Privacy policy

Privacy

Last updated: August 26, 2026. Autoplot is a native Mac application for scientific plotting and analysis. Most of the work happens locally; hosted services are used for accounts, subscriptions, waitlist signup, the public roadmap, analytics, and the optional assistant.

The short version

Your imported data files, project files, analysis variables, cards, workspaces, annotations, local Python runtime, generated scripts, and exported figures are stored on your Mac unless you choose to move or share them.

Autoplot does not sell personal information and does not use imported data files, project contents, assistant prompts, or raw scientific data for advertising.

The website uses Google Analytics, served through Cloudflare Google Tag Gateway, for website pageview measurement, referrer and campaign analytics, and aggregate browser, device, session, and approximate-region reporting. The analytics tag removes known app-return and checkout identifiers from URL payloads before sending pageview events.

Release app builds use Firebase Analytics, linked to Google Analytics, for coarse product analytics: app sessions, paywall funnel milestones, workspace mode changes, and figure/card creation category. Firebase may create app-instance and session identifiers for analytics measurement, but Autoplot does not set a Firebase user ID or attach account IDs, emails, checkout URLs, file paths, file names, column names, variable names, assistant prompts, generated code, or scientific data values to app analytics events.

Who controls the data

Autoplot is operated from Sweden while the legal entity is being formed. Until the entity details are finalized, use [email protected] for privacy requests, account requests, and data deletion requests.

If this policy changes because the legal entity, vendors, or product behavior changes, we will update this page before relying on the new practice.

Website and waitlist

If you join the waitlist, we collect your email address, the signup source, and the time of signup. We use that to send launch and product-access messages, prevent duplicate signups, and respond to support requests.

The website is hosted on Cloudflare Pages. Google Analytics measures website page path and title, referrer and campaign parameters, and aggregate usage information such as users, sessions, approximate geolocation, browser, and device information so we can understand which public pages are useful. The tag may use first-party analytics cookies or client identifiers for that measurement, and Autoplot strips known app-return, checkout, auth, and token URL parameters before pageview payloads are sent. If Turnstile bot protection is enabled on the signup form, Cloudflare receives the information needed to verify the challenge. Cloudflare may also process normal hosting security logs, such as IP address, user agent, request time, and requested URL.

Public roadmap

The feature-request form publishes your product surface, what you would like to do, how you picture it working, why it matters, and an internal opaque submission marker in a public GitHub issue. The issue also receives request, status, and product-surface labels. Anyone can read, discuss, or copy that content on GitHub. The GitHub account that owns Autoplot's configured publishing token appears as the issue author; the visitor is not presented as the GitHub author. The website shows the issue's public comment count and links to the GitHub discussion; it does not copy comment bodies or accept website comments. GitHub may retain issue history, caches, forks, or copies after an edit or deletion.

Before publication, a private Cloudflare D1 pending feature request record stores the opaque submission id, product surface, the three request answers, a salted hash of the Autoplot account email, publication state and bounded failure code, optional short-lived publication lease fields, and creation, update, and expiry times. It never stores the raw email, name, Supabase user id, or access token. The request can be published for up to 24 hours and is deleted immediately after successful publication. After expiry it cannot be published; its stored row is removed by the next request cleanup or an authorized operator purge. No fixed deletion time is currently guaranteed for an abandoned expired row. The one-time link's own lifetime is separately controlled by Supabase and may be shorter.

After publication, the corresponding Cloudflare D1 feature_requests record stores the internal submission id, GitHub issue number and URL, derived title and product surface, roadmap status and optional shipped URL, GitHub creation state and bounded creation error, contributor id, Supabase user id, salted email hash, and creation time. New verified feature requests store no raw email or public display name and publish no account identity to GitHub.

Do not put patient data, confidential material, raw datasets, credentials or other secrets, private file paths, or anything that should stay inside a lab or company in either roadmap text or an attachment.

Private roadmap feedback

General feedback is private to the Autoplot team. It does not create a GitHub issue and does not appear in the public request list, roadmap, vote counts, or leaderboard. Email and explicit permission for submission-specific follow-up are required before feedback is accepted. The Cloudflare D1 feedback_submissions record stores a submission id, feedback text, the required raw contact email, the required follow-up flag, optional private attachment key, validated media type, byte size, SHA-256 digest, storage state, bounded storage error, and creation and update times. It does not store the original filename. This permission is not a newsletter or general-marketing subscription.

One optional JPEG, PNG, WebP, or PDF attachment of no more than 10 MiB may be stored in a private Cloudflare R2 bucket. Autoplot stores the exact accepted bytes under a deterministic private key with validated content type and attachment-disposition metadata. There is no public website route or public object URL for these files. The attachment is not published to GitHub. The same sensitive-data warning applies to both the text and the file.

Cloudflare Turnstile helps block automated spam for both feature requests and general feedback. It processes the browser and request information needed to verify the check. If the check fails, is unavailable, or is not configured as required, the submission is not accepted.

Roadmap identity, voting, and storage

For verified feature requests, the roadmap normalizes the Autoplot account email, creates a salted SHA-256 hash, and discards the raw address. The D1 program_users mapping stores contributor id, Supabase user id, salted email hash, no public display name, and creation and update times. Opening the one-time link verifies the matching account and automatically publishes the completed request; there is no additional confirmation click.

Voting uses Supabase email magic links only for an existing Autoplot account. The roadmap asks for the exact Sign-in email shown in the Mac app and requests a link with account creation disabled; the website cannot create an account. Supabase processes the email, authentication state, session identifiers, and tokens. The roadmap stores the access token and expiry in this browser's local storage so the session survives a reload, and uses the token's email only to show the active account. Signing out removes the local roadmap token; an expired or rejected token is also removed. Server-side token verification remains the authorization boundary.

The D1 feature_requests schema still has a legacy nullable raw-email field used by earlier roadmap operation. This reactivation did not inspect or change production rows. Production values have not been inventoried, so older feature_requests rows may contain raw submission emails.

The D1 votes record stores only the GitHub issue number, Supabase user id, and vote time; it does not store an email address or email hash. The email hash used for private contributor matching is in program_users instead. One verified account can cast one vote per request, and the public board exposes only aggregate vote counts.

The public leaderboard API returns a per-contributor aggregation under the associated public display name for submitted public-request count, and a separate per-contributor aggregation under the public display name for the combined count of requests with Accepted, Building, or Shipped status. The leaderboard page remains unbuilt and unlinked; the API itself remains public.

Roadmap retention and deletion

Public feature-request records are retained while needed to operate and reconcile the GitHub issue, record its roadmap or shipping state, handle failed issue creation and abuse, match contributor attribution, and preserve an intelligible public record. Private pending feature requests become ineligible for publication after 24 hours; successful publication removes their private answers immediately, while abandoned expired rows are removed opportunistically or by an authorized operator purge. No fixed deletion time is currently guaranteed for an abandoned expired row. Vote records are retained while needed to enforce one verified account, one vote per request and publish aggregate counts. No fixed deletion period has been set for feature_requests, program_users, or votes.

Private Quick feedback D1 records and any R2 attachments are retained while needed to review the feedback, respond when permitted, act on it, maintain storage integrity, handle abuse, or document the resulting product decision. No automatic deletion schedule or fixed deletion period has been set for this record class or its files.

Deleting a Supabase account or removing the browser token does not automatically delete roadmap records. You may ask [email protected] to delete or de-link private fields or records where appropriate. Deleting private Quick feedback with an attachment requires coordinated removal of both the D1 feedback_submissions row and the R2 object identified by its attachment key; deleting only one does not remove the other.

Public GitHub content, issue history, caches, forks, and copies outside Autoplot's control may remain. Deleting an account does not guarantee removal of public issue history or aggregate counts. Any legacy raw email in an older feature_requests row remains subject to this retention and deletion treatment until an approved production reconciliation and separately approved cleanup occur.

App accounts

The app can create an anonymous hosted-AI account through Supabase. If you choose to protect that account, sign in, or recover a purchase, Supabase processes your email address, password-authentication state, session identifiers, and auth tokens.

Supabase auth tokens are stored locally in Application Support on your Mac so the app can restore your session. Signing out clears the local session state used by Autoplot.

Hosted assistant

The assistant is optional and requires a hosted account session. Production assistant requests are sent through Supabase Edge Functions to a server-selected AI provider. The current backend uses QWen 3.6 35B on deepinfra.com behind that gateway.

When you use Chat mode, Autoplot sends your prompt and chat history. When you use Execute mode, Autoplot also sends a workspace manifest so the assistant can understand the current project. That manifest may include file names, column names, variable names, row counts, variable sources, derived formulas, card and figure settings, result summaries, annotations, selected tab, and the selected working-folder path.

Autoplot does not intentionally upload imported raw dataset values, full project files, exported figures, saved scripts, API keys, passwords, or payment details as part of the normal hosted-AI request. If you type or paste raw data, secrets, or other sensitive information into the assistant prompt, that text is sent as part of the request.

Assistant metering

To enforce hosted-AI credits and prevent duplicate billing, the backend stores account identifiers, billing period details, entitlement tier, credit budget and spend, request identifiers, provider usage metadata, and related RevenueCat sync metadata.

The billing ledger is designed not to store prompts, transcripts, generated code, generated responses, project data, or user datasets.

Subscriptions

Subscriptions and purchase status are handled with RevenueCat and related payment providers. Autoplot uses RevenueCat entitlement evidence to determine Plus or Pro access, recover purchases, and refresh billing status.

Autoplot does not store full card numbers or bank details. Billing emails, product identifiers, entitlement status, subscription period metadata, and support-recovery information may be processed so the app can provide paid access and help with account recovery.

App analytics

Release app builds use Firebase Analytics for Apple platforms, linked to Autoplot's Google Analytics property. The app records coarse events such as session start and end with engagement duration, workspace mode changes, figure/card creation category and manual-vs-assistant creation source, paywall impressions and dismissals, checkout opens, restore starts, and trusted paid-tier confirmations.

Autoplot also sends default coarse context with app analytics events, such as app environment, distribution channel, app version, and build number. Firebase may generate app-instance and session identifiers and process technical app/device analytics metadata. Autoplot does not set a Firebase user ID, does not use app analytics as support diagnostics, and does not attach Supabase IDs, RevenueCat app user IDs, Apple IDs, Google account IDs, emails, checkout URLs, file paths, file names, column names, variable names, assistant prompts, generated code, free-form errors, or scientific data values to Firebase/Google Analytics app events. Firebase app analytics is configured without advertising personalization signals, IDFV collection, or IDFA/AdSupport collection. We use this analytics data to understand product usage and improve the app, not for advertising.

Why we use data

We process waitlist and support data to communicate with you and answer requests. We process account, authentication, subscription, and hosted-AI usage data to provide the app, protect purchases, enforce credits, prevent abuse, and keep the service secure.

We process website and app analytics to understand which pages and product flows are useful, diagnose broad product adoption patterns, and improve onboarding, pricing, and feature decisions without uploading your raw scientific data.

For users in the EU, UK, and similar jurisdictions, the usual legal bases are contract where processing is needed to provide the product, legitimate interests for security, abuse prevention, support, and product operations, consent where you choose optional communications, and legal obligation where records must be kept for tax, accounting, or compliance.

Sharing and transfers

We share personal data only with service providers that help run Autoplot: Cloudflare for Pages hosting, D1 roadmap records, private R2 feedback attachments, Turnstile bot protection, security, and the Google Tag Gateway path; Google Analytics for website analytics; Firebase Analytics and Google Analytics for app product analytics; Supabase for authentication, database, and Edge Functions; GitHub for publishing, hosting, and discussing public Detailed requests; RevenueCat and payment providers for subscription management; QWen 3.6 35B on deepinfra.com through the hosted AI gateway; and email or support providers when you contact us.

The roadmap fields described above are deliberately transferred to GitHub for public display. Anyone can read or copy that public issue content, and GitHub may retain its history and copies as described above.

Those providers may process data in countries other than yours, including the United States. Where privacy law requires transfer safeguards, we rely on the provider's contractual and legal safeguards rather than selling or broadly disclosing your data.

Retention

Local project data stays on your Mac until you delete it. Waitlist records are kept until they are no longer needed for launch communications or you ask us to delete them. Account, subscription, and usage records are kept while your account is active and for a reasonable period afterward for support, fraud prevention, accounting, and legal compliance.

Website and app analytics records are retained according to the configured provider controls and only as long as needed for product and website operations. Support emails are kept only as long as needed to handle the request and maintain a useful support history.

Your rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data, and to withdraw consent for optional communications. California and other US state privacy laws may also give you rights to know, delete, correct, limit certain sensitive-data uses, opt out of sale or sharing, and not be discriminated against for using your rights.

Autoplot does not sell personal information and does not share personal information for cross-context behavioral advertising. To make a request, email [email protected]. We may need enough information to verify that the request is yours.

Children and sensitive data

Autoplot is built for scientific and professional use. It is not directed to children under 13, and we do not knowingly collect children's personal information.

Please do not put patient data, secrets, credentials, export-controlled information, or other sensitive data into assistant prompts unless you have confirmed that your use is lawful and appropriate for a hosted AI service.

Security and contact

We use local storage boundaries, authenticated backend requests, provider-side access controls, and limited diagnostic logging to reduce unnecessary exposure. No system is perfect, but the product is designed so normal scientific datasets do not need to become website uploads.

Questions, deletion requests, and privacy requests: [email protected].

Ready when you are