Privacy Policy for The Plot
Last updated: 7 August 2026
1. Introduction
This Privacy Policy ("Policy") explains how ThePlot LTD ("Company," "we," "us," or "our") collects, uses, stores, and protects your personal data when you use The Plot mobile application ("App"). It also explains your rights and the choices you have. By creating an account or using the App, you confirm you have read and understood this Policy. Where we rely on your consent for a particular use of your data, we ask for that consent separately and you can withdraw it at any time (see Section 7).
2. Who we are and how to reach us
- Data controller: ThePlot LTD, United Kingdom.
- Contact for privacy questions and data requests: info@theplot.world
- You have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EU, you may also contact your local data protection authority.
3. The data we collect
a. Account and profile information
- Email address, to create your account, verify it, sign you in, and send you essential service messages.
- Password, only if you choose to sign in with an email and password. It is handled by Firebase Authentication and stored in a securely hashed form; we never see or store your password in plain text. If you sign in with a passkey, Apple, or Google instead, we do not hold a password for you at all.
- Name and username, to identify your account and for social features.
- Date of birth, collected at sign-up to confirm you are old enough to use the App. You must be 16 or older.
- Country, selected at sign-up, used to tailor content and search to your region.
- Profile details you choose to add: profile photo, pronouns, a short bio (up to 500 characters), and one "favourite place" to highlight on your profile.
- A "home" location, if you set one, used for your travel passport. You can set it by searching for a place or, if you allow it, from your device location, and you can change or remove it.
- Consent and acceptance records: which version of these Terms and this Policy you accepted, when, and the data-sharing settings you have chosen.
b. How you sign in
The App supports several ways to sign in: email and password, a passkey (a secure sign-in tied to your device that uses your fingerprint, face, or device passcode), Sign in with Apple, and Sign in with Google. If you use Face ID, Touch ID, a fingerprint, or a passkey, the biometric check happens on your own device. Your fingerprint or face data never leaves your device and is never sent to us or stored on our servers.
c. Content you create
- Photos you take or upload for your posts and profile.
- Places you select for a post, including the underlying place identifier from Google Places.
- Written notes, ratings, and vibe tags you add to a post.
- Voice notes you record about a place (see Section 4, these get special handling).
- Trips you build from your posts, and the "passport" and country "stamps" built up from where you have posted.
- Social activity: who you follow, your followers and follow requests, posts you like, comments and replies you write, posts you save, and users you block.
Your account is private by default. You control who can see your content through your privacy settings.
d. Information we work out from your content
From the text of your voice notes and from your posts, our systems (including AI, see Section 5) work out useful information about places: what a place is like, what it is good and bad at, vibe words, and search terms that would help someone find it. This is used to build honest, shared travel information. Where you have turned on personalisation (Section 7), we may also work out things about your travel taste to tailor your recommendations.
e. Activity signals (only if you turn on personalisation)
If, and only if, you turn on "personalise my recommendations," we log some of what you do in the App (the places and searches you make, items you save, comments, follows, and likes, and posts or profiles you open) to learn your travel taste and improve what we suggest to you. If this setting is off, we do not log these signals. It is off unless you turn it on. You can see, and delete, what we have logged (Section 7).
f. Technical and device information (collected automatically)
- Device and app information (device model, operating system, app version).
- IP address and approximate location derived from it, for security and abuse prevention, not to track your movements.
- Diagnostics, performance data, and crash reports.
- Usage and event analytics, so we can improve the App.
- Timestamps and account-creation metadata.
We use Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, and Firebase App Check for these purposes. See Section 6 for the third parties involved.
g. Information about other people
If your content mentions, tags, or describes other people (including people who do not use the App), your content may include their personal information. You are responsible for what you share about others and should have a fair reason to do so. See Section 8.
4. Voice notes (special handling)
Voice notes are a core part of the App, so we want to be very clear about how they work.
- We record and keep your voice recordings. When you record a voice note about a place, the audio is uploaded and stored with your account so that you (and people you share the post with) can play it back on the post. It is your own content.
- We turn your voice note into text (a transcript). Transcription is done using Google's Speech-to-Text service, and this processing takes place on servers located in the European Union.
- An AI reads the transcript to work out useful information about the place you are talking about (see Section 5). This uses Claude, an AI model run inside Google Cloud. Your transcript is processed to produce vibe words and search terms; it is not used to train third-party AI models.
- We never create a "voiceprint" and never try to identify you by your voice. We do not do speaker identification or voice recognition of any kind. The transcription process only turns spoken words into text.
- Your recordings are deleted when you delete the post, or when you delete your account. We keep them only for as long as the post exists.
- Transcripts may occasionally contain sensitive information, for example if you happen to mention something about your health, beliefs, or personal life while talking. We do not seek this out, but because it can happen, we store transcripts securely and with restricted access.
5. Artificial intelligence (AI) in the App
Parts of the App use AI to turn what people say and post into useful travel information:
- Understanding voice notes: as described in Section 4, an AI model (Claude, run inside Google Cloud) reads the text of your voice note to derive vibe words and search terms about a place.
- Photo framing: when you set a cover photo, the App uses on-device image analysis to work out the best point to centre the photo on. This runs entirely on your device, makes no internet calls, and is not used to identify anyone. It is only used to frame the picture nicely.
AI-derived information about places is treated as a helpful signal, not as hard fact. We do not present an AI guess as a definitive statement.
6. Data sharing and third-party services
We do not sell, rent, or trade your personal information. We do share data with the service providers that make the App work, and only as needed to provide the service:
- Google Firebase and Google Cloud, for hosting, sign-in, database, file and photo storage, cloud functions, push notifications, analytics, crash reporting, performance monitoring, and app security. Also used for voice transcription (Google Speech-to-Text) and AI processing of transcripts (Claude via Google Cloud Vertex AI).
- Google Maps, Google Places, and Google Geocoding, to show maps, let you search for places, and turn coordinates into a place name.
- Mapbox, to display interactive maps.
- Apple and Google, if you choose to sign in with Apple or Google.
- Branch, to power deep links and shared links, which may involve processing limited device and link information.
- Other apps you choose to share to: if you share content to another app, that app's own privacy policy applies to what you share.
We may also disclose data where the law requires it, to protect the safety, rights, or property of our users or the public, or in connection with a business transfer (Section 18).
7. Your privacy controls and consent
The core App works fully with all optional data-sharing switched off. You are in control:
- Account privacy: your account is private by default; you choose who can see your content.
- Contribute to the shared place database: you can choose whether the information derived from your posts and voice notes helps build our pooled, anonymised information about places (about the places, not about you). You can change this in settings.
- Personalise my recommendations: a separate, opt-in setting that is off by default. When on, we log the activity signals in Section 3e to tailor your recommendations. When off, we do not log them.
- "What we know about you": a screen in the App where you can see the signals we have logged about you and delete them.
- Notification preferences: you choose which push notifications you receive (follows, likes, comments, follow requests, new trips).
- Device permissions: you can grant or withdraw camera, photo library, microphone, and location permissions at any time in your device settings (Section 15).
8. Information about other people
If your content names, tags, or describes other people, including people who do not use the App, you are responsible for what you share and confirm you have a fair basis to share it. If someone who does not use the App contacts us about their information appearing in content, we will handle their data-protection rights as required by law.
9. Purpose and lawful basis for using your data
We only use your data where we have a lawful basis to do so under UK and EU GDPR:
- To provide the App (contract): creating and running your account, showing your feed and trips, social features, basic search, and showing your content to the people you share it with.
- Legitimate interests: keeping the App secure, preventing fraud and abuse, fixing problems, understanding usage so we can improve, and building shared place information.
- Consent: personalising your recommendations (the opt-in setting in Section 7), and any use that specifically asks for your consent. You can withdraw consent at any time.
- Legal obligation: where we must process or disclose data to comply with the law.
10. Photo and content storage
- Photos and other content are stored using Google Firebase Storage.
- Content is kept while your account and the relevant post exist, and removed when you delete the post or your account (subject to short technical backup cycles).
- Photos are not edited beyond the compression and optimisation needed for performance.
- Who can see your content is governed by your privacy settings.
11. Data retention
- Account, profile, posts, transcripts, and other content: kept while your account is active, and removed when you delete them or close your account, subject to short technical backup cycles and any retention the law requires.
- Voice recordings: kept while the post exists; deleted when you delete the post or your account.
- Derived data and personalisation signals: kept while the relevant setting is on and your account is active; deleted when you turn the setting off, delete them, or close your account.
- Consent and acceptance records, and limited security logs: kept as long as needed for our legal and accountability obligations.
12. International transfers
We use Google (Firebase and Google Cloud) and the services listed in Section 6 to run the App. Some of these providers may process data outside the UK and EU. Where that happens, the transfer is protected by an appropriate safeguard, such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses, and a data processing agreement. Voice transcription and AI transcript processing are configured to run on EU-based infrastructure.
13. Your rights
Under UK and EU data protection law you have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to be forgotten").
- Restrict or object to certain uses.
- Withdraw consent at any time (for example, turn personalisation off).
- Data portability: obtain a copy of your data in a portable format.
You can do much of this in the App (edit your profile, change your settings, use the "What we know about you" screen, and delete your account). You can also contact us at info@theplot.world and we will respond within the time limits the law sets.
14. Deleting your account and data
You can delete your account at any time from within the App. When you do, we remove your account, your content (including photos and voice recordings), and the personalisation signals and derived information tied to you, and we recompute any shared place information so your contribution no longer influences it. Some limited data may be kept where the law requires it, or in short-lived technical backups that then expire.
15. Device permissions
The App asks for the following device permissions. You can grant or withdraw each of them at any time in your device settings:
- Camera: to take photos for your posts.
- Photo library: to choose photos to upload, and to save images when you share to other apps.
- Microphone: to record voice notes.
- Location: to show you nearby content, centre the map on you, suggest nearby places when you add a post, and set your "home" location if you choose to use your current location. We only request location while you are using the App. What gets saved to a post is the place you choose, not a continuous record of your movements. You can use the App and enter places manually without granting location access.
- Face ID and biometrics: to sign you in quickly and securely. The biometric check happens on your device and is never shared with us.
16. Children's privacy
The App is for people aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child under 16 has given us their data, contact us at info@theplot.world and we will delete it.
17. Security
We take security seriously and design for it throughout the App. Measures include encrypted connections, secure authentication (including passkeys and biometrics), restricted access to stored data, app-integrity checks, and keeping secrets and keys out of the App and in a secure secret store. No system is perfectly secure, but we work to protect your data and to handle any incident responsibly.
18. Business transfers
If we are involved in a merger, acquisition, or sale of assets, your data may be transferred to the new entity. We will let you know and this Policy will continue to apply until the new entity provides its own.
19. External links
The App may contain links to third-party services. We are not responsible for the privacy practices or content of those services. Please read their policies.
20. Changes to this Policy
We may update this Policy from time to time. If we make a material change, particularly to how we use your data for personalisation, we will tell you in the App and, where required, ask for fresh consent before the new use begins. We will not quietly repurpose data you gave us under an earlier version. The "Last updated" date at the top shows the current version.
If you have any questions about this Privacy Policy, contact us at info@theplot.world