Privacy Policy
Last updated: 25 August 2026
1. Who we are
PLOT is operated by Energetic Vision s. r. o., a company registered in the Slovak Republic, with its seat at Gorkého 2674/12, 902 01 Pezinok, Slovakia, IČO 57 106 266 ("we", "us"). We are the data controller for the personal data described here.
We offer the service across the European Union, beginning with Slovakia and Czechia, so the GDPR applies to everything below wherever you are.
Questions or requests about your data: team@energeticvision.sk. We do not have a Data Protection Officer, as we are not required to appoint one.
2. What we collect
| Data | Why | Legal basis |
|---|---|---|
| Email address | To create and identify your account, and to send password resets | Performance of a contract |
| Password (stored only as a bcrypt hash, never in readable form) | To let you sign in securely | Performance of a contract |
| Plan, credit balance and usage records (which feature, when, what it cost) | To apply your allowance and prevent abuse | Performance of a contract; legitimate interest in preventing abuse |
| Billing identifiers from Stripe (customer and subscription id) | To link your subscription to your account | Performance of a contract |
| IP address on sign-in and password-reset attempts | To rate-limit brute-force attacks. Deleted automatically after 24 hours | Legitimate interest in security |
| Photographs and images you upload | To generate the result you asked for | Performance of a contract |
3. What we do not keep
We do not store your photographs or the images we generate. An uploaded image is held in temporary memory and storage only for as long as it takes to process your request, sent to the AI provider named below, and then deleted. The generated result is returned straight to your browser. Neither the original nor the result is written to our database or kept on our servers.
We never see or store your card details. Payment is handled entirely by Stripe on their own pages; card data does not pass through our servers.
4. Who else processes your data
We use a small number of providers to run the service. They act as our processors:
| Provider | What they receive | Where |
|---|---|---|
| Google Ireland Ltd / Google LLC (Gemini API) and OpenAI Ireland Ltd / OpenAI, L.L.C. | The image you upload and the instruction for it, in order to generate a result | Outside the EU/EEA — see section 5 |
| Stripe | Your email and payment details, to take payment and manage your subscription | EU and USA |
| Brevo (Sendinblue SAS, France) | Your email address, to deliver password-reset messages | EU (France) |
| Websupport s.r.o. | Hosts the application and database | Slovakia |
We do not sell your personal data, and we do not use it for advertising.
5. Transfers outside the EU/EEA
Generating an image requires sending it to our AI provider, whose servers may be outside the European Economic Area, including in the United States. Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses and/or an applicable adequacy decision, as set out in that provider's data processing terms.
Please keep this in mind when uploading: only upload images you are entitled to share for this purpose. Avoid uploading photographs in which people are identifiable unless you have their agreement.
6. How long we keep things
- Account data — for as long as your account exists.
- Usage records — for as long as your account exists, then deleted with it.
- Sign-in and reset IP records — automatically deleted after 24 hours.
- Password-reset links — expire after one hour and can be used only once.
- Uploaded and generated images — not retained at all (section 3).
- Invoices and payment records — kept by Stripe and by us for as long as tax and accounting law requires (10 years for accounting records under Slovak law).
7. Your rights
Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. You can also withdraw consent where we rely on it, and complain to a supervisory authority.
Two of these are built into the app and need no request:
- Download your data — Account → Download my data gives you a JSON file of everything we hold.
- Delete your account — Account → Delete my account erases your account, usage records and security logs immediately, and cancels any active subscription. This cannot be undone.
For anything else, email team@energeticvision.sk. We will respond within one month.
Our lead supervisory authority is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR), dataprotection.gov.sk. If you live in another EU country you may complain to your own national authority instead — you do not have to come to ours.
8. Cookies
We use one strictly necessary cookie, which keeps you signed in. It is not used for tracking or advertising, and it is removed when you sign out. We store a sign-in token in your browser's local storage for the same purpose, as a fallback where cookies are blocked. We do not use analytics or advertising cookies, so no consent banner is required.
9. Security
Passwords are stored as bcrypt hashes and never in readable form. Traffic is encrypted with HTTPS. Sign-in attempts are rate-limited. Password-reset links are stored only as hashes, expire within an hour and work once. API keys and database credentials are held server-side and are never sent to your browser.
10. Children
The service is intended for business use and is not directed at anyone under 16. We do not knowingly collect data from children.
11. Changes
If we change this policy we will update the date at the top, and for significant changes we will tell you by email.