Legal

Privacy Policy

Effective

Who we are and what this policy covers

This Privacy Policy explains what personal data Ploof collects, why, and what you can do about it. It applies to the Ploof Studio app for Mac, the website ploof.dev and studio.ploof.dev, and any related services (together, the "Services").

Ploof is operated by Yozhef Serhiiovych Hisem, an individual based in Chop, Zakarpattia Oblast, Ukraine ("Ploof", "we", "us"). We are the controller of the personal data described here. You can reach us at support@ploof.dev.

Ploof Studio is distributed through Setapp, operated by MacPaw Way Ltd. Your Setapp account (including its deletion), subscription and payments are handled by Setapp under the Setapp Privacy Notice, not this policy.

This policy should be read together with our Terms of Use.

Data we collect

We collect only what we need to build, edit and publish your sites.

Account dataName, email address, username, avatar and account ID from the provider you sign in with (GitHub, Google or Vercel)The sign-in provider, with your permission
Connected-account tokensAccess tokens that let Ploof create repositories, push code and deploy on your GitHub or Vercel accountGitHub or Vercel, when you connect them
Project contentYour prompts and comments, files you attach (logos, photos), reference site URLs, and the code, text and images of the sites Ploof generatesYou, and Ploof while it builds
Domain searchesNames you search for when looking for a custom domainYou
Technical dataApp version, macOS version, device type, IP address, error logs and timestampsYour device, automatically
Support messagesWhatever you send us when you contact usYou

We do not process special categories of data (such as health or religious beliefs), and we ask you not to put them into prompts or site content. We do not sell your personal data, and we don't use our own analytics, advertising or crash-reporting tools. Ploof includes the Setapp Framework, which Setapp uses to process product-interaction data, device identifiers and user identifiers for app functionality and analytics. Setapp handles that data under its own Privacy Notice and states that it isn't used for tracking.

How we use your data

If you are in the EEA, the UK or Switzerland, we rely on the legal bases below under the GDPR and UK GDPR.

Sign you in and keep your account workingAccount data, technical dataPerformance of our Terms of Use
Generate, edit and check your sitesProject contentPerformance of our Terms of Use
Publish to GitHub Pages or Vercel and export ZIPsConnected-account tokens, project contentPerformance of our Terms of Use, at your request
Suggest custom domainsDomain searchesPerformance of our Terms of Use
Keep the Services secure, prevent abuse and fix bugsTechnical data, account dataLegitimate interests
Answer support requestsSupport messages, account dataPerformance of our Terms of Use; legitimate interests
Comply with the law and defend legal claimsAny data we hold, as neededLegal obligation; legitimate interests

We don't train our own AI models on your prompts, files or generated sites, and we don't use them for advertising.

How AI processes your content

Ploof uses third-party AI models to write and change your sites. Depending on the AI connection used, your request goes to one of these providers:

  • Setapp AI, operated by MacPaw Way Ltd., which passes requests on to the AI model providers it works with;
  • Anthropic, PBC (Claude models);
  • OpenAI, L.L.C. (GPT models).

When you send a prompt or comment, we send the provider only what the model needs to do the job: your text, attached files, the reference site you named and the current files of your project.

We don't control whether Setapp or an underlying provider logs, retains, reviews or filters what you send, or uses it to improve its services. That depends on their terms, safety systems and the law, so we can't promise zero retention for every provider. Please review their current terms before sending confidential content.

Your own API key. You can also add your own Anthropic or OpenAI API key. Requests made with it go to that provider under your own account and agreement, and the usage is billed to you. Ploof uses the key only to send your requests. You can remove it at any time.

AI output can be wrong or incomplete. Please review your site before you publish it, and do not put other people's personal data into prompts unless you have the right to.

Who we share data with

We share personal data only with the services below, and only as much as each one needs.

Setapp AI (MacPaw Way Ltd.)Runs AI requests that build and edit your sites, when this connection is usedOur processor
AnthropicRuns AI models that build and edit your sites, when this connection is usedOur processor
OpenAIRuns AI models that build and edit your sites, when this connection is usedOur processor
GitHubSign-in; creating repositories and publishing to GitHub Pages on your accountIndependent controller for your GitHub account
GoogleSign-in with GoogleIndependent controller for your Google account
VercelSign-in; deploying your site and buying domains on your Vercel accountIndependent controller for your Vercel account
Setapp (MacPaw Way Ltd.)Distribution, subscription, payments, AI credits, and app usage data collected by the Setapp FrameworkIndependent controller
[Hosting provider]Stores account and project data on our serversOur processor

When you publish, your site becomes public on the host you chose. Anything on it, including names, photos or contact details you added, can be seen by anyone.

We may also disclose data if the law requires it, to protect our rights or users' safety, or to a successor if Ploof is sold or merged. In that case we will tell you first.

How long we keep data, and how we protect it

Account data and projectsWhile your account is active. We delete them within 30 days after you delete your account or ask us to
Connected-account tokensUntil you disconnect the account in Ploof, revoke access at GitHub or Vercel, or delete your account
Technical data and error logsUp to 12 months
Support messagesUp to 2 years after the request is closed
Data needed for legal claimsAs long as the law requires or the claim lasts

Sites you published stay on GitHub or Vercel after you delete your Ploof account. They live on your accounts, so you remove them there.

We protect data with encryption in transit (HTTPS), encrypted storage of access tokens, and access limited to the people who run Ploof. No system is fully secure. If a breach is likely to put your rights at high risk, we will tell you without undue delay.

Some of our providers are in the United States and other countries outside the EEA. Where required, transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

Your rights

Depending on where you live, you can ask us to:

  • give you a copy of your personal data, in a portable format;
  • correct data that is wrong;
  • delete your data;
  • restrict or object to how we use it;
  • withdraw consent you gave, at any time.

You can also disconnect GitHub or Vercel, or export your sites as a ZIP in the app. Account deletion is handled by Setapp, through your Setapp account. For anything else, email support@ploof.dev. We answer within 30 days and may ask you to confirm your identity first. It's free, unless a request is clearly unfounded or excessive.

If you are in the EEA or UK, you can also complain to your local data protection authority. California residents have the rights described in the CCPA. We do not sell or share personal data for cross-context behavioral advertising.

Children

The Services are not meant for children under 13, or under 16 where local law sets that age. We do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We may update this policy as Ploof changes. We will post the new version here with a new effective date. If the changes are significant, we will also tell you in the app or by email before they take effect.

Contact us

Yozhef Serhiiovych Hisem (individual)
Chop, Zakarpattia Oblast, Ukraine
Email: support@ploof.dev

Something unclear?

Write to us and a person reads it and replies.

support@ploof.dev