Privacy Policy

Last updated: June 21, 2026

1. Overview

This Privacy Policy explains how Plynox (“we”, “us”) collects, uses, and protects your personal data when you use our Service. We act as the data controller for the personal data described here. We do not sell your personal data.

2. Data we collect

  • Account data: your name, email address, and, for email sign-ups, a securely hashed password (we never store passwords in plain text). If you use Google sign-in, we receive your basic Google profile (name, email, avatar).
  • Subscription & billing data: your plan, status, and renewal date. Payments are handled by Stripe; we receive billing status and a Stripe customer reference, but never your full card number.
  • Technical data: limited logs and your IP address, used for security, abuse prevention, and rate-limiting.

3. How we use your data

  • to create and operate your account and deliver the Service;
  • to process subscriptions and payments through Stripe;
  • to send essential account and security notifications (e.g. password changes);
  • to secure the Service, prevent abuse, and comply with legal obligations.

4. Legal bases (GDPR)

Where the GDPR applies, we process your data on these bases: performance of our contract with you (providing the Service and Pro features), our legitimate interests (securing and improving the Service), your consent (where requested), and compliance with legal obligations.

5. Who we share data with

We share data only with service providers that help us run the Service, under appropriate safeguards:

  • Stripe: payment processing and subscription billing;
  • Google: optional sign-in (only if you choose it);
  • Our email provider: to deliver transactional emails.

We do not sell, rent, or trade your personal data. We may disclose data if required by law or to protect our rights and users.

6. Cookies & sessions

We use strictly necessary cookies to keep you signed in and to secure authentication. We do not use third-party advertising or tracking cookies.

7. Data retention

We keep your personal data for as long as your account is active and as needed to provide the Service. We retain limited billing records where required for legal, tax, or accounting purposes. When you delete your account, we delete or anonymize your personal data, subject to those legal retention requirements.

8. Your rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data (you can edit your profile in your dashboard);
  • request deletion of your account and personal data (“right to be forgotten”);
  • data portability: receive a copy of your data in a common, machine-readable format;
  • object to or restrict certain processing, and withdraw consent;
  • lodge a complaint with your local data-protection authority.

To exercise any of these rights, email privacy@plynox.app. We respond within the timeframes required by applicable law.

9. Security

We protect your data with measures including password hashing (bcrypt), encrypted transport (HTTPS), scoped access controls, and rate-limiting. No system is perfectly secure, but we work to safeguard your information.

10. International transfers

Our providers may process data outside your country. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will update the date above and, for material changes, provide additional notice where appropriate.

13. Contact

Questions about your privacy? Email privacy@plynox.app. See also our Terms of Service.