Privacy Policy

At a glance

Your data stays with you by default

During normal use, session data is stored locally in your browser, in local storage and in the URL. If you use an API or MCP interface, the data sent for that request is transmitted to and processed by the server.

You decide what to share

Your session data is contained in the URL, so you share it by sharing the link. If you enable the optional Dynamic Link, your plan is also stored on the server so multiple devices can work on the same session and the link always shows the latest version. You can disable the Dynamic Link at any time.

Anonymous usage statistics

We collect anonymized usage statistics without cookies to improve the application. You can opt out at any time below.

1. How Sessionplan works

Local data storage (default)

By default: All session data is stored locally in your browser, in local storage and in the URL. During normal use, no session data is sent to a server.

This includes:

  • Session titles and descriptions
  • Block content, notes and material details
  • Timing and duration information
  • Custom block types and people
  • Saved templates and library entries

All of this stays on your device. Data is only shared when you actively share a link, enable the Dynamic Link, or use an API or MCP interface.

You can delete local copies in the session history or remove all locally stored data through the settings.

Optional Dynamic Link (server storage)

If you enable the Dynamic Link in the share dialog, your session data is sent to the server whenever it changes. This allows multiple devices to work on the same session and keeps the link up to date.

  • Enabling it is voluntary and requires an explicit action
  • The session content is transferred in plain text
  • No personal data is stored server-side by default
  • The server copy is deleted when you disable the Dynamic Link or delete the session from its history
  • Legal basis: consent under Art. 6 (1) (a) GDPR

API, OpenAPI and MCP

Sessionplan also provides technical interfaces: a REST API at /data/openapi.yaml and an MCP server at /mcp/. When you use these interfaces, the session data you submit is transmitted to and processed by Sessionplan. This also applies when you use an external AI tool to access them.

These interfaces create or read snapshot links and do not permanently store the submitted session as a server-side session. Processing takes place for the individual request. Technical requests may still be recorded in server and API logs, for example with the endpoint, status, time, a pseudonymized IP address and technical counters. The session content itself is not written as API log text.

With a GET request, a submitted link or snapshot code may also appear in browser history, the URL and technical access logs. For sensitive content, use the POST variant where possible and avoid entering confidential data into Sessionplan or an external AI tool.

When you use an external AI tool, its own privacy policy also applies. Sessionplan cannot control how that tool processes the content you enter there.

What you should not store using a Dynamic Link

Dynamic-Link data is stored in plain text on the server. Please do not store confidential or sensitive content, including:

  • Sensitive personal data such as health information, passwords or financial data
  • Copyrighted content without the required permission
  • Illegal or otherwise unlawful content

If you notice problematic content in a shared link, please report it to sessionplan@timjpeters.com. We will review it and remove reported content as quickly as possible.

No guarantee of data availability

We make an effort to keep content shared through Dynamic Links available, but cannot guarantee permanent storage. As a rule, data remains available for at least 90 days after its last use; this may change without prior notice.

Our advice: If your session plan is important, regularly export it as a JSON file through the settings and store it locally.

Your rights and control

  • Delete individual sessions through the session history
  • Delete all locally stored data through the settings
  • Export sessions as JSON and store them locally
  • Delete server copies by disabling the Dynamic Link or deleting the session from its history

Who is responsible?

Responsible for this website and its data processing:

Tim J. Peters
c/o co.up
Adalbertstraße 8
10997 Berlin
Germany
Email: sessionplan@timjpeters.com

2. Website hosting

This website is hosted externally. When you visit the website, technical data such as your IP address, browser type and access times may be stored in server logs. This is technically necessary to deliver the website.

Hosting is based on Art. 6 (1) (f) GDPR, our legitimate interest in providing the website securely and efficiently.

3. Your data protection rights

You have the following rights at any time:

  • Access: request information about stored data
  • Rectification: request correction of inaccurate data
  • Erasure: request deletion of your data
  • Withdrawal: withdraw consent to data processing at any time
  • Complaint: lodge a complaint with a data protection supervisory authority

Data portability: Since session data is stored locally, you can export it as a JSON file at any time and use it freely.

This website uses SSL/TLS encryption for secure data transmission. You can recognize this by the lock icon and “https://” in your browser address bar.

4. Usage statistics with Matomo

What is collected?

This website uses Matomo, privacy-friendly open-source software for usage statistics. Matomo is self-hosted and does not use cookies.

The following anonymized data is collected:

  • Anonymized IP addresses (the last bytes are removed)
  • Approximate location (country or region only)
  • Date and time of your visit
  • Pages visited and referring website
  • Browser and operating system
  • Features used, such as creating a block or exporting data

These statistics help us understand which features are used and improve Sessionplan. The data is anonymized and cannot be used to identify you.

The data is not shared with third parties and remains on our own servers in Germany. There is no connection to Google, Facebook or other tracking services.

You can disable tracking below. Your choice is stored locally in your browser.

Technical log files

When you visit the website, technical information is automatically stored in server log files. This is technically necessary to display the website, including your browser, operating system, referrer URL, hostname, access time and IP address.

This data is not combined with other data sources or used to identify you.

Matomo Analytics opt-out

This website uses Matomo Analytics to create anonymized usage statistics. Matomo works without cookies and does not store personal data.

You can disable or re-enable tracking at any time:

○ Tracking is active

Last updated: 9/9/2026