Planbook is a gradebook and classroom assistant that runs entirely inside a teacher's own browser. It keeps class lists, attendance, grades, and the notes a teacher needs in order to teach a class well. This page says, in plain words, what it stores, where that lives, and what leaves the device.
It is written for teachers, and for the principals and technology directors who are asked to approve it.
The short version
- No server of ours ever receives student information. Planbook has no server, no database and no place to send anything to. It is a web page and the files it is made of, and everything you type stays on the device you typed it on.
- No account is required. There is nothing to sign up for, nothing to sign in to, and no password. You open Planbook and use it.
-
If you choose to turn on Google Drive sync, Drive holds only the file Planbook
itself created. The one permission Planbook asks for is
drive.file, which reaches files this app made and nothing else in your Drive.
What Planbook stores, and where
Everything Planbook holds for a school year is one file's worth of information kept in your browser's own storage, on your own device:
- your classes, terms and grading categories;
- your roster — student names, and any guardian or counselor names, email addresses and phone numbers you enter;
- attendance, hall passes, assignments, scores and any note you add to a score, and the letter scale you set — a note on a score stays on your screen and is never printed or put in a message;
- the support details you keep on students — accommodations, IEP and 504 plans, case managers and review dates, medical needs, behavior plans and what a plan says about attendance;
- what you have written down about a student — short behavior entries and notes to yourself, kept on that student's record and never sent anywhere by the app;
- and a record of the messages you handed over to be sent — to whom, when, the subject and the message, and which signal it was about; not whether it was delivered, which Planbook cannot tell.
Separately, Planbook remembers a few things about this browser rather than about any student: which school year and class you had open last, whether you dismissed the install banner, when you last saved a backup, and whether your mail is a mail app, Gmail in the browser or Outlook on the web. Nothing from inside a student's record is kept there.
What leaves your device, when, and to where
Nothing leaves it on its own. Loading the page fetches Planbook's own files from the website, the way any web page does, and the browser checks those same files for updates. Beyond that, Planbook makes no network requests at all — no analytics, no usage tracking, no error reporting, no advertising, and no third-party code of any kind — except for Google Drive sync, which uses Google's own sign-in library from accounts.google.com. That library loads first when Connect is tapped in About, or when Open from Google Drive is tapped on the first screen of a device with nothing on it yet. Once a sign-in succeeds, sync is turned on for that device, and after that the library loads each time Planbook opens, until sync is switched off in About — which needs no network and no sign-in. Planbook asks Google for a sign-in only when Connect, the sync button or Open from Google Drive is tapped. On a device where neither Connect nor Open from Google Drive has ever been tapped, nothing is fetched from Google.
Student information moves only when you move it, and there are three ways to do that. Each is a deliberate act, and you can see it happen:
- Saving a backup file. Planbook writes a school year — or every year you have — to a file, and your browser saves it wherever you tell it to. The file is yours, on your disk. It is not sent anywhere.
- Turning on Google Drive sync. Optional, off unless you switch it on, and it uploads the year's file to your Google Drive so your laptop and your iPad show the same gradebook.
-
Sending a message you drafted. Planbook drafts an email to a guardian,
counselor or administrator and hands it over unsent, through one of two doors chosen in
the draft itself and remembered by the browser it was chosen in, nowhere else. The default
door is the device's own mail app, reached through an ordinary
mailto:link. The other is Gmail in the browser or Outlook on the web: choose one and the same link opens that site's own compose page in a new browser tab, with the recipient, the subject and the message already filled in — which means the draft travels tomail.google.comoroutlook.office.comin the address of that compose page, on that tap and on no other. That is the site the message is about to be sent from and no other party, and nothing goes there until the link is tapped. Through either door the message is read, changed and sent from the mail account that was going to send it anyway; Planbook never sends mail itself, and the sent copy lands in that account's own sent folder.
There is no fourth destination.
Google Drive sync, and the one permission it asks for
Planbook is fully usable with no Google account at all, and that is not a temporary state of affairs — an app that stops working when a school blocks third-party sign-in is not much use to the teacher it stopped working for. Sync exists to carry one file between a teacher's own devices, and it is off until it is turned on.
When it is on, Planbook asks for exactly one permission:
https://www.googleapis.com/auth/drive.file — "See, edit, create and delete
only the specific Google Drive files that you use with this app."
That permission reaches the file Planbook created and nothing else. The rest of your Drive is invisible to it. Planbook does not ask for access to your other Drive files, to your spreadsheets, or to your mail — and it does not ask to send email as you, because it never sends email at all.
If sync ever needs a different permission, this page changes first, and the date at the top changes with it.
Student records with accommodation and medical information
Planbook deliberately holds IEP and 504 accommodations, case managers, plan review dates, medical needs such as an allergy or a seizure protocol, behavior plans, and what a plan says about attendance. A teacher is legally obliged to implement accommodations, and a list nobody opens protects nobody — so Planbook puts them where the work happens rather than filing them away.
Because that is the most sensitive information in the app, three rules are built into it rather than promised:
- They are never on screen by default. A list shows a small dot beside a name, and the details open only when the teacher deliberately taps for them — because these screens get projected onto classroom walls.
- A presentation mode hides every sensitive field at once, for exactly that moment.
- They never appear in a message Planbook drafts. Its templates refuse to fill in accommodation, medical or plan information at all — a merge field that asks for it is refused rather than filled — so that an email quoting a student's 504 plan is not a mistake that can be made.
The one place this information does travel is a backup file you save, which contains it in as many words. That is deliberate — a backup that left it out would not bring your gradebook back — and the app says so on the screen where you save one. Keep that file the way you keep a paper folder of the same information.
Planbook and student-data privacy — the guide for administrators →What this policy does not promise
Planbook does not encrypt anything. The information sits in ordinary browser storage, and a backup file is plain text that anyone who opens it can read. Someone who can unlock your device and open your browser can read what is in Planbook, the same way anyone who opens your desk drawer can read a paper folder. Lock the device, do not share a login, and keep backup files somewhere only you can reach — and not in an email.
Deleting it
There is nothing on our side to delete, because nothing was ever sent to us. What is on your device is yours to remove: clearing this site's data in your browser's settings, or deleting the installed app along with its data, removes everything Planbook is holding on that device. That cannot be undone, so save a backup first if you want one.
A backup file you saved is an ordinary file and stays until you delete it. If you turned on Drive sync, the file is in your own Google Drive and you delete it there, like any other file.
Schools, FERPA, and children
Planbook is a teacher's own tool. The school's student information system remains the official record; Planbook does not connect to it and does not replace it. Because no vendor receives student information, adopting Planbook introduces no new third party for a district to evaluate — but whether that satisfies a particular district's obligations is that district's determination to make, not ours. The companion document written for that review is linked above, and it addresses accommodation and medical information directly.
This page describes how the software works. It is not legal advice and it does not make a compliance determination on any school's behalf.
Changes to this policy
If what Planbook does with your information changes, this page changes before the behaviour does, and the date at the top of the page changes with it.
Contact
Questions about Planbook or about this policy:
privacy@hwgteach.com