Plott
Legal

Privacy policy

Last updated 6 October 2026 · version 2

Plott is used by two kinds of people: studios, who create an account and run their projects in Plott, and clients, who open the private link a studio sends them. This policy explains what we collect from each, why, and what you can ask us to do with it. We do not run advertising and we do not sell personal data. We use one analytics service, PostHog, on our website and in the studio dashboard. Outside India it runs only if you accept it. It never runs on the pages clients open.

Who we are

Plott is owned and operated by Yash Jaysukhbhai Sanathara, an individual based in India. For anything in this policy — a question, a request to see or delete your data, or a complaint — contact:

What we collect from studios

  • Your account: your name, your email address, your phone number if you give one, and your password. We never store the password itself — only a one-way bcrypt hash of it.
  • Your studio: its name, address, phone number and type of work, and the details you choose to show clients, such as a tagline, contact email, phone number and social links.
  • Your team: the email addresses of the people you invite, the role you give each of them, and what each role is allowed to do.
  • Your projects: project names, web addresses, addresses and stages, watermark and project-code settings, email preferences and your time zone.
  • The people you add: the names, roles, email addresses and phone numbers you enter for your clients and contacts.
  • Enquiries: for each enquiry you record — the person’s name, phone number, email address, the kind of project, its location and budget, where the enquiry came from, and your notes on it.
  • Tasks: the tasks, comments and files your team adds.
  • What you write to clients: your notes and replies, shown with the name of the person who wrote them.
  • Quotes and invoices you make for your clients: the client’s name, address and GSTIN, the line items and amounts, and the details you put on your own bills — legal name, GSTIN, PAN, address, logo, bank account and UPI ID. Plott only records these. It never takes or holds payments between you and your clients.
  • Documents for signing: the PDFs you upload and the names and email addresses of the people you ask to sign them.
  • Your Plott subscription: your plan, the billing name, address and GSTIN you give us, and the invoices we issue to you. Payments are handled by Cashfree. We receive a payment reference, the payment method used (for example UPI or card) and whether it succeeded. We never see or store card numbers or bank account details.
  • Agreeing to our terms: when you accept the terms of service and this policy, we record the version, the time, your IP address and your browser.
  • Password resets: if you ask to reset your password, we email you a six-digit code. We store only a one-way hash of it, and it stops working after ten minutes.
  • Demo requests: if you ask for a demo on our website — your name, email address, studio, city, team size and the time you picked.

Your files and Google Drive

Plott works from a Google Drive folder you share with our service account. That access is read-only: Plott cannot rename, move, edit or delete anything in your Drive.

We store information about your Drive files — names, folder paths, Drive file IDs, sizes, modification dates, page counts, and the sheet numbers and revisions read from file names. We do not keep permanent copies of the Drive files themselves.

To make pages load quickly, we keep resized preview images, watermarked when the studio has turned watermarks on, for up to seven days, after which they are deleted automatically. They are private: each one is reachable only through a link that expires within two hours. When a studio downloads an original, it is streamed from Drive rather than stored.

Files you upload to Plott directly are different: documents for signing, signed copies, files attached to tasks, your logo, and the PDFs of your quotes and invoices are stored by us for as long as your account is open.

To stop Plott reading a folder, remove our service account from the folder’s sharing settings in Google Drive.

Analytics

To understand how people find Plott and where the product is hard to use, our website and the studio dashboard use PostHog. If you visit from India, it is on from your first visit. Anywhere else, we ask the first time you visit: if you decline, or do not answer, PostHog is not loaded and nothing is recorded. When it is on, it records:

  • Visits: the pages you open, the site or link that brought you here, your browser and device type, and your approximate location (country and city) worked out from your IP address.
  • What you use: clicks, and actions such as creating a project, sending a document for signing or starting a payment. We record that the action happened, not what the project or document contains.
  • Who you are, once signed in: your name, email address and role in the studio, so we can tell one studio’s use from another’s.
  • Errors: technical details when a page fails, so we can fix it.
  • Screen recordings, on our website only: a replay of how a page was used — mouse movement, clicks, scrolling and what was on the screen at the time. What you type into forms is hidden from these recordings. Recording stops when you sign in: nothing in the studio dashboard is ever recorded this way.

PostHog does not run on client links, on the page where a document is signed, or on email preference pages.

You can turn analytics off at any time, wherever you are: turn analytics off. To be asked again, clear the cookies for plott.work in your browser.

What we collect from clients

When you open a link a studio has sent you, we record:

  • Who you are to the studio: the name, and the email address and phone number if the studio added them, that the studio invited you with.
  • Signing in: a link we email you signs you in for 14 days. After that, or on a new device, we email you a six-digit code. We store only a one-way hash of it, and it stops working after ten minutes.
  • What you write: your notes and replies, and the spot on the image or page you pinned them to.
  • What you approve: if a studio asks you to approve a drawing — your name and email address, the exact version of the file you approved, the time, your IP address and your browser.
  • What you sign: if a studio asks you to sign a document — your name and email address, your signature as you typed or drew it, when you opened and signed it, your IP address and your browser. These are kept with the signed copy as a record of the signing.
  • When you visited: when you first and last opened the link, and which files you opened full size. The studio can see this, so they know whether you have seen their latest work.
  • Your email choices: which notification emails you have unsubscribed from.

If a studio has opened a project to anyone who has its code, you can look at it as a guest. A guest gives no name and cannot leave notes.

The studio decides what to share with you and who else is invited. Unless the studio has turned this off, the other people invited to the same project can see your notes, with your name, and you can see theirs.

We do not run analytics on the pages you open as a client. If you have also visited plott.work yourself, the analytics cookie from that visit stays in your browser, but nothing is recorded or sent to PostHog from a client link.

Cookies

Plott sets seven cookies. Three are needed to sign in, two remember a choice you made, one notes the country you are visiting from, and one is for analytics on our website and the studio dashboard. None are used for advertising.

CookieWhat it doesLasts
plott_sessionKeeps a studio signed in to its dashboard.30 days
plott_client_…Keeps a client signed in to a project they were invited to, so their notes stay theirs.7, 30 or 90 days, as the studio chooses
plott_guest_…Remembers that a guest has entered the code for a project that is open to anyone with its code.7, 30 or 90 days, as the studio chooses
plott-sideRemembers whether the dashboard’s side menu is open or folded.1 year
plott_consentRemembers whether you accepted or declined analytics, so we ask only once.1 year
plott_countryHolds the two-letter code of the country you are visiting from, so we know whether to ask about analytics.Until you close your browser
ph_…_posthogSet when analytics is on. Tells PostHog that two visits came from the same browser, on plott.work and the studio dashboard.1 year

The dashboard also keeps two small preferences in your browser’s own storage — the page to go back to and how your file list is laid out — and PostHog keeps a copy of its cookie there. These never leave your browser except as described under Analytics.

How we use it

  • To show a studio’s work to the clients it has chosen, and collect their feedback, approvals and signatures.
  • To run the studio’s tasks, enquiries, quotes and invoices.
  • To send the notification, reminder and digest emails each person has chosen to receive.
  • To charge for Plott and issue invoices.
  • To send studios, and people who asked for a demo, occasional emails about Plott. Every one has an unsubscribe link. Clients of studios never receive these.
  • To understand how the website and dashboard are used, and improve them, when analytics is on.
  • To keep accounts and private links secure, and to prevent abuse.
  • To answer support requests and fix problems.

Who else handles it

We use a small number of service providers to run Plott. They process data only on our behalf and only to provide their service:

  • Google — read-only access to the Drive folders studios share with us.
  • Cloudflare — hosting for the Plott website and application, our database, live notifications, and storage of preview images and uploaded files.
  • Resend — delivery of our emails.
  • Cashfree — payments for Plott subscriptions. Cashfree receives the name, email address and phone number of the person paying.
  • PostHog — analytics for our website and the studio dashboard, stored in the United States.

We do not sell personal data or share it with anyone for their own marketing. We will disclose information only if the law requires it.

How long we keep it

Account and project information is kept for as long as the studio’s account is open.

When a studio deletes a project, it disappears from the dashboard and its link stops working straight away. Its records — including clients’ notes — are retained so that an accidental deletion can be reversed. To have a project or an account erased permanently, write to hello@plott.work.

Cached preview images are deleted within seven days of being made. Sign-in links for clients stop working after 14 days, signing links after 30 days, and team invitations after 7 days.

Invoices we issue for Plott subscriptions, and records of approvals and signatures, are kept as business records even after a project is deleted.

Your choices and rights

You can ask us to:

  • tell you what information we hold about you and give you a copy of it;
  • correct information that is wrong;
  • delete your information; or
  • stop sending you emails — every email we send also has an unsubscribe link.

Write to hello@plott.work. We may need to confirm who you are first, and we aim to reply within 30 days. If you are a client and your request is about a particular studio’s project, you can also ask that studio directly.

Security

  • Passwords are stored only as one-way hashes, and resetting a password signs the account out on every other device.
  • Sign-in, password-reset, sign-in code and project-code attempts are limited per IP address. To count them we store only one-way hashes of the address and email, never the address itself, and the counts are deleted after a day.
  • Traffic to Plott is encrypted. The cookies that sign you in are signed and cannot be read by page scripts.
  • Only the people a studio has added to a project can sign in to its link, unless the studio opens the project to anyone with its code.
  • Our database has no public address. Only the Plott application reads it.

Children

Plott is a tool for businesses and is not intended for anyone under 18.

Changes to this policy

If we change how we handle personal data, we will update this page and the date at the top. For significant changes we will also tell studios by email before they take effect. Read this alongside our terms of service.

Contact

Questions, requests or complaints about your data go to the person responsible for it: