Who can see what, and what happens to your plan
An event plan gets shared with people who never make an account: a helper, a caterer, a guest, the person running the day. This page says exactly what each of them can see, when the plan is read by a model, where your data lives, and how to take it back. The two lists below are generated from the same rules the product enforces, so they cannot drift from what actually happens.
Every link that can reach your plan
There are 10 kinds of link, and each one shows one audience one slice of the plan. 5 of them end together, from one button in the event's Settings under Shared links. The rest end on their own, or stay alive on purpose.
Link secrets are looked up by a one-way hash, so a link that reaches the wrong person can be switched off on its own, without changing anything else.
Links that are switched off during the current pilot are not listed here. This page reads the same switch the rest of the site does.
Vendor packet
- Who creates it
- You
- Who it is for
- A booked vendor — the caterer, say
- What they see
- What they owe you and by when; headcount and dietary needs as totals.
- What they never see
- Guest names, emails, phones, or anything a guest wrote you.
- Lives for
- 14 days after the event date.
- Switching it off
- One button, in the event's Settings under Shared links. Or pause that one packet from the vendor's row.
Vendor confirmation
- Who creates it
- You
- Who it is for
- A booked vendor
- What they see
- The details you asked them to confirm or correct.
- What they never see
- Guest names and contact details; other vendors' terms.
- Lives for
- 14 days after the event date.
- Switching it off
- One button, in the event's Settings under Shared links. Or end that round from the vendor's row.
Handoff packet
- Who creates it
- You
- Who it is for
- The person running the day
- What they see
- The run of show and a contact card, built fresh each time it is opened.
- What they never see
- Anything tagged organizers-only; guests' personal details.
- Lives for
- 14 days after the event date.
- Switching it off
- One button, in the event's Settings under Shared links. Or stop sharing the packet from the event's own door.
Plan link
- Who creates it
- You
- Who it is for
- Helpers, vendors or guests — you pick the audience per link
- What they see
- The timeline items and details tagged for that audience, in a view built for that role. Your contact card appears only if you switched it on for helpers or vendors.
- What they never see
- Anything tagged organizers-only; who is assigned to what; internal notes; guest names, emails and phones.
- Lives for
- 30 days from the day it is made. A named per-person link keeps the date you choose — and never expires if you choose none.
- Switching it off
- One button, in the event's Settings under Shared links. Or end one link on its own, from the share bar.
Co-planner invite
- Who creates it
- You
- Who it is for
- A co-planner you invite
- What they see
- Nothing until they accept. Then the planning workspace for the role you gave them.
- What they never see
- Anything outside that role.
- Lives for
- 30 days to accept.
- Switching it off
- One button, in the event's Settings under Shared links. The button cancels invites nobody has accepted yet; a co-planner who already joined is removed from your team list instead.
Plan preview link
- Who creates it
- A visitor who builds a preview before making an account
- Who it is for
- That visitor
- What they see
- The preview they built.
- What they never see
- Anything else.
- Lives for
- 30 days from the day it is made.
- Switching it off
- Ends on its own — it is never attached to an event.
Guest RSVP link
- Who creates it
- Made when a guest answers your invitation
- Who it is for
- That guest
- What they see
- Their own RSVP and the event page you published.
- What they never see
- Other guests beyond what your guest-list setting shows; anything on the planning side.
- Lives for
- Used once, to sign that guest in.
- Switching it off
- Kept alive on purpose, so a guest never loses their own RSVP. You manage guests from your guest list.
Guest return record
- Who creates it
- Made when a guest answers your invitation
- Who it is for
- That guest, coming back to change their answer
- What they see
- The same as the RSVP link above — nothing more.
- What they never see
- The same as the RSVP link above.
- Lives for
- As long as that guest's RSVP link does.
- Switching it off
- A hashed record of the guest's own link. It carries its own end date and is left alone by the event-wide button, for the same reason.
Email reply link
- Who creates it
- An email Koplanit sends you
- Who it is for
- You
- What they see
- One reply, bound to one task.
- What they never see
- Anything else.
- Lives for
- One use, then it is spent.
- Switching it off
- Spent on first use, and it expires on its own.
Email action link
- Who creates it
- An email Koplanit sends you
- Who it is for
- You
- What they see
- One status change on one task, from the email.
- What they never see
- Anything else.
- Lives for
- One use, then it is spent.
- Switching it off
- Spent on first use, and it expires on its own.
Guest links stay alive by design. A guest should never lose their own RSVP because an organizer reset the plan's links.
What each person sees of others
Helpers
Helpers see the timeline items and details tagged for helpers, in a view built for that role. They do not see who is assigned to what, internal notes, or anything tagged organizers-only. They see your contact card only if you switched it on for helpers.
Vendors
Vendors see what they owe you and what they need in order to arrive and set up. Headcount and dietary needs reach them as totals, never as names, emails or phones. They see your contact card only if you switched it on for vendors.
Guests
Guests see the event page you published and their own RSVP. Whether they see other guests is your setting: hidden, a count, or names, capped at 50. Guests never receive your email or phone; a reply from a guest, a helper or a vendor reaches you through a relay that shows them nothing of yours.
Co-planners
Co-planners see the planning workspace for the role you gave them, and nothing outside it.
When the plan is read by a model
Some parts of the plan are drafted or narrated by a model. Here is each one, what it is sent, and when.
Event description draft
- What is sent
- The event's name, type, date, location and capacity.
- When
- When you ask for a description draft.
Task suggestions
- What is sent
- The event's name, type and date, and the titles of tasks you already have.
- When
- When you ask the planning assistant for task ideas.
- Needs
- The planning assistant, switched on for this deployment.
A “what to expect” note for guests
- What is sent
- The event's name and type, your dress code, whether kids are welcome, and your gift guidance.
- When
- When you ask the planning assistant to draft the note.
- Needs
- The planning assistant, switched on for this deployment.
Budget insight note
- What is sent
- The event type, and the pooled figures for that type across other events — typical RSVP, attendance and lead-time rates, and how many events they came from. None of your own budget lines, guests or names.
- When
- When you open budget insights.
Up-next narration
- What is sent
- The event's name, how many days are left, the titles of the top few actions, your guest count and your task counts.
- When
- On its own, when the event overview's “Up next” card loads.
Daily triage for the founder
- What is sent
- Error titles and paths from the last day, and the text of feedback messages people sent.
- When
- Once a day. It reaches the founder's inbox and is never shown to organizers.
Two features that ship dark
- Planning assistant
- A chat panel that drafts alongside you. It ships switched off, and its two features above are unreachable until a deployment turns it on.
- Seating suggestions
- Reading a seating request written in your own words. It ships switched off; the seating solver itself does its work without a model.
Every call above goes to Anthropic's API, to the Claude Haiku 4.5 model. Each one is limited per account and given a few seconds to answer before it is dropped. None of them carries a hidden system prompt, and nothing a model writes is ever run as code: it is shown as text, or checked against a strict shape before it is used.
Koplanit does not use your data to train any model. Anthropic states that, by default, it does not use inputs or outputs from its API to train its models.
Anthropic: is my data used for model training? (checked 4 September 2026)
On this deployment
- Model features
- Enabled
- Planning assistant
- Off
- Seating suggestions
- Off
These three come from the running deployment, not from anything typed on this page.
Your data: take it, delete it
Download everything
Settings, then Security, then Download Your Data gives you one file with your profile, settings, events, RSVPs, messages and memberships, in a standard export shape.
Delete your account
Settings, then Security, then Delete Account takes effect immediately. Nothing waits in a grace period. Your identity is removed and your contributions are anonymized: messages and task comments you wrote are replaced with a placeholder, RSVPs you made lose your name, email and phone, and tasks and timeline items you were assigned are unassigned. Events you created are kept for the people you shared them with, without your name on them.
Delete an event
It waits 30 days in Trash, where you can restore it. Then it is purged.
Downgrade
Your data is never deleted. After cancellation, your account reverts to the Free plan. Events over the limit become read-only.
Guests
There is no self-serve erase for guests yet. A guest who wants their RSVP removed can email support@koplanit.com, and it is done by hand.
Where it runs, and who else touches it
Koplanit runs on AWS in the US East (N. Virginia) region: the app on ECS Fargate, the database on RDS PostgreSQL, uploads in S3. The database takes an automatic backup every night, and a full restore drill passed on 22 July 2026.
The database is encrypted at rest, and every file you upload is stored encrypted with Amazon S3 managed keys. Your browser talks to Koplanit over HTTPS.
| Who | Why |
|---|---|
| Anthropic | The model features above. |
| AWS | Hosting, storage, secrets. |
| Stripe | Billing. Only planners pay; guests and co-planners never do. |
| Resend | Sending email. |
| Twilio | Sending text messages. A reply of STOP is honoured, and that number is never texted again. |
| PostHog, Google Analytics, Meta, TikTok | Analytics and ads measurement, only after you accept the cookie choice. Global Privacy Control is honoured. |
| Expo | Delivering push notifications to a mobile app. |
Do not sell or share my personal information
Push notifications are wired, but no app registers for them yet.
Nothing that leaves your browser for an analytics or ads provider ever contains a share link. Until you make a cookie choice, nothing is tracked.
If something breaks, and who answers
Koplanit is founder-led. Messages to support@koplanit.com are read personally and answered within two business days.
If something breaks, the previous version can be back in about ten to fifteen minutes. Automatic alarms send an email the moment error rates, crashes or slow responses cross a threshold. Logs are kept for 30 days.
What this page does not claim
- No SOC 2 report.
- No uptime guarantee.
- No breach-notification promise beyond what the law requires; counsel is contacted the same day.
- The backup retention window is not published.
- This page does not describe the connection between the app and its database.
Ready to plan something together?
Koplanit is in invite-only early access. Join the waitlist and you'll be first in line when planning opens up.
Join the waitlist