Hi Austin
Yes, if Office 365 is compliant, so are iPlanner. We don't save any data.
iPlanner is a true Office 365 Add-in. It follow the scurity model set by Microsoft, hence it follow the authentication and consent model set by Microsoft. No data is saved locally or any other places. iPlanner get tasks data and display them, it is all LIVE. When you deploy the addin it is avialable on all clients the user has. Outlook for windows, MAC, Web and Outlook for IOS. When you deploy the Add-in you will not need to install or update with any local installation. An important part of Microsoft authentication and consent model is that a Global Administrator must give consent to the Office 365 organization/tenant user allowing them to use Microsoft Graph access O365 services, like Planner, SharePoint, Groups and Calendar on your tenant. This mean no one else can access these data.
The only thing we have is user information for the Add-in license management. When you open the User management in the Add-in you can see what we can see.
If you have any question please feel free to contact me.
/Alon