Skip to main content
← BackPrivacy · GDPR Art. 13

Privacy, written in plain ink.

How Plooi handles your personal data — what we collect, why, for how long, and the rights you have over it. EU-hosted by default, GDPR-aligned by construction.

Effective 2026-06-08 · Version 2026.1

Who is responsible

The data controller for personal data processed via this site and the Plooi application is:

Plooi (registration in progress)
c/o Dominik Witzke
Germany
privacy@plooi.ai

What we collect

We only collect what we actually need to run the service:

WhereWhatWhy
Waitlist formEmail, optional role / team size / use caseSend your alpha invite when a seat opens
Sign-in (alpha)Email, password hash, OAuth identifiers (if used)Authenticate you into your workspace
Workspace dataThe notes, methods and outputs you create on the canvasRender and persist your work between sessions
Server logsTruncated IP, user agent, request path, status codeSecurity, abuse prevention, debugging — retained 30 days

We do not set advertising or behavioural-tracking cookies on this marketing site. No Google Analytics, no Meta pixel, no Hotjar. A future analytics tool — if any — will be cookieless and disclosed here first.

Hosting and EU data residency

Plooi runs on infrastructure that keeps user data inside the European Union by default.

  • Application + database: Supabase, Frankfurt (Germany) — Postgres + storage, encrypted at rest.
  • Edge functions: Deno Deploy on Supabase, EU regions only.
  • Transactional email: Resend (Dublin, Ireland) — we send the alpha invitation when your seat opens; the email address is the only personal data involved.
  • Hosting (this site): Vercel, EU edge regions. No analytics cookies are set.

AI providers (BYOK)

Plooi's canvas runs methods against your own provider keys (Bring Your Own Key) — for Google Gemini, OpenAI, or Anthropic — encrypted at rest with AES-256-GCM and held server-side. When a node runs, the prompt and any input you connected travel to the provider you chose. We do not share your prompts or outputs with any other party. You can remove a key at any time from Settings.

How long we keep things

  • Waitlist entries: until you ask us to delete them, or 24 months after the last contact, whichever comes first.
  • Account data: as long as your account exists. Account deletion erases it within 30 days.
  • Server logs: 30 days.

Your rights (Art. 15-22 GDPR)

You have the right to access your data, to request rectification of inaccurate data, to erase it, to restrict processing, to object to processing based on legitimate interests, and to receive a copy in a portable format.

Where we rely on your consent (the waitlist), you can withdraw it at any time — email us or ask us to delete your entry. Withdrawal doesn’t affect the lawfulness of processing carried out before it (Art. 7(3) GDPR).

Email privacy@plooi.ai with your request — we respond within 30 days. You can also lodge a complaint with your data-protection authority; in Germany that is usually the supervisory authority of your federal state.

Cookies

This marketing site sets no cookies beyond what the browser strictly needs to load fonts and serve assets. The authenticated Plooi app sets a session cookie (HttpOnly, Secure, SameSite=Lax) — without it, you cannot stay signed in.

Changes to this policy

When we change this policy, we bump the version above and update the "Effective" date. Material changes (new categories of data, new processors, new purposes) are announced in the app and via email at least 14 days before they take effect.