Privacy Policy
Effective
This Privacy Policy explains what personal data Ploof collects, why, and what you can do about it. It applies to the Ploof Studio app for Mac, the website ploof.dev and studio.ploof.dev, and any related services (together, the "Services").
Ploof is operated by Yozhef Serhiiovych Hisem, an individual based in Chop, Zakarpattia Oblast, Ukraine ("Ploof", "we", "us"). We are the controller of the personal data described here. You can reach us at support@ploof.dev.
Ploof Studio is distributed through Setapp, operated by MacPaw Way Ltd. Your Setapp account (including its deletion), subscription and payments are handled by Setapp under the Setapp Privacy Notice, not this policy.
This policy should be read together with our Terms of Use.
We collect only what we need to build, edit and publish your sites.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, email address, username, avatar and account ID from the provider you sign in with (GitHub, Google or Vercel) | The sign-in provider, with your permission |
| Connected-account tokens | Access tokens that let Ploof create repositories, push code and deploy on your GitHub or Vercel account | GitHub or Vercel, when you connect them |
| Project content | Your prompts and comments, files you attach (logos, photos), reference site URLs, and the code, text and images of the sites Ploof generates | You, and Ploof while it builds |
| Domain searches | Names you search for when looking for a custom domain | You |
| Technical data | App version, macOS version, device type, IP address, error logs and timestamps | Your device, automatically |
| Support messages | Whatever you send us when you contact us | You |
We do not process special categories of data (such as health or religious beliefs), and we ask you not to put them into prompts or site content. We do not sell your personal data, and we don't use our own analytics, advertising or crash-reporting tools. Ploof includes the Setapp Framework, which Setapp uses to process product-interaction data, device identifiers and user identifiers for app functionality and analytics. Setapp handles that data under its own Privacy Notice and states that it isn't used for tracking.
If you are in the EEA, the UK or Switzerland, we rely on the legal bases below under the GDPR and UK GDPR.
| Purpose | Data used | Legal basis |
|---|---|---|
| Sign you in and keep your account working | Account data, technical data | Performance of our Terms of Use |
| Generate, edit and check your sites | Project content | Performance of our Terms of Use |
| Publish to GitHub Pages or Vercel and export ZIPs | Connected-account tokens, project content | Performance of our Terms of Use, at your request |
| Suggest custom domains | Domain searches | Performance of our Terms of Use |
| Keep the Services secure, prevent abuse and fix bugs | Technical data, account data | Legitimate interests |
| Answer support requests | Support messages, account data | Performance of our Terms of Use; legitimate interests |
| Comply with the law and defend legal claims | Any data we hold, as needed | Legal obligation; legitimate interests |
We don't train our own AI models on your prompts, files or generated sites, and we don't use them for advertising.
Ploof uses third-party AI models to write and change your sites. Depending on the AI connection used, your request goes to one of these providers:
- Setapp AI, operated by MacPaw Way Ltd., which passes requests on to the AI model providers it works with;
- Anthropic, PBC (Claude models);
- OpenAI, L.L.C. (GPT models).
When you send a prompt or comment, we send the provider only what the model needs to do the job: your text, attached files, the reference site you named and the current files of your project.
We don't control whether Setapp or an underlying provider logs, retains, reviews or filters what you send, or uses it to improve its services. That depends on their terms, safety systems and the law, so we can't promise zero retention for every provider. Please review their current terms before sending confidential content.
Your own API key. You can also add your own Anthropic or OpenAI API key. Requests made with it go to that provider under your own account and agreement, and the usage is billed to you. Ploof uses the key only to send your requests. You can remove it at any time.
AI output can be wrong or incomplete. Please review your site before you publish it, and do not put other people's personal data into prompts unless you have the right to.
| Data | How long |
|---|---|
| Account data and projects | While your account is active. We delete them within 30 days after you delete your account or ask us to |
| Connected-account tokens | Until you disconnect the account in Ploof, revoke access at GitHub or Vercel, or delete your account |
| Technical data and error logs | Up to 12 months |
| Support messages | Up to 2 years after the request is closed |
| Data needed for legal claims | As long as the law requires or the claim lasts |
Sites you published stay on GitHub or Vercel after you delete your Ploof account. They live on your accounts, so you remove them there.
We protect data with encryption in transit (HTTPS), encrypted storage of access tokens, and access limited to the people who run Ploof. No system is fully secure. If a breach is likely to put your rights at high risk, we will tell you without undue delay.
Some of our providers are in the United States and other countries outside the EEA. Where required, transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
Depending on where you live, you can ask us to:
- give you a copy of your personal data, in a portable format;
- correct data that is wrong;
- delete your data;
- restrict or object to how we use it;
- withdraw consent you gave, at any time.
You can also disconnect GitHub or Vercel, or export your sites as a ZIP in the app. Account deletion is handled by Setapp, through your Setapp account. For anything else, email support@ploof.dev. We answer within 30 days and may ask you to confirm your identity first. It's free, unless a request is clearly unfounded or excessive.
If you are in the EEA or UK, you can also complain to your local data protection authority. California residents have the rights described in the CCPA. We do not sell or share personal data for cross-context behavioral advertising.
The Services are not meant for children under 13, or under 16 where local law sets that age. We do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
We may update this policy as Ploof changes. We will post the new version here with a new effective date. If the changes are significant, we will also tell you in the app or by email before they take effect.
Yozhef Serhiiovych Hisem (individual)
Chop, Zakarpattia Oblast, Ukraine
Email: support@ploof.dev
Something unclear?
Write to us and a person reads it and replies.