CLOSED BETA · PRIVACY
Privacy Notice
This notice explains what PLOTPLUME STUDIO collects during the closed beta, why it is used, and the choices available to invited testers in Israel and the United States.
Effective 6 September 2026
1.Who operates the beta
PLOTPLUME STUDIO, formerly presented as WITNESS STUDIO, is currently operated by Gil Naparstak, an individual based in Israel (the “Operator,” “we,” or “us”). It is not yet operated by a company.
This notice applies only to the invitation-only beta for adults aged 18 or older in Israel and the United States.
2.Information we collect
- Account information: the signed-in identifier, name and email address supplied through the authentication service or a private beta invitation.
- Invitation and session records: invitation status, expiry and acceptance times, plus one-way hashes of single-use invitation and session tokens. Passwords are stored only as uniquely salted, deliberately slow hashes; raw passwords and raw tokens are not stored.
- Campaign attribution: when you open a Plotplume campaign link, we count the visit and place a first-party cookie containing random identifiers for up to 30 days. We store only a one-way hash of the visitor identifier, the campaign and platform, visit times and counts, and whether a beta invitation was later accepted in the same browser. We do not store an IP address, email address, browser fingerprint or device profile in this campaign record.
- Project content: titles, scripts, scenes, shots, prompts, notes, settings and other production information you save.
- Private media: images, videos, filenames, file types, sizes and attachment relationships.
- Optional AI Help: when you choose to ask for help, your question and a limited summary of the current screen are sent to OpenAI to generate an answer. This feature does not send the full project. Plotplume does not store the question or AI response as a transcript or product telemetry. AI Help sets the OpenAI Responses request not to store response application state. Under OpenAI's default API data controls, abuse-monitoring logs may contain submitted content and may be retained for up to 30 days unless different approved data controls apply. OpenAI does not use API content to train its models unless the customer explicitly opts in. Do not include sensitive or confidential information in an AI Help question.
- Usage records: storage totals, project counts and actions needed to operate, protect and troubleshoot the service.
- Feedback and requests: messages, category, current page and basic browser/device information submitted through Feedback.
- Legal records: the versions of these documents you accept, the time of acceptance and associated browser information.
3.Why we use information
- Provide the private workspace, media storage, exports, restore tools and scene-review features.
- Authenticate users and keep each creator’s projects separated.
- Understand which of our own campaign links lead to visits and invitation acceptance, using first-party aggregate measurements.
- Measure beta limits and maintain service reliability and security.
- Respond to feedback, privacy requests and technical problems.
- Improve the beta and establish or defend legal rights.
4.Choice and consequences
Providing information is voluntary and is not required by law. However, the signed-in account information and acceptance record are necessary to enter the private beta. Project content and media are required only when you choose to use the relevant features.
If you do not provide required account information or accept the current documents, you cannot use the signed-in beta.
5.Sharing and service providers
We may disclose information to hosting, authentication, storage, security and technical service providers only as needed to operate the beta. When you choose AI Help, OpenAI receives your question and the limited screen context described above to generate the answer. We may also disclose information when required by law or a valid legal process; to protect users, the service or legal rights; or as part of a future organizational transaction subject to appropriate notice and safeguards.
We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising. Campaign attribution is handled by Plotplume on its own domain and is not sent to an advertising network.
6.International processing
The service and its providers may process information in Israel, the United States and other locations where the relevant infrastructure operates. Privacy protections may differ between countries. We select and configure providers with the aim of applying appropriate security and contractual protections, but no cross-border system is risk-free.
7.Retention and deletion
- Account and project information is generally kept while the beta account exists.
- The campaign attribution cookie expires after 30 days. Aggregate campaign records may be kept while needed to evaluate the beta and can be removed with the associated campaign.
- Deleting a project removes its project data and associated private media through the available deletion process.
- Deleting the account removes the profile, projects and private media. Acceptance records, limited security records or information needed for legal obligations may be retained where necessary and permitted.
- Feedback is retained while it is useful for follow-up and may be resolved or removed by the Operator.
- Incomplete uploads and operational logs may be retained temporarily for security and reliability.
Download the available HTML report before deletion if you want a readable copy; media files are not included in that report.
8.Your choices and rights
Depending on applicable law, you may have rights to request access, correction, deletion or information about the handling of your personal information. The workspace also provides project deletion, account deletion and a downloadable account report.
Select Privacy or data request in the signed-in Feedback form. If you cannot sign in, write to support@plotplume.com. We may need to verify identity before acting on a request.
United States residents may have additional state-law rights where the relevant law and business thresholds apply. We will not discriminate against a user for making a valid privacy request.
9.Security
We use access controls, account separation, private storage patterns, input limits and other technical and organisational measures intended to protect beta information. No online service can guarantee absolute security. Use replaceable test material and avoid uploading secrets, highly sensitive personal information or material whose loss would cause serious harm.
10.Adults only
The beta is not directed to children and is limited to invited users aged 18 or older. Do not upload personal information or media of a minor unless you have all necessary authority and a legitimate production need. If we learn that a child used the beta, we may suspend access and delete the information.
11.Changes to this notice
We may update this notice as the beta changes. A material update may require fresh acknowledgement before further signed-in use. The effective date and recorded version identify the notice that applied when you accepted it.
