← back to deskplot
Draft. This is a working draft. Production version posted before public launch with paid subscriptions or App Store distribution.

Privacy

Effective: 2026-05-30 · Operator: deskplot, a sole proprietorship

The short version. The local editor works offline and stores nothing on our servers. If you make an account: we store your email, username, a hash of your password, and your devices. If you subscribe: Paddle handles payment; we receive only your subscription status. We don't run analytics, don't track you, don't sell or share data, and don't read your synced content.
  1. What we collect
  2. How we use it
  3. Lawful bases (GDPR/UK)
  4. Who we share data with
  5. Sub-processors
  6. International transfers
  7. How long we keep data
  8. Your rights
  9. US state-specific rights
  10. Information for minors
  11. Cookies and tracking
  12. Automated decision-making
  13. Security
  14. Changes
  15. Contact

1. What we collect

Summary. Three buckets: what you give us, what we observe automatically when you sign in, and what we receive from third parties.

From you

Automatically

From third parties

2. How we use it

Summary. Run your account, secure it, fulfill your subscription, and respond to legal obligations. Nothing else.

We do not use your data to train AI models. We do not sell, rent, or trade your data with anyone for their own purposes. We do not place advertising. We do not send marketing emails. If we ever start sending marketing, you'll be asked to opt in first.

3. Lawful bases (GDPR / UK GDPR)

4. Who we share data with

Only the sub-processors listed below, only for the purposes stated. We disclose data outside that list only when required by valid legal process (and we'll notify you unless legally prohibited from doing so).

5. Sub-processors

Summary. Five vendors handle data on our behalf. None of them use your data for their own purposes.
Sub-processorPurposeWhere
Cloudflare, Inc.Hosting, CDN, DDoS protection, Workers + D1 storageGlobal (incl. US, EU)
Paddle.com Market LtdMerchant of Record, payment processing, tax remittanceUK / EU / US
Resend, Inc.Transactional email deliveryUS
Apple Inc.iOS in-app subscription billing, when you purchase via App StoreUS
Have I Been PwnedPassword breach checking via k-anonymity (no data about you sent)UK / global CDN

6. International transfers

Cloudflare, Paddle, Resend, and Apple operate globally; data may be processed in the United States, EU, and elsewhere. Where personal data leaves the EU/UK, transfers are covered by Standard Contractual Clauses or equivalent safeguards with each sub-processor. You can request a copy of the SCCs we rely on.

7. How long we keep data

DataRetention
Account profileWhile active, plus 30 days after deletion for recovery
Synced contentUntil you delete it or close your account
Authentication audit log12 months
Billing records7 years (tax law)
Magic link tokensUp to 1 hour, then deleted
Session tokens (hashed)Up to 30 days from last use

8. Your rights

Regardless of where you live, you can:

EU/UK residents additionally have rights to restrict processing, data portability, withdraw consent (where applicable), and complain to a supervisory authority. To exercise any of these, write to privacy@deskplot.com. We respond within 30 days at the latest.

9. US state-specific rights

Summary. CCPA/CPRA, Colorado, Connecticut, Virginia, Nevada — same core rights, same way to exercise them.

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Nevada, and other US states with comprehensive privacy laws have rights to know, access, correct, delete, and (where applicable) opt out of "sales" or "sharing" of personal information.

We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA, Colorado CPA, or similar laws. There is therefore no "Do Not Sell or Share" toggle to operate. We do not process sensitive personal information beyond what's listed in section 1.

To exercise California rights, email privacy@deskplot.com or write to the postal address in section 15. We provide two methods on request. We don't discriminate against users who exercise these rights.

10. Information for minors

deskplot is not directed at children under 13 (United States) or under 16 (most EU member states; some require 13). We do not knowingly collect personal data from anyone in that bracket. If you believe a child has provided personal data, write to privacy@deskplot.com and we will delete it and the associated account.

11. Cookies and tracking

The marketing site (deskplot.com) sets no cookies. The desktop and mobile apps store an opaque session token in the OS keychain — this is not a cookie, never leaves your device except to be sent in the Authorization header on our API calls.

Should we ever introduce cookies (e.g., for an authenticated web client), they will be strictly necessary, first-party only, and disclosed in an updated version of this page. We do not honor or override "Do Not Track" or Global Privacy Control because we don't engage in the tracking those signals were designed to suppress.

12. Automated decision-making

We do not perform automated decision-making or profiling with legal or similarly significant effects under GDPR Article 22 or analogous laws. We use automated rate-limiting and abuse-detection systems, but their decisions are reviewable by a human and don't determine your access to legal rights or services on their own.

13. Security

Passwords are hashed with a modern memory-hard function using current OWASP-recommended parameters. Sessions use opaque random tokens stored only as their SHA-256 hash. Card data never reaches our servers. Webhook payloads are signed and replay-protected. We use TLS 1.2+ for all traffic. We follow OWASP guidance and write an audit log on every authentication event.

If you discover a security vulnerability, please report it to security@deskplot.com. We don't currently run a paid bug bounty but we acknowledge meaningful reports.

14. Changes

If we make material changes, we'll notify you by email and post a notice on this page at least 14 days before they take effect. Continued use after that date counts as acceptance.

15. Contact

Privacy questions or rights requests: privacy@deskplot.com

Postal address: [postal address to be added before launch]