-identified text and ratings are kept for the remainder of the period

  • Volunteer application records (that you applied, and to which opportunity — never the application or its attachments): 24 months

  • Precise location (volunteer search): Not stored; used only for the moment of the search

  • Job role, work area, and posts to your organization's feed: Life of your employment

  • Connections you or your organization set up — a connected workspace, a calendar subscription link: Until disconnected or removed

  • Aggregated employer reports, which contain no direct identifiers: 36 months

  • Employment records: Duration of employment, then 7 years, as employment law requires

  • Billing records: 7 years, as tax law requires

  • Consent records (date, version, and scope of consent; never content: Duration of the account, then 7 years

  • Records of requests you make (access, deletion, export): Purged 14 days after the request is fulfilled

  • Records evidencing that the Company completed a deletion, and logs of internal access to user content: 3 years

  • Records of security incidents, and of legal holds: 7 years; a legal hold, for its duration plus 7 years

  • Device and usage information: Notification tokens until you sign out; analytics 14 months; crash diagnostics 90 days; service logs 30 days

  • Technical records of payment and integration processing: Up to 180 days

  • Backups: Up to 30 days

When a retention period ends, the information will be securely deleted or de-identified in accordance with this schedule and the Account Deletion section. Information may be retained longer where required by law or to evidence compliance, and crash diagnostics, service logs, and technical payment and integration records expire on the shorter periods stated above.

Account Deletion

You may delete your account at any time in Settings. Deletion proceeds as follows:

  • Immediately. The account is closed and can be used only to cancel the deletion; uploaded images, notification tokens, and reminders are deleted; and future billing is stopped for subscriptions billed directly by My Purpose Plan. Subscriptions billed through the Apple App Store or Google Play must be cancelled separately in the applicable app-store account settings. A calendar subscription link stops publishing immediately and is deleted at fourteen (14) days.

  • For fourteen (14) days. Remaining Personal Information is held to permit reversal. Signing in and cancelling the deletion during this period restores the account and its content, except for items deleted immediately under the preceding step.

  • At fourteen (14) days. All remaining Personal Information is permanently deleted or de-identified in accordance with the Data Retention section, and deletion instructions are issued to the Company’s service providers.

  • Backups. Deleted information expires from backups no later than forty-four (44) days after the deletion request. Backups are not selectively modified; a disaster-recovery restoration re-applies outstanding deletions before the Services return to operation.

  • Employer removal. If an employer removes an individual from its team, team-related content — including check-in and check-out entries, recognition sent to colleagues, organization-feed posts, workplace survey responses, daily AI-generated check-in content, reminders, job role, and work area — is deleted or de-identified within fourteen (14) days. The individual’s personal account persists and its purpose statement, purpose tiles, messages, images, and consent records are not affected; employment and billing records remain subject to the periods stated in Data Retention.


Exercising Control Over Your Personal Information

Subject to certain exceptions prescribed by law, and depending on your state or jurisdiction you may have certain rights to your Personal Information. The Company honors these rights for all users, irrespective of state of residence. These rights include:

  • The right to know what Personal Information we have collected about you;

  • The right to request access to or a copy of your Personal Information;

  • The right to request deletion of your Personal Information;

  • The right to correct inaccuracies in your Personal Information;

  • The right to opt out of certain processing of your Personal Information;

  • The right to opt out of the sale or sharing of your Personal Information; and

  • The right not to be discriminated against for exercising such rights. 


To exercise any of the rights described above, you may submit a request through Settings in the application or through the contact information below: hello@mypurposeplan.com

Please note that we may ask for information to authenticate your identity after you submit a request. We will respond to your request within the timeframe required by applicable law, and within forty-five (45) days of receipt, with one forty-five (45)-day extension where reasonably necessary; we will inform you of any extension. If we deny your request, we will state the reasons. You may appeal by responding to the decision, and we will answer appeals within forty-five (45) days. If the appeal is denied, you may contact the Attorney General of your state.

You or your legally designated representative may submit a request to exercise your Personal Information rights through the above contact information. Where required by applicable law, we will verify the representative’s authority and your identity.

If you have any concerns about our data practices, please contact us. You may also contact the data protection authority in your jurisdiction. We will not discriminate against you for exercising any of the above rights.

Contacting us

If you have any questions about this Privacy Policy, the practices of the Services, or your dealings with the Services, please contact us at:


My Purpose Plan, Inc

12550 North Readers Lane,

Manakin-Sabot, VA 23103
hello@mypurposeplan.com