Privacy Policy
Effective date: 7 August 2026 · Written with India’s Digital Personal Data Protection Act, 2023 (DPDP) in mind
Last updated: 6 September 2026
Plotilla, formerly Mythwrites, is a writing and worldbuilding tool operated by Vishal Kundar, trading as Myrmidon Studio (a sole proprietorship registered in India), and published at https://plotilla.com. In this policy “Plotilla”, “we” and “us” mean that operator, and “you” means the person using the service. On a Paddle receipt or payment statement you may see the account name Myrmidon Studios: that is the same business.
The short version
Your manuscripts are yours. We store them so you can reach them from any device, and for nothing else. We do not sell your data, we do not read your writing for product or marketing purposes, we run no advertising or analytics trackers, and we never send your work to an AI model on our own initiative. A run happens only when you start one: Included Mythic AI goes through our server to Together AI, while bring-your-own-key AI goes directly from your browser to the provider you picked. We never see your card details: payments are taken by Paddle, our merchant of record. Delete your account and we delete your projects, your profile and your login, with two exceptions on projects owned by other people that are set out in full below.
What we collect, and why
- Account data: your email address, display name and a password credential. In cloud mode the password is handled and hashed by Supabase Auth and we never see it. We need this to create your account, sign you in, and contact you about the service. Supabase Auth sends account and security email directly, on our behalf: signup confirmation, password reset, and a notice when your email or password changes.
- Sign in with Google: if you create or open your account with Google sign-in, Google gives us the email address and name on your Google account, marked as verified, and we use them as your account email and display name instead of a password. Google learns that you signed in to Plotilla and when. We receive no other Google data: no contacts, no files, no calendar, and no access to your Google account beyond that one-time identity check. You can use an email address and password instead at any time.
- Your project content: manuscripts, chapters, world entries, characters, timelines, lineages, project notes, author notes, CYOA branches, and any images you upload. We store, sync and display it back to you and to collaborators you invite. We treat it as confidential.
- Collaboration data: if you invite someone we store the email address and name you enter for them, the access level you chose, and the state of the invitation, and we email them an invite link. If you accept an invitation, your name and email become visible to that project’s owner.
- Billing data: checkout is not switched on yet, so no billing data is being collected at all. When it is switched on, Paddle will be our merchant of record and will run the checkout. You give Paddle your name, billing country and payment details directly on its checkout, and that information is held by Paddle under its own privacy policy. All we send Paddle is the email address on your account, an internal user id, and which plan you chose. All we get back and store is your plan, the subscription status, the renewal or access-until date, the Paddle subscription reference, and a note of which payment provider that subscription belongs to. We never see or store your card, UPI or bank details.
- Support data: the name, email, subject and message you send through the support form, plus the project name if you attach one. We use it to answer you.
- Feedback data: the account email and display name the report is filed under, plus the kind, title and body of what you send through the Feedback page, and, where present, the page you were on, the project name you attached and your browser's user agent string. We use it to fix bugs, evaluate ideas and decide whether to grant complimentary access as a thank you. Deleting your account strips the email, name, page, project name and user agent from a report you sent, but not its title or body, since that free text is the report itself; see “What deleting your account actually does” below. If you want a feedback report to stay anonymous even after account deletion, avoid putting anything identifying in its title or body.
- Technical and security data: Fly.io and the network path to the application receive ordinary web request metadata such as IP address, browser user agent, requested path and timestamp. Plotilla also temporarily processes the trusted client IP for rate limiting, abuse prevention and Paddle webhook source checks. Some IP-derived rate-limit keys are stored in Supabase and old rows are removed opportunistically after their security window, so we do not promise an exact deletion deadline. We do not use this information for advertising, analytics, behavioural profiling or device fingerprinting.
- Browser demo mode: when cloud sync is not configured, everything stays in your own browser’s storage and never reaches our servers. Demo mode also keeps a salted hash of your demo password in that browser. It is there to let you try the product, not to protect anything valuable.
We do not collect your date of birth, government ID, location, contacts, or any biometric data. We set no advertising or analytics cookies. Your sign-in session is held in host-scoped Supabase SSR cookies. In production they are Secure and SameSite=Lax; they are intentionally not HttpOnly because the browser Supabase client maintains the session. Legacy Supabase localStorage auth data is cleared during migration; local demo/project state may still use browser storage.
Where your work is stored
Project content is stored as structured data in a Postgres database hosted by Supabase in the Northeast Asia (Tokyo) region, protected by row-level security so that only you and the collaborators you invited can read it. Images go into a private bucket and are served through short-lived signed links rather than public URLs. The application is served through Fly.io in production.
That region is in Japan, so your data is stored and processed outside India. We are telling you plainly rather than leaving it to be inferred: if you would rather your writing not leave the country, this is the point to decide, and you can export everything and close your account at any time. As at the effective date of this policy the Indian government has not restricted transfers to any country under the DPDP Act. If we move the database to another region we will say so here before the move.
Who else touches your data
This is the complete list of processors we use. We name them individually, rather than by role, so you can go and check them yourself.
- Supabase: authentication, database and image storage. Holds your account data and all project content.
- Google: identity provider for Sign in with Google only, and only if you choose that way to sign in. It receives the fact that you are signing in to Plotilla and returns your Google account email and name, as described under Account data above. Google handles that sign-in under its own privacy policy. If you use an email address and password, Google receives nothing.
- Fly.io: the active production application host. It sees request metadata including IP address and processes your content in transit.
- Paddle: payments, as our merchant of record. It is the seller for your subscription, so it runs the checkout, holds your payment method, charges you, issues the receipt and handles refunds. It receives your account email address, an internal user id and the plan you picked from us, and your name, billing country and payment details from you at its checkout. Paddle processes that under its own privacy policy, as a controller of it in its own right rather than only on our behalf.
- Resend or Postmark, whichever is configured: transactional email only, which we send ourselves for collaboration invites; the support and feedback notifications described above, which carry the content of the ticket or report you submitted; subscription-started, payment-succeeded, price-change, payment-failed and cancellation notices; a complimentary-access reward; and the account-deletion farewell. Receives the recipient address and that email’s content, so a support or feedback notification passes your name (or display name), email, message and any page or project name you included through whichever of these two providers is configured. Account confirmation, password-reset and security email is sent directly by Supabase Auth instead, described under Account data above. We send no marketing email.
- Sentry: error monitoring, when an error reporting endpoint is configured. Receives error messages and technical context. We do not send your manuscript text to it.
- Together AI: the model provider behind the AI runs included with Mythic. Receives the prompt and the bounded project, chapter, chat, or imported-document context of a run you start, forwarded by our server on our own key. It is in the United States and handles what we send it under its own API terms. Nothing goes to it unless you explicitly run an AI feature on the included provider.
- The AI provider you choose, if you choose one: see the AI section below. That is a transfer you make from your own browser with your own key, not one we make for you.
There is no other payment processor in this list, and no second one is taking your money today. If we ever add or change one we will name it here before it receives anything, and an existing subscription stays with the provider that created it.
We use no advertising networks, no analytics platforms, no session recording tools and no data brokers. We do not sell, rent or share your personal data or your writing with anyone for their own purposes.
AI features: exactly what leaves your device
AI assistance runs one of two ways, and which one you pick changes where your writing goes. The provider selector on the AI page is where you choose, and it is set per project.
Included with Mythic. A run on the Plotilla AI provider goes to our server, which forwards it to Together AI on our own key and hands you back the answer. Together AI is in the United States and processes it under its own API terms. Our server does not store what it forwards or what comes back: neither the context nor the answer is written to a database, a log or an error report, and nothing of the run survives the response.Mythic includes fifteen of these runs a day.
Your own key. Right now that means OpenAI or Anthropic: you paste an API key for one of them. The AI settings page also has a local/custom-endpoint field, but our current browser security policy (the Content-Security-Policy that limits which addresses this browser may call) only allows OpenAI, Anthropic and our own processors, so a custom endpoint there does not work in production today. That key stays in this browser session, is cleared when the session ends or you sign out, is stripped out of every save, sync and export, and is never sent to Plotilla’s servers. On this path your browser calls the provider directly: the request does not pass through our servers, so we cannot see, store or log your prompts or the model’s replies. Plotilla does not apply the fifteen-runs-a-day Included-AI quota to this path; your provider’s own rate limits, usage limits and charges apply instead. You may need to enter the key again after the browser session ends. This is the path to use if you would rather we were not in the middle of it at all.
For assistant, continuity-review, and chat runs, the request carries a bounded context from the project you have open:
- the project name and description;
- every character, with their role and the opening of their personality and backstory notes;
- every world entry, with the opening of its description, and for magic systems the full rules, limitations and costs;
- every timeline event, with the opening of its description;
- chapter title, word count, revision state and lock state, plus up to roughly 200 characters per chapter at project scope, 1,600 per chapter in the selected book, or 12,000 characters from the selected chapter at chapter scope;
- the instruction you typed and, in chat, a bounded recent thread.
A short selected chapter can therefore be sent in full; a longer one is clipped at the stated limit, and the total context is also capped. Author-note bodies are excluded. Smart Import sends numbered source paragraphs, up to its displayed context limit, only when you explicitly choose Extract lore; the original file is not retained. If part of your work is confidential or under embargo, review the displayed scope and provider before starting a run. The classic consistency, plot-hole and description tools can use a local heuristic when a bring-your-own-key provider has no key; continuity review, chat, and lore extraction do not send anything and ask you to add a key or choose Included AI.
On training. We never use your manuscripts, worlds or characters to train any AI model, and we never grant anyone else a licence to them for that purpose. On the included path, what Together AI may do with what we forward is governed by Together AI’s own API terms, not by this policy. On your own key, what the provider you chose does with your text is governed by your contract with that provider, not by this policy. OpenAI and Anthropic both state that content submitted through their APIs is not used to train their models by default, but that is their promise to you rather than ours, and you should read their current terms before sending anything sensitive.
Our lawful basis
In practice, we process your personal data on the consent you give when you create an account and accept our terms, and to act on requests you make to us or meet a legal obligation, such as keeping payment and tax records. India's DPDP Act sets out a framework for lawful processing along these lines. The Digital Personal Data Protection Rules, 2025 were notified in November 2025 and bring the Act into force in stages: the Data Protection Board provisions started first, and the substantive rules on notice, consent and a data fiduciary's duties are scheduled to commence later. We describe our actual practice here rather than asserting that a specific not-yet-commenced provision already governs us. You can withdraw consent at any time by deleting your account. Withdrawal does not undo processing that already happened, and it does not erase records the law requires us to keep.
Your rights
India's DPDP Act sets out rights along these lines in Sections 11 to 14, and the Act is being brought into force in stages: not every substantive provision is operative yet. Rather than wait for commencement, we give every user the practices below now, wherever you live. Export and portability in particular are capabilities we built into the product, not a claim about what any specific law currently requires of us.
- Access and portability. The Export page downloads the project you have open as DOCX, EPUB, PDF, Markdown, plain text, HTML or JSON, and if you own the project, as a complete Plotilla archive that includes its images. Export runs one project at a time, so a writer with several exports each one. For a copy of everything else we hold about you, including your profile and support history, email us and we will send it within 30 days.
- Correction. Change your name and email in account settings, or ask us.
- Erasure. Profile, then Delete account. The next section sets out exactly what that removes.
- Nomination. You may nominate someone to exercise these rights for you if you die or become unable to exercise them yourself. Email us the nominee’s name and address and we will record it. For a writer this matters more than usual: tell your nominee that your drafts live here.
- Grievance redressal. See Contact below. We acknowledge within 3 working days and aim to resolve within 30 days.
Billing records are the one place to ask twice. Paddle holds your payment details as the seller, so a request to see or erase those goes to Paddle as well as to us, and we will tell you what we hold and point you at them for the rest.
The Act also places duties on you, including not raising false or frivolous complaints and not impersonating anyone else when you give us personal data.
What deleting your account actually does
In cloud mode, deleting your account:
- first asks the payment provider to cancel any live subscription, so no further payment can be taken. That cancellation is immediate rather than end-of-period, because there is no longer an account to serve for the rest of the month. We ask before we delete anything, and if the provider cannot be reached we still delete your account, tell you so on this screen, and flag it for a person to finish by hand;
- deletes every project you own, and with it all chapters, world entries, characters, timelines, notes and that project’s collaborator list;
- deletes every image in projects you own from the private storage bucket. Images you uploaded into somebody else’s project stay with that project unless its owner or support removes them;
- deletes your support tickets;
- strips your name, email address, page, project name and browser details from any feedback you sent us, and unlinks it from your account. The report itself stays, because by then it may already have changed the product for everybody else, but its title and body are not touched: they are the free-text report itself, and we have no reliable way to strip identifying content out of prose without either mangling the feedback or missing something. If you want a report gone entirely rather than just unlinked, or wrote something in its title or body that you would not want to remain after deletion, email us and we will remove it by hand;
- deletes your login from the authentication system, and with it your profile row, including your subscription record. This is the last step, because once the login is gone nothing can be retried.
Two honest exceptions for somebody else’s project. If you accepted an invitation, your name and email stay on its collaborator list until the owner removes you or deletes the project. Images you uploaded into that project stay with its work too. Ask us and we will remove either for you.
Deleting your Plotilla account does not by itself erase the records Paddle keeps as the seller of your subscription, which it holds for its own tax and accounting obligations. Ask Paddle directly about those.
If any part of the deletion fails, we tell you so on the spot rather than reporting success. Should the subscription cancellation be the part that fails, your account is still deleted and we say so, and you should contact us or Paddle so the subscription is stopped.
Deletion is immediate and cannot be undone, so export anything you want to keep first. In browser demo mode there was never a server copy, and deleting simply clears that browser’s storage.
Retention
We keep your account and project data for as long as your account exists, because that is the service. After deletion we retain nothing except records the law requires, principally payment and tax records for the period Indian tax law prescribes, and any correspondence needed to defend a legal claim. What we hold of a payment is the plan, the dates and the Paddle reference; the transaction record itself is Paddle’s and is kept by Paddle. Database backups may hold residual copies for a short period before they roll off.
Security
Everything travels over HTTPS. Database rows are protected by row-level security policies, so one account cannot read another’s projects. Uploaded images sit in a private bucket reached only through expiring signed links. AI keys never reach our servers. Card details never reach them either, because the checkout is Paddle’s and not ours. If a personal data breach happens we will tell you and the Data Protection Board of India without waiting to be asked, consistent with the breach-notification approach in the DPDP Act regardless of which of its provisions have come into force at the time.
Being straight with you: this is a small independent product, not a bank. We offer no security guarantee, and you should keep your own copies of anything you cannot afford to lose. The Export page is there for exactly that.
Children
Plotilla is for adults. You must be 18 or older to create an account. We do not knowingly collect data from children, we do not track or profile children, and we run no advertising directed at anyone. If you believe a child has created an account, tell us and we will delete it.
If you are outside India
Plotilla is operated from India and this policy is written to India's DPDP framework, which stays our home privacy framework no matter where you live. That does not shrink your rights: if you are in the European Economic Area, the United Kingdom, California, or anywhere else with its own data protection statute, we extend the same voluntary rights described above to you, regardless of whether that statute has commenced or applies to us: access, correction, deletion, portability, and the right to complain. Beyond that, we do not claim to comply with every country's privacy law, and nothing in this policy should be read as a certification that we do. Where mandatory privacy law applicable to you in your own country gives you a right this policy does not already describe, that mandatory right is not affected by anything here: write to the contact below and we will handle it. We do not sell personal information as California law uses that term.
Changes to this policy
If we change this policy in a way that materially affects you, we will email the address on your account and show a notice in the app at least 14 days before the change takes effect, so you have time to export your work and leave if you disagree. The effective date at the top always tells you which version is current.
Contact and grievances
Grievance officer under the DPDP Act: Vishal Kundar, reachable at support@mythwrites.com. Write there for any privacy question, to exercise any right above, or to complain. We acknowledge within 3 working days.
If we do not resolve your complaint to your satisfaction, you may take it to the Data Protection Board of India.