Privacy Policy for The Plot
Last updated: 19 August 2026 (version 3.0)
What changed in this version
We have added new features, so we have updated this Policy to describe them. In short:
- Finding a place from a photo. When you choose photos for a post, the App now reads the location your camera saved inside them, on your device, to suggest where you were. Section 4.
- Browsing the map. When you browse the map, we ask Google what venues are in the area you are looking at. Section 5.
- Sharing outside the App. We have explained more clearly what happens when you share a post to another app, and that a shared link can be opened by anyone who has it. Section 6.
- More third-party services named. We have added the weather, map-search, country and currency services the App uses. Section 10.
- Clearer retention periods. Section 14.
Nothing about how we use your data for personalisation has changed. That setting is still off unless you turn it on.
1. Introduction
This Privacy Policy ("Policy") explains how ThePlot LTD ("Company," "we," "us," or "our") collects, uses, stores, and protects your personal data when you use The Plot mobile application ("App"). It also explains your rights and the choices you have.
By creating an account or using the App, you confirm you have read and understood this Policy. Where we rely on your consent for a particular use of your data, we ask for that consent separately and you can withdraw it at any time (see Section 11).
If you have questions about this Policy or how we handle your data, contact us at info@theplot.world.
2. Who we are and how to reach us
- Data controller: ThePlot LTD, United Kingdom.
- Contact for privacy questions and data requests: info@theplot.world
- You have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EU, you may also contact your local data protection authority.
3. The data we collect
a. Account and profile information
- Email address, to create your account, verify it, sign you in, and send you essential service messages.
- Password, only if you choose to sign in with an email and password. It is handled by Firebase Authentication and stored in a securely hashed form; we never see or store your password in plain text. If you sign in with a passkey, Apple, or Google instead, we do not hold a password for you at all (see "How you sign in" below).
- Name and username, to identify your account and for social features.
- Date of birth, collected at sign-up to confirm you are old enough to use the App. You must be 16 or older. We store the date you give us, and you can see and change it in your account settings.
- Country, selected at sign-up, used to tailor content and search to your region.
- Profile details you choose to add: profile photo, pronouns, a short bio (up to 500 characters), and one "favourite place" to highlight on your profile.
- A "home" location, if you set one. This is a place you choose as your home base, used for your travel passport (for example, your "home" and "origin" stamps). You can set this by searching for a place or, if you allow it, from your device location. You can change or remove it.
- Consent and acceptance records: which version of these Terms and this Policy you accepted, when, and the settings you have chosen for data sharing. We keep these as a record that you agreed, and for our own accountability.
b. How you sign in
The App supports several ways to sign in: email and password, a passkey (a secure sign-in tied to your device that uses your fingerprint, face, or device passcode), Sign in with Apple, and Sign in with Google. If you use Face ID, Touch ID, a fingerprint, or a passkey, the biometric check happens on your own device. Your fingerprint or face data never leaves your device and is never sent to us or stored on our servers.
c. Content you create
- Photos you take or upload for your posts and profile.
- Places you select for a post, including the underlying place identifier from Google Places.
- Written notes, ratings, and vibe tags you add to a post.
- Voice notes you record about a place (see Section 7, these get special handling).
- Trips you build from your posts, and the "passport" and country "stamps" that are built up from where you have posted.
- Social activity: who you follow, your followers and follow requests, posts you like, comments and replies you write, posts you save, and users you block.
Your account is private by default. You control who can see your content through your privacy settings. One important exception is explained in Section 6: a link you share outside the App can be opened by anyone who has it.
d. Information we work out from your content
From the text of your voice notes and from your posts, our systems (including AI, see Section 8) work out useful information about places: what a place is like, what it is good and bad at, vibe words, and search terms that would help someone find it. This is used to build honest, shared travel information. Where you have turned on personalisation (Section 11), we may also work out things about your travel taste to tailor your recommendations.
e. Activity signals (only if you turn on personalisation)
If, and only if, you turn on "personalise my recommendations," we log some of what you do in the App: the places you search for and open, the areas you browse on the map, items you save, comments, follows, and likes, and posts or profiles you open. We use this to learn your travel taste and improve what we suggest to you. If this setting is off, we do not log these signals. It is off unless you turn it on. You can see, and delete, what we have logged (Section 11).
f. Technical and device information (collected automatically)
When you use the App we automatically collect standard technical information needed to run it, keep it secure, and fix problems:
- Device and app information (device model, operating system, app version).
- IP address and approximate location derived from it, for security and abuse prevention, not to track your movements.
- Diagnostics, performance data, and crash reports.
- Usage and event analytics (which parts of the App are used, so we can improve it).
- Timestamps and account-creation metadata.
We use Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, and Firebase App Check for these purposes. See Section 10 for the third parties involved.
Please also note that any service your device contacts can see your device's IP address. That includes the map, weather, search, country and currency services listed in Section 10, because your device calls some of them directly.
g. Information about other people
If your content mentions, tags, or describes other people (including people who do not use the App), your content may include their personal information. You are responsible for what you share about others and should have a fair reason to do so. See Section 12.
4. Finding a place from your photos
This is new, so we want to be clear about exactly how it works.
Most cameras save the location where a photo was taken inside the photo file itself. When you choose photos for a post, the App reads that saved location so it can suggest the place you were at, instead of making you search for it.
How it works:
- The location is read on your device. Photos are not uploaded for this.
- We group photos taken close together into a single "stop", so a dozen pictures of one dinner count as one place.
- We send that coordinate, not the photo, to Google Places to ask what venues are nearby, and show you the results to choose from.
What we do not do:
- We do not scan your photo library. We only read the photos you have chosen for the post.
- We do not store the coordinate. It is not written to your account, not attached to your post, and not recorded in our logs.
- The photos you upload have this location information stripped out before they leave your device, so it does not travel with the image or reach anyone you share the post with.
Your control: on Android, reading photo locations needs a separate permission which we ask for the first time it is used, and you can decline it. On iOS it forms part of photo library access. On either platform you can turn off location tagging in your camera app, and you can always search for a place by hand instead. If the App cannot read a location, it simply makes no suggestion; nothing else stops working.
5. Maps and location
a. Your device location
With your permission, and only while you are actively using the App, we use your device location to show you nearby content, centre the map on you, suggest nearby places when you add a post, and set your "home" location if you choose to use your current location.
We use location at the moment you ask for a nearby feature. We do not track your movements in the background, and we do not build a history of where you have been. What gets saved to a post is the place you chose, not a continuous record of your location. You can use the App and enter places manually without granting location access at all.
b. Browsing the map
When you browse the map, we ask Google Places what venues are in the area you are viewing so we can show them as pins. This means the part of the map you are looking at is sent to Google. Map imagery itself is provided by Mapbox.
Only public posts from other people appear on the map. Posts from private accounts, and posts you have not made public, are never shown to anyone who is not entitled to see them.
If you have turned personalisation on, the places you open from the map are among the activity signals we log (Section 3e). If it is off, we do not log them.
6. Sharing your content outside the App
When you share a post or a trip to another app, whether a messaging app, a social platform, or anywhere else, we create a link that shows a preview of it. To do that, we send our link partner Branch the post or trip's title, its identifier, and a link to its cover photo.
Please read this part carefully, because it is the one place where your privacy settings do not apply:
Anyone who has that link can open the preview, whether or not they use The Plot, and whether or not your account is private. The platform you share to will usually fetch and store a copy of the preview image in order to display it. We cannot recall a link once you have sent it.
Only share links with people you are happy to show that content to. Sharing is always something you choose to do; nothing is shared outside the App unless you tap share.
The share card the App creates for you may also include a map of your route (drawn by Mapbox) and the weather at the places on it (from Open-Meteo). See Section 10.
7. Voice notes (special handling)
Voice notes are a core part of the App, so we want to be very clear about how they work.
- We record and keep your voice recordings. When you record a voice note about a place, the audio is uploaded and stored with your account so that you (and people you share the post with) can play it back on the post. It is your own content.
- We turn your voice note into text (a transcript). Transcription is done using Google's Speech-to-Text service. This processing takes place on servers located in the European Union.
- An AI reads the transcript to work out useful information about the place you are talking about (see Section 8). This uses Claude, an AI model run inside Google Cloud. Your transcript is processed to produce vibe words and search terms; it is not used to train third-party AI models.
- We never create a "voiceprint" and never try to identify you by your voice. We do not do speaker identification or voice recognition of any kind. The transcription process only turns spoken words into text.
- Your recordings are deleted when you delete the post, or when you delete your account. We keep them only for as long as the post exists.
- Transcripts may occasionally contain sensitive information, for example if you happen to mention something about your health, beliefs, or personal life while talking. We do not seek this out, but because it can happen, we store transcripts securely and with restricted access.
8. Artificial intelligence (AI) in the App
Parts of the App use AI to turn what people say and post into useful travel information:
- Understanding voice notes: as described in Section 7, an AI model (Claude, run inside Google Cloud) reads the text of your voice note to derive vibe words and search terms about a place.
- Photo framing: when you set a cover photo, the App uses on-device image analysis to work out the best point to centre the photo on (for example, a face or the main subject). This runs entirely on your device, makes no internet calls, and is not used to identify anyone. It is only used to frame the picture nicely.
AI-derived information about places is treated as a helpful signal, not as hard fact. We do not present an AI guess as a definitive statement.
9. Photo and content storage
- Photos and other content are stored using Google Firebase Storage.
- Content is kept while your account and the relevant post exist, and removed when you delete the post or your account (subject to the backup cycle in Section 14).
- Photos are compressed and optimised for performance, and their embedded location information is removed, but they are not otherwise edited.
- Who can see your content is governed by your privacy settings, subject to Section 6.
10. Data sharing and third-party services
We do not sell, rent, or trade your personal information. We do share data with the service providers that make the App work, and only as needed to provide the service.
a. Core infrastructure
- Google Firebase and Google Cloud, for hosting, sign-in (Firebase Authentication), database (Firestore), file and photo storage, cloud functions, push notifications (Firebase Cloud Messaging), analytics, crash reporting, performance monitoring, and app security (App Check). Also used for voice transcription (Google Speech-to-Text) and AI processing of transcripts (Claude via Google Cloud Vertex AI).
- Apple and Google, if you choose to sign in with Apple or Google.
b. Maps and places
- Google Maps, Google Places, and Google Geocoding, to show maps, let you search for places, turn coordinates into a place name, find what venues are near a photo's location (Section 4), and find what venues are in the area of map you are browsing (Section 5).
- Mapbox, to display interactive maps, and to draw the route maps on share cards.
- OpenStreetMap (Nominatim), operated by the OpenStreetMap Foundation, used as an additional source of place search results. When you search this way, your search text and the area you are searching in are sent to them.
c. Sharing
- Branch, to create and open shared links. When you share a post or trip, we send Branch its title, its identifier, and a link to its cover photo so the shared link shows a preview. Branch also processes limited device information in order to open the link in the App. See Section 6.
- Sharing to other apps: if you choose to share content to another app, that app's own privacy policy applies to what you share.
d. Small supporting services
These receive very little, usually a coordinate or a code, but your device contacts them directly, so they can see its IP address.
- Open-Meteo, to show the weather at the places in your feed and on your posts. We send the place's coordinates.
- REST Countries, to show country names from a country code. We send a country code only.
- ER-API (open.er-api.com), to convert currency. We send a currency code only.
e. Other disclosures
We may also disclose data where the law requires it, to protect the safety, rights, or property of our users or the public, or in connection with a business transfer (Section 19).
11. Your privacy controls and consent
The core App works fully with all optional data-sharing switched off. You are in control:
- Account privacy: your account is private by default; you choose who can see your content.
- Contribute to the shared place database: you can choose whether the information derived from your posts and voice notes helps build our pooled, anonymised information about places (about the places, not about you). Your audio recording itself is never added to that database, and nothing in it is linked to your identity. You can change this in settings.
- Personalise my recommendations: a separate, opt-in setting. It is off by default. When on, we log the activity signals in Section 3e to tailor your recommendations. When off, we do not log them.
- "What we know about you": a screen in the App where you can see the signals we have logged about you and delete them.
- Notification preferences: you choose which push notifications you receive (follows, likes, comments, follow requests, new trips).
- Device permissions: you can grant or withdraw camera, photo library, photo location, microphone, and location permissions at any time in your device settings (Section 20).
12. Information about other people
If your content names, tags, or describes other people, including people who do not use the App, you are responsible for what you share and confirm you have a fair basis to share it. If someone who does not use the App contacts us about their information appearing in content, we will handle their data-protection rights as required by law.
13. Purpose and lawful basis for using your data (UK/EU GDPR)
We only use your data where we have a lawful basis to do so:
- To provide the App (contract): creating and running your account, showing your feed and trips, social features, basic search, suggesting places from your photos, showing the map, and showing your content to the people you share it with.
- Legitimate interests: keeping the App secure, preventing fraud and abuse, fixing problems, understanding usage so we can improve, and building shared place information.
- Consent: personalising your recommendations (the opt-in setting in Section 11), and any use that specifically asks for your consent. You can withdraw consent at any time.
- Legal obligation: where we must process or disclose data to comply with the law.
A note on automated decisions: our recommendations are suggestions, not decisions that have a legal or similarly significant effect on you.
14. Data retention
- Account, profile, posts, transcripts, and other content: kept while your account is active, and removed when you delete them or close your account, subject to the backup cycle below and any retention the law requires.
- Voice recordings: kept while the post exists; deleted when you delete the post or your account.
- Derived data and personalisation signals: kept while the relevant setting is on and your account is active; deleted when you turn the setting off, delete them, or close your account.
- Backups: deleted content can persist in our technical backups for up to 7 days, after which those backups expire.
- Consent and acceptance records, and limited security logs: kept for as long as we need them to show which version of these documents you agreed to, and to meet our legal and accountability obligations.
15. International transfers
We use Google (Firebase and Google Cloud) and the services listed in Section 10 to run the App. Some of these providers may process data outside the UK and EU. Where that happens, the transfer is protected by an appropriate safeguard, such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses, and a data processing agreement. Voice transcription and AI transcript processing are configured to run on EU-based infrastructure.
16. Your rights
Under UK and EU data protection law you have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to be forgotten").
- Restrict or object to certain uses.
- Withdraw consent at any time (for example, turn personalisation off).
- Data portability, to obtain a copy of your data in a portable format.
You can do much of this in the App (edit your profile, change your settings, use the "What we know about you" screen, and delete your account). You can also contact us at info@theplot.world and we will respond within the time limits the law sets.
17. Deleting your account and data
You can delete your account at any time from within the App. When you do, we remove your account, your content (including photos and voice recordings), and the personalisation signals and derived information tied to you, and we recompute any shared place information so your contribution no longer influences it. Some limited data may be kept where the law requires it, or in the technical backups described in Section 14, which then expire.
Links you have already shared outside the App may continue to show a cached preview on the platform you shared them to, because that copy is held by that platform and not by us. See Section 6.
18. Security
We take security seriously and design for it throughout the App. Measures include encrypted connections, secure authentication (including passkeys and biometrics), restricted access to stored data, app-integrity checks (App Check), and keeping secrets and keys out of the App and in a secure secret store. No system is perfectly secure, but we work to protect your data and to handle any incident responsibly.
19. Business transfers
If we are involved in a merger, acquisition, or sale of assets, your data may be transferred to the new entity. We will let you know and this Policy will continue to apply until the new entity provides its own.
20. Device permissions
The App asks for the following device permissions. You can grant or withdraw each of them at any time in your device settings:
- Camera, to take photos for your posts.
- Photo library, to choose photos to upload, to read the location saved inside the photos you choose so we can suggest a place (Section 4), and to save images when you share to other apps.
- Photo location (Android only), a separate permission that lets us read the location stored inside a photo. If you decline it, the App still works; it just cannot suggest places from your photos.
- Microphone, to record voice notes.
- Location, to show you nearby content, centre the map on you, suggest nearby places when you add a post, and set your "home" location if you choose to use your current location. We only request location while you are using the App. You can use the App and enter places manually without granting location access.
- Face ID and biometrics, to sign you in quickly and securely. The biometric check happens on your device and is never shared with us.
- Notifications, to send you the push notifications you have chosen to receive.
21. Children's privacy
The App is for people aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child under 16 has given us their data, contact us at info@theplot.world and we will delete it.
22. External links
The App may contain links to third-party services. We are not responsible for the privacy practices or content of those services. Please read their policies.
23. Changes to this Policy
We may update this Policy from time to time. If we make a material change, particularly to how we use your data for personalisation, we will tell you in the App and, where required, ask for fresh consent before the new use begins. We will not quietly repurpose data you gave us under an earlier version. The "Last updated" date at the top shows the current version.
If you have any questions about this Privacy Policy, contact us at info@theplot.world.