Last updated 8 October 2026
Privacy policy
This policy describes how the current version of Plot handles information. Plot is a browser-based, drag-and-drop workspace for SaaS research, product decisions, and planning.
Anonymous use and Plot accounts
You can open the Plot board without an account. Until you sign in, the current board is stored in that browser on that device. Creating an account is required for the Thinking Partner, Video Feedback, cross-device cloud saving, board-linked feedback, usage limits, and optional AI credit.
A hosted authentication and data-storage service stores account records, password credentials, sign-in sessions, account timestamps, roles, cloud board data, daily companion usage, optional AI-credit balances, purchase references, and credit-usage ledger entries. Plot does not receive your plaintext password. Regular accounts receive up to 10 Thinking Partner answers per UTC day; the configured administrator account remains unlimited.
Information you add to a board
A board can contain an idea and domain, notes, content ideas and their target networks, competitors, public app-marketplace reviews, public video comments, custom reviews, feature requests, feedback forms and responses, an ideal customer profile, positioning, checklists, uploaded images, and the layout you create. Before sign-in, Plot writes this board to local browser storage. When a new account has no cloud board, Plot transfers that device board into the account after successful authentication. If the account already has a cloud board, Plot opens the account board and preserves the anonymous device copy rather than silently overwriting either version.
Database access controls restrict cloud-board access to its owner, and an account board can be loaded on another device after sign-in. Archived custom reviews and requested features remain in the board data while hidden from the active list. Deleting a cloud board also deletes its feedback forms and responses. Do not enter secrets on a shared device.
Thinking Partner
When you ask the Thinking Partner a question, Plot sends your question and a structured text summary of the relevant board cards to the Plot server. That summary can include notes, content ideas, idea details, competitors, review and video-comment evidence, custom reviews, feature requests, ICP and positioning fields, checklists, and feedback inputs. If your question contains a public website domain, Plot may retrieve that page’s title, description, and visible text and include it as website context. The server sends this material to an AI service provider to generate a grounded response. Proposed card changes are shown for approval and are not added until you approve them.
The AI service provider may automatically cache an identical prompt prefix and report token usage and cache hits to Plot. Plot uses those measurements to deduct optional AI credit after the daily free allowance. Infrastructure and AI providers process requests under their own terms and retention practices. Do not send confidential, regulated, or sensitive personal information to the Thinking Partner.
The Thinking Partner is instructed to use only the board context supplied with the request, but generated answers can still be incomplete or wrong. Its references to board cards are review aids, not guarantees.
Research and external services
When you load video feedback, the video URL goes to the Plot server and then to a public video-data service to retrieve public video details and comments. Plot does not access private video data or sign in to your external account. Video feedback is limited to 1,000 public comments per Plot account per UTC day. Detached comments can remain in your account’s board after the original comment changes or is removed.
App search and review requests use public app-marketplace services, sometimes through Plot’s server. Domain checks send the queried name to a registration-data lookup service. Competitor logos, website favicons, public profile images, persona avatars, and the site font can load from external services. Those services may receive the requested URL, your IP address, browser details, and ordinary request metadata.
Billing integrations
Plot's billing-data cards are currently unavailable. Their endpoints are disabled while account-level authorization is being built, so shared billing data is not exposed through the public product. Plot does not initiate charges, refunds, or subscription changes.
Board-linked MVP feedback
The Feedback form card creates questions and a copyable integration prompt for another coding tool; Plot does not build or host the resulting MVP. The generated integration contains a long submit-only token tied to one board. Testers can use that token to submit a stable pseudonymous respondent identifier, answers, and timestamps, but the token cannot read the board or other responses. Submitted answers appear only to the signed-in board owner in the Feedback card. A Feedback button in the board toolbar lets a signed-in account choose to complete a one-time in-product survey; it uses the same Feedback-card mechanism. Do not use feedback questions to request passwords, credentials, sensitive personal data, or information you are not authorized to collect.
Custom reviews and feature requests are user-entered records; Plot does not verify that they are authentic or that you have permission to use them.
Purposes and legal bases
Plot uses the information described above to preserve an anonymous device board, authenticate users, save and synchronize account boards, enforce companion and video limits, perform the research or AI request you initiate, operate and secure the service, prevent abuse, and troubleshoot failures. The hosting provider may process IP addresses, request headers, timestamps, logs, and similar technical data for delivery, security, and diagnostics. The current application code does not include advertising, and Plot does not sell board content.
Where applicable law requires a legal basis, requested feature processing may be necessary to provide the service; proportionate security and operation may rely on legitimate interests. Plot must confirm the correct bases, notices, processor agreements, transfer mechanisms, and consent requirements for its final deployment.
Retention, sharing, and transfers
Account and board records remain until they are deleted, subject to necessary security, legal, fraud-prevention, refund, and billing records. Daily companion counters, credit balances, token-cost ledger entries, and card suggestions are stored by account. Payment order references may be retained to prevent duplicate credit grants and process refunds. AI, hosting, and external-service logs follow the relevant provider and deployment settings. Data may be processed outside your country depending on those providers and the final hosting configuration.
Information is shared only as needed with providers that operate account storage, hosting, requested AI responses, optional credit checkout, and the research or media feature you request, plus providers of logos, favicons, avatars, fonts, and registration lookups. Their own notices govern their processing.
Your controls and rights
You can remove cards, export the visible board as PNG, clear browser site data to remove an anonymous device board, sign out, or delete an account board. Clearing browser storage before an anonymous board has been transferred to an account can permanently remove that local copy. You may contact Plot at support@plotwork.space to request account deletion or exercise access, correction, deletion, objection, restriction, portability, or complaint rights that apply where you live.
Children, security, and changes
Plot is intended for adults building products, not children. Account profile access is protected with authentication and database row-level security, but no online service is completely secure. Use non-production or minimized data for integrations that do not yet have account-level isolation. We may update this policy when features or data handling change, and the latest revision date appears above.