Privacy Policy
Effective August 24, 2026 · Last updated August 24, 2026
If and when these features are approved and enabled, optional contributions use a 0% PicPlots platform fee on web, iOS, and Android. PicPlots sends 100% of the displayed amount to the recipient's Stripe connected account and absorbs standard processing fees. An approved resale uses a 10% PicPlots platform fee wherever it is legally completed. These rules do not mean either feature is currently available.
What we store
- Account and profile information: your email address, account identifier, username, optional display name, personal board title, title color, selected theme, founding/verification status, sign-in records, and authentication status. If you choose Google, Apple, or Facebook sign-in, the provider may give Supabase and PicPlots a provider-scoped account identifier, email address, email-verification status, and basic profile details you approved. Apple may give PicPlots a private relay email instead of your personal address. PicPlots does not request access to your posts, contacts, friends, or social feed. Your personal board title, title color, and selected theme are private account viewing preferences. They are not included in public profile responses.
- Your dream post: the photo you upload, optional short description, optional secure link, label, selected plot or Featured Top 12 rank, placement history, private engagement count, and moderation status. Active dream post content is publicly visible on the board and profile pages, so do not submit anything you do not want made public. Engagement counts are not publicly displayed in the current release.
- Purchase records: for website purchases, Stripe customer, subscription, payment, receipt, and billing-status identifiers. For a Google Play subscription, we store the account-bound purchase intent, selected product and placement, a one-way lifecycle identifier derived from the Play purchase token, and the entitlement and lifecycle status. The server processes the Play purchase token to validate the purchase with Google, acknowledge it, prevent duplicate fulfillment, and reconcile later provider updates. For some refund or revocation notices, it also processes a Play order identifier to confirm that the notice applies to the current purchase.
- Conditional contribution and resale records: if and when PicPlots enables either feature after the required approvals, we may store the contributor, recipient, buyer, seller, placement, amount, displayed fee split, consent, Stripe connected-account reference, payment and payout status, refund or dispute status, and fraud-review records needed to process and protect the transaction. The current production release does not collect these records from a live contribution or resale flow because those features are disabled.
- Board activity: plot views, sharing activity, notifications, and the records needed to reserve and operate a paid dream post.
- Safety and support: reports, blocks, moderation decisions and queued reviews, support messages, and records needed to investigate nudity or sexual content, illegal or dangerous content, abuse, fraud, copyright complaints, or service failures.
- Technical information: basic request, device, browser, IP-address, and error information that our hosting, authentication, storage, and payment providers may process to deliver and secure the service.
What we never see
Website payments are processed by Stripe, and eligible Android subscription payments are processed by Google Play. If optional contributions or approved web resale become available, Stripe also processes the payment and connected-account payout. Your full card number and payment-account credentials go to the provider, not to PicPlots. Google, Apple, and Facebook passwords also go only to the provider. PicPlots never receives them. The app and server receive only the account or transaction information needed to operate and protect the applicable feature.
On your device
PicPlots uses local storage for privacy choices, other preferences, draft photos, pending-checkout recovery, a local copy of your recent dream posts, and an offline cache of account appearance settings. The app always starts with the default appearance and applies a personal board title, title color, or theme only after it confirms the signed-in account. Those settings are saved to your PicPlots account so they follow you across devices. Clearing browser or app data removes local copies. It does not cancel a subscription, erase synced account settings, or automatically delete server records.
Anonymous usage statistics
PicPlots collects anonymous usage statistics and crash reports, subject to your choice below. Sharing is on by default with disclosure for most visitors; visitors we detect as likely to be in the EU or UK (from the browser's time zone, checked on your device with no network request) are asked first, and nothing is sent unless they agree. Your choice stays on your device. You can opt out at any time from Privacy choices on the PicPlots app bar or website footer, and opting out stops collection immediately. Global Privacy Control or Do Not Track always overrides any saved choice and keeps both usage statistics and crash reports off.
Usage statistics are limited to a fixed event name, one coarse approved category, web/iOS/Android/desktop surface, a coarse operating-system tag and device family, your major.minor app release, and a new one-time event UUID. When someone follows one of NIRO's three disclosed business dream links on the board, the event can include only the fixed business identifier for DeNiro Card, GAIC, or SkyWrite. It does not include an arbitrary user link. A coarse country is derived on our server from your connection and is never sent by the app. Crash reports are capped to a few per visit and carry only the error type, a length-limited message and stack with website links and email addresses removed, and the same coarse fields. Nothing includes dream photos or descriptions, arbitrary user links or page addresses, plot coordinates or Featured Top 12 ranks, report text, account information, Stripe or Google Play purchase information, precise location, or persistent device or session identifiers.
How information is used and shared
- We use information to authenticate users, publish profiles and dream posts, privately measure engagement for service improvement and abuse controls, reserve and display plots, process and reconcile subscriptions, moderate content, prevent abuse, and answer support requests. If contributions or resale are later enabled, we also use the conditional records described above to verify recipients and sellers, disclose and settle the payment split, manage payouts, investigate fraud, and handle refunds and disputes. View counts and view notifications are not displayed in the current release.
- We share information with service providers only as needed to run PicPlots, including Stripe for website payments and any later approved contribution, connected-account, payout, or resale flow; Google Play for eligible Android subscription validation and lifecycle management; Supabase for authentication, database, and file storage; and Google, Apple, or Facebook when you choose that provider to authenticate. Each sign-in provider also processes the sign-in under its own privacy policy.
- We may disclose information when required by law, to protect users or the service, or as part of a business transfer. We do not sell or rent personal information.
Retention and your choices
We keep active account, profile, placement, notification, and moderation data while needed to provide PicPlots. PicPlots does not store a raw IP address in its report, security-event, or application rate-limit tables. The server converts request attributes into separate, keyed pseudonymous values for abuse prevention. A rate-limit value is no longer used after its window ends, which is never longer than 24 hours. A signed-out report's pseudonymous deduplication value is no longer used after its window ends, which is never longer than 30 days. Scheduled and request-time cleanup delete expired limiter rows and replace expired report keys with report-specific values that cannot link the report to later requests. A temporary service or scheduler interruption may delay that physical cleanup, but expired values remain ineligible for rate limiting or report deduplication. Notification history and the report reason and placement may remain where reasonably necessary for safety, disputes, or legal obligations. Hosting and security providers may keep their own limited request logs under their policies.
Payment, fraud-prevention, dispute, tax, backup, and legal records may be retained longer where reasonably necessary or legally required. You can cancel direct website billing or delete your PicPlots account and public content through Manage Account. Google Play subscriptions are managed through Google Play. If you used Sign in with Apple, PicPlots deletes the account even when PicPlots does not hold an Apple access or refresh token. In that case PicPlots directs you to finish revoking access in Apple Account settings under Sign-In & Security, Sign in with Apple. You may also email us to request access or correction; we may need to verify your identity and may retain records the law allows or requires.
Children
PicPlots is not directed to children under 13. If you are under 13, do not create an account or submit personal information or content. Purchasing a plot is an adult activity. You must be at least 18 years old, or the age of legal majority where you live, to purchase any Regular Plot or Featured Top 12 position. If you believe a child under 13 provided personal information to PicPlots, email us so we can investigate and delete information we control where required, subject to identity verification and any legal retention obligation.
Questions
Send privacy questions or requests to support via the Contact page. Subscription cancellation and refund eligibility are covered by the refund policy.