Privacy and data
Plotic is designed so the project remains yours: it works locally, exports complete .plotic projects, and can run on your own infrastructure.
Data controller
The controller is Pedro Terrero, self-employed, tax ID 74885526X, with tax address at Calle Almanzor 6, 29006 Málaga, Spain. For privacy questions and rights requests: privacy@plotic.co.
Where data is stored
In Plotic Cloud, projects, history, comments, and account data are stored on infrastructure located in Austria. Recovery backups are encrypted before leaving the server and retained in pCloud's European Union region for a maximum of 30 days.
Projects created under Local projects stay in this browser profile and are not included in Cloud backups or account exports. Clearing browser data can delete them. Export .plotic backups yourself or copy a project to Cloud if you want it synced.
Plotic does not provide end-to-end encryption: the server must process document state for sync, collaboration, history, and recovery. Internal content access is not available through a normal administration interface; exceptional assistance requires consent, purpose, and an audit record.
Services involved
- Cloudflare protects and delivers web traffic.
- Stripe processes payments, invoices, and tax information.
- Google Cloud Gemini Enterprise Agent Platform, the evolution of Vertex AI, only when you enable Plotic AI, processes the minimum context needed for an analysis in Plotic's configured European region. BYOK keys are never sent to this platform.
- Resend delivers account and invitation email, plus beta bug reports. Account and invitation emails do not contain screenplay text. A bug report contains only what you write, an optional reply address, the section you were in (editor or projects) and your browser user-agent.
- Google is involved only when you choose Google sign-in.
- Your AI provider receives only the content needed when you request an analysis. Plotic never runs background analysis.
Each provider may process data in different locations. Check its terms before enabling an integration.
Beta bug reports
Bug reports are emailed to info@plotic.co. Plotic does not attach project text, project names, screenshots or files automatically. Do not include sensitive screenplay content in your description. Cloudflare Turnstile checks submissions for abuse; Plotic temporarily limits reports from one connection.
AI and your screenplay
Plotic does not train models on your screenplay. When you configure AI with your own key, that key is encrypted on the server and never returns to the browser. Retention, training, and location for submitted data depend on the provider you select; Plotic shows the provider before analysis.
For a local project, each AI request asks for consent and sends only the context needed for that analysis through Plotic's server to the selected provider. The server keeps usage metadata, not the local screenplay or findings; findings stay in the browser. AI requires an account and connection.
Your controls
In Account → Privacy and data, you can download your data and owned projects. You can also delete your account using a code sent to your email. Deletion cancels an active subscription, deletes owned projects, and anonymises your messages in projects owned by other people. Recovery backups expire within 30 days.
Local copies stored in other browsers or devices cannot be remotely removed while those devices are offline. Clear site data on those devices if you also want to remove those copies.
Deleting a Cloud account does not delete separate browser-local projects. Delete them from Local projects or clear this site's browser data if you also want to remove them.
This policy should be reviewed by legal counsel before the final commercial launch.