Ploto
Privacy Policy

Ploto Privacy Policy

Ploto is a Windows application that saves projects in a location chosen by the user. Normal use requires neither an account nor an internet connection, and project content is not sent automatically to servers operated by the provider of Ploto. When you use the AI Terminal, project content is sent to the AI service you choose.

Last updated: 2026-09-24
Contact: hiroki.lab@outlook.com

Technical information for IT departments is published separately, covering execution privileges, storage locations, network destinations and encryption.

View technical information

1. Basic Principles

Ploto (the app) is a project management application for Windows. No account registration or sign-in is required to use it.

Projects are saved on the device or in a shared location chosen by the user. Ploto has no proprietary cloud synchronization feature and does not automatically send project content entered by the user, such as tasks, assignees, schedules, notes or whiteboards, to servers operated by the provider of Ploto. However, if the user enables the AI Terminal and lets their own AI service read a project, that content is sent to the AI service as described in Section 3.3.

The app does not include Ploto-operated analytics or telemetry, advertising SDKs, behavioral tracking, or automatic crash reporting to external services.

2. Information Stored on the Device

Projects are saved as .ploto files in a location chosen by the user. Display settings, the license key, recently opened files, notice display state and similar information are stored on the device. While a project is open, a working copy is created on the device for stable editing and saving, and is deleted when the project is closed normally.

To prevent multiple people from editing the same project simultaneously in a shared location, a temporary lock file is created in the same location as the project. This file contains the Windows user name, computer name, process ID and timestamps, and is deleted on normal exit.

Ploto does not apply its own encryption to .ploto files. If you store confidential business information, configure device encryption, access and sharing permissions for the storage location, and backups in accordance with your organization's rules. See the technical information for IT departments for details about storage locations, file names and removal.

3. Situations Where External Services Are Used

Normal project creation, editing and saving can be performed offline. When the user chooses one of the following operations, the relevant external service processes the information required.

3.1. Microsoft Store and Windows

The Microsoft Store processes app distribution, updates, in-Store purchases and reviews. Depending on device and organization settings, Windows and the Microsoft Store may process installation information, crash information, and diagnostic information about the operating system and device. The provider of Ploto may use aggregated information that does not directly identify an individual to improve quality. The Microsoft Privacy Statement applies.

3.2. Purchasing a Paid License on the Web (Pro and AI Terminal)

For web purchases, Stripe processes the purchaser's email address, payment method, product, amount, currency, date and time, and connection information. Sensitive payment information such as card numbers is processed directly by Stripe and is not obtained or stored on servers operated by the provider of Ploto.

To issue a device-bound license, when a purchase starts the app generates a Ploto-specific one-way hash on the device from a device identifier made available to the publisher by Windows, and sends it to Stripe. The original device identifier is not sent. A process hosted on Vercel issues the license key, and Resend sends it to the purchaser's email address. After purchase, the license is verified on the device.

The Stripe Privacy Policy, Vercel Privacy Notice and Resend Privacy Policy apply respectively.

3.3. AI Terminal (AI Integration)

The AI Terminal lets AI CLIs that the user has installed on this PC and signed in to under their own subscription (such as Claude Code, Codex, Gemini CLI and OpenCode) read and edit the project open in Ploto. Project operations from AI are not accepted until the user grants permission in the first-time confirmation screen.

When the AI reads a project, the content it reads, such as task names, assignee names, schedules, notes, ToDos and tags, is sent through the AI CLI to the provider of the AI service chosen by the user and processed there. This transmission is performed by the AI CLI and the AI service; it does not pass through servers operated by the provider of Ploto, and the provider of Ploto does not receive that content or the conversation. How transmitted information is handled (including use for training, retention period and processing region) is governed by the agreement between the user and the AI service provider and by that provider's privacy policy. When handling business data, use an AI service and plan approved by your organization.

The AI operates Ploto through MCP (Model Context Protocol) or through an API that can only be used within this PC. Both connections are limited to this PC and cannot be reached from outside. AI operations start in read-only mode, and editing requires the user to turn on a switch or grant permission. The AI cannot save the project file; saving is done by the user in Ploto's window. On the other hand, the built-in terminal is a shell running with the user's Windows privileges, and Ploto's permission settings do not restrict file operations or commands that the AI CLI performs in that shell. Those follow the AI CLI's settings and the user's approvals.

For AI integration, the following information is stored on the device: consent status, the trial usage count, AI Terminal license information (protected by Windows data protection), and connection settings and instructions for AI (%USERPROFILE%\.ploto\ai). In addition, Ploto writes its connection settings and connection instructions to each AI client's settings folder: for Codex when AI integration is enabled, and for other AI clients only when the user clicks the register button. None of these contain credentials. Ploto does not store or transmit conversations with the AI or terminal output.

For details such as the instructions Ploto gives to AI, storage locations and how to disable the feature, see the technical information for IT departments.

3.4. Contact and Optional Forms

If a user sends a contact email or submits a Google Form, the information entered and any optional email address are used to respond, provide support, investigate issues and improve quality. The app does not automatically attach or send project content. Do not send confidential information, personal data, project files or screenshots without your organization's permission. The Google Privacy Policy applies.

3.5. Viewing the Official Site and This Policy

The official site at ploto-app.com is delivered through GitHub Pages and uses Google Analytics 4. If the official site is opened with ?ga=off, a preference is stored in that browser so the measurement tag is not loaded.

This policy is delivered through GitHub Pages at hiroking-ocean.github.io. This page does not include Ploto-operated access analytics or load external web fonts. GitHub may process standard access information. This page stores only the selected theme and display language in the browser. The GitHub General Privacy Statement applies.

4. Purposes of Use and Processing by Third Parties

Information received by the provider of Ploto through purchases, inquiries, optional forms and similar channels is used only as necessary to issue, resend and bind licenses to devices; prevent misuse; handle payments and support; investigate defects; improve quality; maintain accounting and tax records; resolve disputes; and comply with other legal obligations.

Project data, purchaser information and inquiry information are not used for sale, rental, advertising or provision to data brokers. Microsoft, Stripe, Vercel, Resend, Google and GitHub process information as necessary for distribution, purchases, license issuance, email delivery, form submission and web browsing. In accordance with each company's policies, information may be processed or stored in countries or regions outside the user's country.

The AI services used with the AI Terminal are providers that the user has chosen and contracted with; they are not processors acting on behalf of the provider of Ploto. The provider of Ploto does not provide information to those AI services, and their handling of information is governed by each AI service's terms and policies.

Information may be disclosed to relevant authorities within the scope of applicable law when required by law, when necessary to protect a person's life, physical safety or property, or when necessary to protect rights or prevent fraud.

5. Retention, Deletion and Requests

Purchase and license information is retained for as long as necessary to redisplay or resend licenses, provide purchase support, prevent fraud, and comply with accounting, tax and other legal obligations. Inquiries and form responses are retained for as long as necessary to respond, investigate, improve quality and comply with the law. The retention period for information held by external providers for their own purposes is governed by each provider's policies.

Projects and other files saved by the user remain until the user deletes them. Uninstalling the app does not remove files in locations chosen by the user or some auxiliary files on the device. See the technical information for IT departments for complete removal instructions.

To request access to, correction of, restriction of use of, or deletion of purchaser information, inquiry information or other data held by the provider of Ploto, contact the address below. After verifying identity, the provider will respond within reasonable limits, except for information that must be retained under legal, transaction or license-record requirements. Because the provider does not hold project content, it cannot disclose, restore or delete that content.

6. Changes and Contact

If this policy is changed, the revised content and updated date will be published on this page. Material changes to the types of information, purposes of use or external recipients may also be announced in the app's release notes when necessary.

For questions about this policy, the handling of user information, deployment by a company or organization, or licenses, please use the contact below.

hiroki.lab@outlook.com
Provider
Hiroki Tanaka(individual developer, trading as hiroki.lab)
Location
Chiba, Japan
Response time
Usually within 3 business days(Japan business days)
Languages
Japanese and English