Legal

Privacy Policy

Last updated September 23, 2026

Plot is a personal map of the things you've started. This page explains what we collect, why, and what control you have over it. We've written it plainly rather than in dense legal language, because we'd actually like you to read it.

What we collect

When you create an account, we collect your email address and a password (handled by our authentication provider, Supabase — we never see or store your password in plain text). If you sign up with Google instead, we receive your email address from Google to create the account, but never your Google password. We generate a username and a short discriminator for you, and you always provide your own display name at signup.

As you use Plot, we store:

  • Your map — the subject areas you've added, when you added them, and their current state (active, dormant, returned, established).
  • Check-in notes — an optional, private note you can attach when you check in on something. This note is never shown to anyone else, including other users you're connected with, and is never read or analyzed by anyone but you.
  • Usage events — we log in-product events (things like adding a subject, checking in, or opening a guide) so we can understand how people actually use Plot and improve it. These are tied to your account and a session identifier, not sold or shared with advertisers.
  • Feedback you send us — if you report a bug or request a feature, we store the message and, if you're signed in, a link to your account so we can follow up if needed.

Your public map

Every Plot map has a public page at yourplotmap.com/u/[your-username] that anyone can view without an account — this is an intentional sharing feature, not a leak. It shows the subjects on your map and their current state. It does not show your check-in notes, your email address, or anything else you haven't chosen to put on your map.

Cookies

Plot uses a small number of cookies to make the product work:

  • Authentication — a session cookie set by Supabase, our authentication provider, required for signing in to function at all.
  • plot_evt_sid — an anonymous-ish identifier that groups your usage events into sessions for our own product analytics. Expires after 30 days.
  • plot_view_as_viewer — an internal preference used only by our own admin accounts; not relevant if you're a regular user, but technically a cookie that exists.

We don't use advertising or cross-site tracking cookies of any kind.

Who we share data with

We don't sell your data, and we don't share it with advertisers or data brokers. We do work with a small number of service providers to run Plot:

  • Supabase — our database, authentication, and hosting provider for all user data.
  • Vercel — hosts the application, and provides Vercel Analytics, an anonymous, aggregate page-analytics product that isn't tied to your identity.
  • Resend — sends transactional email on our behalf, such as account-related messages and the weekly digest.
  • Google — if you choose to sign in or sign up with Google, Google authenticates you and shares your email address with us to create or match your account. We don't receive or store your Google password.

How long we keep data

Usage event logs are kept indefinitely, by design — they're what let your map reflect your own real history over time, and they're used only for understanding and improving the product, never sold or handed to a third party.

You can permanently delete your account at any time from Settings. This actually deletes your account with our authentication provider and removes your profile, map, check-ins, and notes — it's real deletion, not a soft flag, and it takes effect immediately.

Your rights

You can already see all of your own data inside the product — your map is literally a visualization of it. Beyond that:

  • Access — everything Plot holds about your activity is visible in your own map and account.
  • Correction — update your display name and profile details from Settings at any time.
  • Deletion — delete your account and all associated personal data yourself, immediately, from Settings → Delete account.
  • Anything else — email us at nicholascox204@gmail.com and we'll help directly.

Children

Plot is not directed at, and we do not knowingly collect data from, children under 13. We don't currently verify age technically, but if we become aware an account belongs to a child under 13, we'll delete it. If you believe a child has created an account, please contact us at the email above.

Payments

Plot does not currently process payments, and we don't collect or store any billing or payment information. If we introduce a paid tier in the future, this policy will be updated before that happens to explain exactly what changes.

Changes to this policy

If we make a meaningful change to how Plot handles your data, we'll update this page and change the date at the top. This is a first-pass version of this policy, written ahead of public launch — if anything here seems unclear or you have questions about how your data is handled, reach out at nicholascox204@gmail.com.