Skip to content

YOUR STORY BELONGS TO YOU

Clear choices about your work.

An explanation of current product data behavior. Updated September 8, 2026.

Your local project

The original .plotnodes file lives in the folder you choose. Plotnodes does not automatically upload it, sync it across devices or attach ownership to your login. Local files use operating-system permissions, not application-level encryption. Backups or third-party folder sync are under your control.

Email review service

Start without an attachment, agree the review scope and AI processing terms, then send only a copy you checked. The reviewer can read it. Owner-controlled mailbox attachments, local working copies and reports are deleted within 30 days after completion or cancellation. Email and AI providers may retain separate copies under their terms. Reply to the review conversation to cancel or request deletion.

Existing test account services

Google sign-in is handled by Firebase Authentication. Desktop connections use expiring authorization records and revocable device credentials. Device secrets are hashed on the server and encrypted locally with operating-system secure storage. The service stores device platform and expiry, account status and content-free AI usage records.

When enabled test users run an automatic AI audit

Only the exact context you preview is sent through Plotnodes to OpenAI: selected cards and relationships, selected disclosures, relevant declared knowledge and any optional passage you included, plus the snapshot project identifier and revision. You must consent and run each audit explicitly. Results cannot change your story.

Plotnodes does not use stories to train its models. OpenAI API data is not used for training by default unless the provider account opts into sharing. Standard abuse-monitoring retention can apply. Requests use store:false; that is not a promise of Zero Data Retention.

Automatic test-service storage and retention

The Desktop audit service does not save submitted story text or returned findings in its database or operational logs. It keeps content-free request status and an internal keyed digest for changed-retry rejection. Audit request records expire after 35 days; daily bounded cleanup may run later. Device credentials expire after 30 days and connection requests after five minutes. Monthly usage totals and account status remain for service operation.

You can save an audit report locally. It includes the selected snapshot and findings. Cancelling prevents late findings from appearing, but cannot erase a request already received by the provider.

Disconnecting and deletion

Disconnect removes the local credential and attempts server revocation. If offline, revoke the device from the account page when online. Server revocation blocks later requests; processing already underway may have occurred.

The legacy Web workspace retains account export and deletion controls. Account deletion blocks connected Desktop devices but never deletes local .plotnodes files. Existing legacy cloud data and browser recovery copies follow that workspace’s notices and are not silently migrated.

Before general availability

This is an early-access product. The Apple Silicon alpha is Developer ID signed and Apple-notarized; Intel and Windows builds are not available. Production provider settings still require verification. This page does not promise that every planned capability is available.

Review process and data terms · Account page · Legacy Web workspace · OpenAI data controls