Legal
Privacy
What Plotra stores, where it is kept, who can see it, and how to export or delete it.
Last updated 4 October 2026.
The short version
- You own your work. Using Plotra gives us no rights to what you write.
- We never train AI on your work. The project has no AI model of its own and doesn't give your text to anyone who does.
- The AI agent sends text only when someone runs it. On your own key it goes to the provider you chose. On Pro's hosted AI it goes to the model provider Plotra uses. The agent is off unless a workspace owner or admin turns it on.
- No ads, and your data is never sold. Not your writing, not your email address, not usage data. The only thing Plotra sells is the Pro plan.
- Payments go through Creem. Plotra never sees your card. It stores only ids and the state of the subscription.
- You can export your work and delete it. Reaching a limit never blocks export.
Who runs it
Plotra is built and run by Sudhan, an independent developer in India. There is no company behind it. "We" on this page means Plotra and the person who runs it. The code that runs the hosted version is the code in the public repository, so you can check what this page says against it.
Contact, for anything about your data, including a complaint: sudhan@plotra.ink. You get an answer within 30 days.
What is stored
Your account
- Your name and email address, and a profile picture if you sign in with Google.
- Your password, stored only as a hash. We can't read it.
- Your sessions: when you signed in, and the IP address and browser of each session, so a session can be told apart and ended.
Your work
- Workspaces and projects, and everything in them: notes and their text, properties, tags, links, timelines, canvases, comments, suggestions and review notes.
- Version history: the snapshots you name, and the automatic ones (the latest 40 per note).
- Files you upload or clip into a project.
Who you work with
- The members of your workspaces and their roles.
- The people each project is shared with. If you invite someone by email, their address is stored even before they have an account, so the invitation can find them.
Billing, if a workspace is on Pro
Payments are handled by Creem, the merchant of record. Creem processes and keeps the payment data: card details, billing address, invoices. Plotra stores only what it needs to know which plan a workspace is on: a Creem customer id, a subscription id, and the state of the subscription (its status, which product it is, whether it is monthly or yearly, and the dates of the current period). It also keeps the ids of the notifications Creem sent, so that none is applied twice. No card number, billing address or invoice is stored by Plotra.
For hosted AI, each agent run records how many tokens and credits it used, so the workspace's monthly allowance can be counted. That record holds numbers, not text.
Usage events
To know whether anyone uses Plotra, the app records that certain things happened: someone signed up, created a project, shared a project, invited a member, imported or exported, turned on the AI agent. An event has a name, a time, and the ids of the account, workspace and project. It never contains titles or text.
Counters
Short-lived counters for rate limits: how many sign-in attempts, invitations or uploads came from an account or address in the last while.
In your browser
- A sign-in cookie. There are no advertising or cross-site tracking cookies.
- A copy of the documents you opened, so editing keeps working if the connection drops. It stays in that browser until you clear the site's data. On a shared computer, clear it.
- Your pane layout, shortcuts and a few view settings.
This site, the one you are reading, sets no cookies and has no analytics. Everything on it, including its background videos and fonts, is served from the site itself.
Where it is kept
The hosted version runs on these services. Each one handles the data described and nothing more is sent to it.
| Service | What it does | What it holds or sees |
|---|---|---|
| Neon | The Postgres database | Your account, your workspaces and projects, the text of your notes, comments, properties and sharing settings |
| Cloudflare | The collaboration server (Workers and Durable Objects) and file storage (R2) | A working copy of each document while and after it is edited; uploaded files; version snapshots; the nightly database backups |
| Vercel | Runs the app, this site and the docs | Requests pass through it. It keeps request logs (IP address, address requested, time) for a short period |
| Resend | Sends email | The recipient's email address and the email itself: an invitation or a share notice, with the sender's name and the workspace or project name |
| Sign-in, only if you choose "Continue with Google" | Google tells us your name, email address and profile picture. We don't get access to anything else in your Google account | |
| Sentry | Error tracking | A technical report when something crashes: the error, the page, the browser. It is not meant to contain your text |
| PostHog | Usage counts | The names of events (see below) with your account's id. No content |
| Creem | Payments for Pro, as merchant of record. Only if a workspace subscribes | What you enter at checkout: your name, email address, billing address and card details. It also keeps your invoices. Plotra never receives the card details |
| The hosted AI model provider | Runs the AI agent for Pro workspaces that use hosted AI. Hosted AI is not switched on yet; the provider is named in this row before it is | The text the agent needs for a run: the notes it reads, the project's story brief and the request. Only when someone runs the agent on hosted AI |
These companies store data in their own data centres, which may be outside your country.
AI
Plotra works without AI, and the AI agent is off unless a workspace owner or admin turns it on, per workspace and per project.
- On either plan, the agent can run on your own API key for a provider you pick, or on a model running on your own computer.
- A workspace on Pro also has hosted AI, which runs on a key the project holds, so nobody needs their own. On a hosted run, the notes the agent reads are sent to the model provider Plotra uses, instead of a provider you chose. Hosted AI is not switched on yet. Before it is, this page will name the provider and say what its terms allow it to do with the text, and it will only be a provider whose terms rule out training on it. If you would rather your text went only to your own provider, add your own key: runs on your own key don't use hosted AI.
- Text leaves Plotra only when someone runs the agent, and it goes only to the provider for that run: the one that person chose, or Plotra's on a hosted run. What is sent is what the agent needs for the task: the notes it reads, the project's story brief, and your request.
- Collaborators count too. If someone who can edit your project runs the agent, the notes it reads go to their provider, under their key, or to Plotra's provider on a hosted run. If you don't want that, leave the agent switched off for the project.
- On your own key, what the provider does with the text is governed by your agreement with that provider. Read their terms, especially on training.
- Your key is stored encrypted, used only on the server for your own runs, never shown again in the browser and never shared with collaborators.
- With a model on your own computer, your browser calls it directly: what the model is sent and what it writes go between your browser and that model, not to any provider, and a key for it is kept in your browser and never sent to us. Our server still does what it does for every run: it builds the instructions, runs the agent's tools as you, and stores the conversation, the model's name and address, and the token counts.
- We never use your work to train a model. We don't have one: hosted AI runs on another company's model.
Who can see your work
- You.
- The members of the workspace a project is in, and the people you shared the project with, each within their role.
- Anyone with the link, if you turn on a project's read-only link or publish a wiki from it. Both are off until you turn them on, and can be turned off again.
- The maintainer. Your work is stored so that the server can sync it between collaborators, which means it is not end-to-end encrypted and the person running the service can technically read the database. The maintainer does not read your work, except when you ask for help with a problem and that requires looking, or when the law requires it.
We don't sell your data, and we don't share it with anyone except the services listed above, each for the job described there. If the law forced us to hand something over, we would tell you unless the law forbade that too.
Exporting and deleting
Export
You can export your work at any time, and no limit ever blocks it. The formats and where to find them are in the guide.
Delete
- A note goes to the project's trash first. "Delete forever" and "Empty trash" remove it for good.
- Comments, files, shared people and workspace members can be removed where they are listed.
- To delete a whole project, a workspace or your account, write to sudhan@plotra.ink from the email address on the account. The app has no button for these yet. The request is carried out within 30 days, and you are told when it is done.
Deleted data is gone from the live database at once. The database is backed up every night and the latest 14 backups are kept, so a copy can remain in a backup for up to 14 days. The copy in your own browser stays until you clear the site's data.
Your other rights
You can ask what is stored about you, ask for a copy of it, have something wrong corrected, or withdraw a consent you gave, for example by turning the AI agent off again. Write to sudhan@plotra.ink. These rights are yours wherever you live; the law where you live, such as India's Digital Personal Data Protection Act or the GDPR, may give you more, including the right to complain to its data protection authority.
If the hosted version ever closes
You would be told by email, with time to export, and the software stays available to run yourself.
How long things are kept
- Your account and your work: until you delete them.
- Automatic versions: the latest 40 per note. Older ones are removed as new ones are made.
- Usage events: kept as counts. They hold no content.
- Billing ids and subscription state: while the workspace exists. Creem keeps payment and invoice records for as long as tax law requires of it.
- Request logs at the hosting providers: for the short periods those providers keep them.
Security
Connections are encrypted in transit. Access to every project is checked on the server and again by the database. That is care, not a guarantee: Plotra is early software run by one person. Keep your own copy of work you can't afford to lose. If you find a security problem, please report it privately as described in the security policy.
Children
The hosted version is for people aged 18 or over. It doesn't knowingly keep an account for anyone younger. If you believe a child has signed up, write to sudhan@plotra.ink and the account will be removed.
Changes to this page
This page lives in the public repository, so every change to it is on record. If something important changes, people with an account will be told by email before it takes effect.
Questions
Write to sudhan@plotra.ink. For anything that isn't private, you can also open an issue.