Privacy
Privacy Policy
Last updated: June 8, 2026
plotlet. ("plotlet," "we," "us," or "our") is an iOS app. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
By using plotlet. you agree to this policy.
1. What we collect
Account information. When you sign up we collect:
- Your phone number (used to send a one-time login code via SMS)
- A username and display name you choose
- An optional profile photo
- An Expo push-notification token tied to your device (so we can send you notifications)
Content you create. Anything you put into the app:
- Groups you create or join, and group chat messages
- Plans, proposals, votes, and notes you add to plans
- Availability you mark (e.g. "Saturday evening")
- Hangouts you log (date + activity type)
- Pulses (low-commitment hangout signals) and your responses to other people's pulses
Preferences. Activity preferences you select during onboarding so we can recommend things you'll like.
Technical data. Standard request metadata that Supabase (our hosting provider) keeps for security and reliability — IP address, request time, device type. We don't run our own analytics or advertising trackers.
2. What we do NOT collect
- We do not collect your contacts (this may change in a future version with explicit opt-in; we'll update this policy first)
- We do not collect your device location
- We do not collect your real-name identity beyond what you choose to share
- We do not share data with advertisers — there are no ads in plotlet.
- We do not sell your personal information
3. How we use your information
- To run the app: deliver messages, sync plans, send push notifications, show recommendations
- To improve the product: aggregate usage patterns to fix bugs and improve features. We don't tie individual content to identity for analysis
- To keep the service safe: detect and prevent spam, abuse, or fraud
We do not use your personal content to train AI models.
4. Third-party services we use
plotlet. is built on third-party platforms that act as data processors:
- Supabase — hosts our database, authentication, and storage. Your account and content data lives here.
- Expo Push Notifications — relays push notifications to your device.
- Apple Push Notification Service — delivers the push notifications to your iOS device.
- Anthropic (Claude API) — used to generate Austin event and venue recommendations. We send Anthropic search queries and aggregated venue lists, never your personal profile, group content, chat, or contacts.
- TMDB and SerpAPI — used to fetch movie metadata and showtimes. We send these services search terms (e.g. movie titles) but not personal information.
Each of these has its own privacy practices.
5. Who can see your data
- You can see all your own data.
- Members of your groups can see content you post in that group (messages, plans you create, pulses you send) and your username/display name and avatar within that group.
- The public cannot browse plotlet. — every user-created object is gated to members of the relevant group or plan.
- We can access your data when strictly necessary for support, security, or legal compliance. We do not browse user content for fun or curiosity.
6. How long we keep your data
We keep your data for as long as your account exists. When you delete your account, your profile, messages, plans, proposals, and other user-generated content are deleted within 30 days. Backup copies may persist for an additional 30 days before being purged.
7. How to delete your account
Email us at plotletsupport@gmail.com from the email tied to your account (or your registered phone) with the subject "Delete my plotlet. account." We'll delete your data within 30 days and confirm by reply.
A self-serve "Delete my account" button is on the roadmap and will be added in a future update.
8. Your rights
Depending on where you live you may have rights to:
- Request a copy of the personal information we hold about you
- Request that we correct or delete that information
- Object to or restrict certain processing
- Withdraw consent at any time
To exercise any of these rights, email plotletsupport@gmail.com.
California residents (CCPA/CPRA): you have the rights described above, plus the right not to be discriminated against for exercising them. We do not sell or share your personal information for cross-context behavioral advertising.
EU/UK residents (GDPR): our legal basis for processing your data is performance of the user agreement (running the app you signed up for) and our legitimate interest in operating and improving the service.
9. Children
plotlet. is intended for users aged 13 and older. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us personal information, email us and we will delete it.
10. Security
We use industry-standard security practices — encrypted transport (HTTPS), authenticated database access, row-level security policies that prevent users from seeing each other's private data. No system is perfectly secure; we work hard to keep yours safe.
11. Changes to this policy
When we materially change this policy, we'll update the "Last updated" date at the top and (when possible) notify you in the app. Continuing to use plotlet. after a change means you accept the updated policy.
12. Contact
Questions? Concerns? Privacy requests?
plotlet
plotletsupport@gmail.com