Plotheus
LoginRegister

Privacy Policy

Last updated: April 19, 2026

1. Who We Are

Plotheus ("we", "us", "our") is a story architecture platform that helps writers structure their narrative worlds. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services.

For the purposes of the General Data Protection Regulation (GDPR) and the UK GDPR, the data controller is the operator of Plotheus. You can reach us at privacy@plotheus.com for any privacy, data protection, or data subject request.

2. Data We Collect

2.1 Account Data

When you create an account with an email and password, we collect:

  • Email address
  • Display name (if provided)
  • Authentication credentials (securely hashed; we never store your password in plaintext)

2.2 Data From Google Sign-In

If you choose to sign in with Google, we use Google OAuth 2.0 (via our authentication provider Supabase) and request the default openid, email, and profile scopes. From your Google account we receive:

  • Your Google account unique identifier (the OpenID sub claim)
  • Your email address and whether it is verified
  • Your full name (and, where provided by Google, given name and family name)
  • Your profile picture URL, if set on your Google account
  • Your preferred locale, if provided by Google

We do not request, access, or store any additional Google data (such as Gmail, Drive, Calendar, Contacts, or YouTube data). We do not receive or store your Google password. See Section 7 below for our Limited Use disclosure.

2.3 Story & Content Data

When you use Plotheus, we store the content you create:

  • Story structures, chapters, scenes, and paragraphs
  • Object types, objects, and their field values
  • Interaction types and relationships
  • Comments, notes, and collaboration invitations you generate

2.4 Usage and Device Data

We may collect technical data to operate and improve the service:

  • IP address (used for security, abuse prevention, and approximate geolocation; not stored long-term in an identifiable form)
  • Browser type and version, operating system, device type, and screen size
  • Pages visited, features used, referring URL, and in-app events (for example, when a story is created)
  • Timestamps, session duration, and error logs
  • An anonymous analytics identifier (distinct_id) generated by PostHog and stored in your browser, used only if you accept analytics cookies

2.5 Cookies and Similar Technologies

We use strictly necessary cookies for authentication and session management, and we use your browser's local storage to remember your cookie preference and to hold an anonymous analytics identifier if you accept analytics. See our Cookie Policy for the full list.

3. How We Use Your Data

We use your personal data to:

  • Provide and maintain the Plotheus platform
  • Authenticate your identity and secure your account
  • Store and serve your story content
  • Communicate important service updates
  • Improve our service based on usage patterns (with anonymized data)
  • Comply with legal obligations

4. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation, we process your data based on:

  • Consent: When you sign up or accept analytics cookies.
  • Contract performance: To provide the service you requested.
  • Legitimate interest: To improve our services and prevent fraud.
  • Legal obligation: To comply with applicable laws.

5. Data Storage & Security

Your data is stored securely using Supabase infrastructure with encryption at rest and in transit. We implement row-level security policies to ensure users can only access their own data. Authentication is handled via industry-standard protocols.

6. Data Sharing and Sub-Processors

We do not sell your personal data, we do not share it with advertisers, and we do not use it for advertising profiling. We rely on the following service providers (sub-processors), each bound by a data processing agreement:

  • Supabase (hosted on Amazon Web Services): database, authentication, and file storage. Processes your account data, Google sign-in data, and story content. Primary region: United States.
  • Google LLC: identity provider used only when you choose "Continue with Google". Supplies the profile fields listed in Section 2.2.
  • Vercel Inc.: application hosting, edge delivery, and request logs. May process your IP address and request metadata. Primary region: United States.
  • PostHog Inc.: product analytics. Receives pageview events, in-app events, IP-derived approximate location, and the anonymous distinct_id described in Section 2.4. Only active after you accept analytics cookies. Data is hosted in the United States (us.i.posthog.com).
  • Google Fonts: used to deliver typefaces. When your browser loads a font, Google receives your IP address and user agent. Governed by Google's own privacy policy.
  • Legal authorities: we may disclose data when required by a valid legal process, to protect the rights, safety, or property of Plotheus, our users, or third parties, or to investigate abuse.

Plotheus never hosts or proxies large language model (LLM) calls. When you export a context package to an AI agent, that data leaves our platform and is governed by the AI provider's own terms and privacy policy. You are responsible for the provider you choose.

7. Google API Services Limited Use Disclosure

Plotheus's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, information obtained from Google Sign-In (as listed in Section 2.2) is used only to:

  • Create and authenticate your Plotheus account;
  • Display your name and profile picture inside the product;
  • Send you transactional service emails related to your account.

We do not sell Google user data, we do not use it for advertising, we do not transfer it to third parties except as necessary to provide and secure the service (as described in Section 6), and we do not allow humans to read it except with your explicit consent, for security and abuse investigations, or when required by law.

8. Data Retention

We retain different categories of data for different periods:

  • Account and Google sign-in data: for as long as your account is active, and deleted within 30 days of account deletion.
  • Story and content data: for as long as your account is active, and deleted within 30 days of account deletion. Backups containing the data are rotated out within 90 days.
  • Request and security logs: up to 30 days, then automatically purged.
  • Analytics events: up to 12 months in an identifier-linked form, after which they are aggregated and fully anonymised.
  • Data retained for legal reasons: kept only as long as required by applicable law.

You can request deletion of your account and associated data at any time by emailing privacy@plotheus.com.

9. Your Rights

Under the GDPR, the UK GDPR, and other applicable data protection laws, you have the right to:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Restriction: Request restriction of processing.
  • Portability: Receive your data in a structured, commonly used, machine-readable format.
  • Objection: Object to processing based on legitimate interest.
  • Withdraw consent: Withdraw any consent you have given at any time, without affecting the lawfulness of prior processing.
  • Non-discrimination: Not be subject to decisions based solely on automated processing. Plotheus does not perform automated decision-making or profiling that has legal or similarly significant effects on you.

To exercise any of these rights, contact us at privacy@plotheus.com. We will respond within the timeframes required by law (generally one month under the GDPR). If you believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection supervisory authority (for example, the Spanish AEPD, the Irish DPC, or the UK ICO), without prejudice to any other administrative or judicial remedy.

10. International Transfers

Because our infrastructure providers are based in the United States, personal data collected through Plotheus may be transferred to and processed in the United States or in other countries where our sub-processors operate. These countries may have data protection laws that differ from the laws in your country.

Where such transfers involve personal data protected by the GDPR or the UK GDPR, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), the EU-U.S. Data Privacy Framework where our sub-processors are certified, and supplementary technical measures such as encryption in transit and at rest. You can request a copy of the safeguards in place by emailing privacy@plotheus.com.

11. Security and Breach Notification

We implement industry-standard technical and organisational measures to protect your data, including encryption in transit (TLS) and at rest, row-level security in our database, hashed credentials, short-lived session tokens, and strict Content Security Policy headers. No online service can be guaranteed to be 100% secure, but if we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected users without undue delay.

12. Children's Privacy

Plotheus is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@plotheus.com and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page and, for material changes, notify you by email or through a prominent notice on the platform before the change takes effect. Continued use of the service after an update constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or about how your personal data is handled, you can reach us at:

Email: privacy@plotheus.com

For Google user data requests specifically: privacy@plotheus.com (please mention "Google data" in the subject).

Plotheus · © 2026
Privacy PolicyTerms of UseCookie Policy