← Back to the app

Privacy Policy

Last updated: 25 August 2026

1. Who we are

PLOT is operated by Energetic Vision s. r. o., a company registered in the Slovak Republic, with its seat at Gorkého 2674/12, 902 01 Pezinok, Slovakia, IČO 57 106 266 ("we", "us"). We are the data controller for the personal data described here.

We offer the service across the European Union, beginning with Slovakia and Czechia, so the GDPR applies to everything below wherever you are.

Questions or requests about your data: team@energeticvision.sk. We do not have a Data Protection Officer, as we are not required to appoint one.

2. What we collect

DataWhyLegal basis
Email addressTo create and identify your account, and to send password resetsPerformance of a contract
Password (stored only as a bcrypt hash, never in readable form)To let you sign in securelyPerformance of a contract
Plan, credit balance and usage records (which feature, when, what it cost)To apply your allowance and prevent abusePerformance of a contract; legitimate interest in preventing abuse
Billing identifiers from Stripe (customer and subscription id)To link your subscription to your accountPerformance of a contract
IP address on sign-in and password-reset attemptsTo rate-limit brute-force attacks. Deleted automatically after 24 hoursLegitimate interest in security
Photographs and images you uploadTo generate the result you asked forPerformance of a contract

3. What we do not keep

We do not store your photographs or the images we generate. An uploaded image is held in temporary memory and storage only for as long as it takes to process your request, sent to the AI provider named below, and then deleted. The generated result is returned straight to your browser. Neither the original nor the result is written to our database or kept on our servers.

We never see or store your card details. Payment is handled entirely by Stripe on their own pages; card data does not pass through our servers.

4. Who else processes your data

We use a small number of providers to run the service. They act as our processors:

ProviderWhat they receiveWhere
Google Ireland Ltd / Google LLC (Gemini API) and OpenAI Ireland Ltd / OpenAI, L.L.C.The image you upload and the instruction for it, in order to generate a resultOutside the EU/EEA — see section 5
StripeYour email and payment details, to take payment and manage your subscriptionEU and USA
Brevo (Sendinblue SAS, France)Your email address, to deliver password-reset messagesEU (France)
Websupport s.r.o.Hosts the application and databaseSlovakia

We do not sell your personal data, and we do not use it for advertising.

5. Transfers outside the EU/EEA

Generating an image requires sending it to our AI provider, whose servers may be outside the European Economic Area, including in the United States. Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses and/or an applicable adequacy decision, as set out in that provider's data processing terms.

Please keep this in mind when uploading: only upload images you are entitled to share for this purpose. Avoid uploading photographs in which people are identifiable unless you have their agreement.

6. How long we keep things

7. Your rights

Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. You can also withdraw consent where we rely on it, and complain to a supervisory authority.

Two of these are built into the app and need no request:

For anything else, email team@energeticvision.sk. We will respond within one month.

Our lead supervisory authority is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR), dataprotection.gov.sk. If you live in another EU country you may complain to your own national authority instead — you do not have to come to ours.

8. Cookies

We use one strictly necessary cookie, which keeps you signed in. It is not used for tracking or advertising, and it is removed when you sign out. We store a sign-in token in your browser's local storage for the same purpose, as a fallback where cookies are blocked. We do not use analytics or advertising cookies, so no consent banner is required.

9. Security

Passwords are stored as bcrypt hashes and never in readable form. Traffic is encrypted with HTTPS. Sign-in attempts are rate-limited. Password-reset links are stored only as hashes, expire within an hour and work once. API keys and database credentials are held server-side and are never sent to your browser.

10. Children

The service is intended for business use and is not directed at anyone under 16. We do not knowingly collect data from children.

11. Changes

If we change this policy we will update the date at the top, and for significant changes we will tell you by email.