Privacy Policy
Last updated: 17 April 2026 · Polara Venture Studio (OPC) Private Limited
1. Who we are
PlotUI is operated by Polara Venture Studio (OPC) Private Limited("we", "our", "us"). We provide an AI-powered in-app support widget for SaaS founders. Questions? hello@plotui.com.
2. What data we collect
From founders (dashboard users)
- Name and email address (via Clerk authentication)
- Organisation name and billing information (via Stripe)
- Repository metadata and knowledge graph nodes you create — source code is never transmitted to our servers
- Dashboard usage events (page views, feature interactions)
From your end-users (widget conversations)
- Text messages entered into the support widget
- Page URL and user role hint at the time of the query
- Anonymous session identifier (stored in
sessionStorage— not a cookie, not persistent) - We do not collect IP addresses, device fingerprints, or any identifying information from your end-users unless they type it in a message
3. How we use your data
- To operate and improve the PlotUI service
- To route unresolved queries to the correct founder support email
- To calculate usage metrics (queries per month, LLM cost per org)
- To send transactional emails (billing receipts, unresolved query notifications)
- We do not sell your data or your users' data to third parties
- We do not use conversation data to train shared AI models
4. Data retention
- Widget conversation logs are retained for 180 days and then automatically deleted
- Knowledge graph data is retained for as long as your account is active
- After account deletion, all data is purged within 30 days
5. Sub-processors
We use the following sub-processors to operate the service:
| Processor | Purpose | Location |
|---|---|---|
| Railway | Infrastructure & database hosting | US |
| Clerk | Authentication & user management | US |
| Stripe | Payment processing | US |
| Google (Gemini) | AI language model inference | US |
| Resend | Transactional email | US |
6. Your rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. To exercise these rights:
- Founders can delete their account in Dashboard → Settings → Account → Delete Account
- For end-user data deletion requests, email hello@plotui.com with the subject "Data Deletion Request"
- We will respond within 30 days
7. Cookies
The PlotUI dashboard uses cookies for authentication (set by Clerk). The widget itself uses sessionStorage only — no cookies, no cross-site tracking.
8. Security
All data is encrypted in transit (TLS 1.2+). Database backups are encrypted at rest. Widget embed tokens are signed with per-organisation HMAC secrets so role claims cannot be forged. We do not store payment card data (handled entirely by Stripe).
9. Changes to this policy
We may update this policy. Material changes will be notified by email to account holders at least 14 days before taking effect.
10. Contact
Polara Venture Studio (OPC) Private Limited · hello@plotui.com