Privacy Policy

Effective date: 06/12/2026 · Last updated: 06/12/2026

This Privacy Policy explains how Plot Cipher LLC (“PlotCipher,” “we,” “our,” “us”) collects, uses, shares, and protects personal information when you visit our website, create an account, subscribe to a paid plan, or otherwise use our platform and services (collectively, the “Service”). It also explains the rights you have under applicable US state privacy laws.

By using the Service you acknowledge that you have read this Policy. This Policy is incorporated into the Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.

1. Information We Collect

A. Information you provide

  • Account information: email address, name, password (hashed using bcrypt and never stored in plaintext), profile image (if you add one), and chosen subscription tier.
  • Billing information: handled by Stripe Inc.; we receive only your billing email, customer ID, subscription ID, and high-level subscription status. We do not receive or store your full payment card number, CVV, or bank routing details.
  • Content you create: deal notes, outreach log entries, pipeline targets and stage transitions, deal room contents (parcels added, comments posted, members invited), saved searches, watchlists, target bids, uploaded documents.
  • Communications: emails to support, feedback you submit, transcripts of any in-product chat.

B. Information we collect automatically

  • Usage data: pages visited, features used, parcels viewed, scores generated, time of access, action timestamps.
  • Device & technical data: IP address, browser type and version, operating system, device type, screen resolution, language preference, referring URL.
  • Cookies and similar technologies: see our Cookie Notice for the full taxonomy.
  • Approximate location: derived from IP address. We do not use precise GPS location.

C. Information from third parties

  • Stripe: webhook events confirming successful charges, refunds, subscription changes, and disputes.
  • Authentication providers (if SSO is enabled): your verified email and basic profile claims.

D. Property & owner data displayed on the Service

The Service displays parcel records, owner names, entity information, and related property data drawn from public sources including Dallas Central Appraisal District (DCAD), municipal records, FEMA, and third-party providers. Some of this data is personal information about third parties (property owners) who are not PlotCipher users. Section 9 below describes the rights of those third parties.

E. CCPA / CPRA Categories of Personal Information

For California residents, the following categories of personal information are collected (defined by Cal. Civ. Code §1798.140):

  • Identifiers (name, email, IP address, account ID)
  • Customer records (billing email, subscription history) — Cal. Civ. Code §1798.80(e)
  • Commercial information (subscription tier, transaction records)
  • Internet/network activity (pages visited, feature usage, log data)
  • Geolocation data (approximate, from IP)
  • Inferences (computed scores about user preferences and behavior used to personalize the Service)

We do not knowingly collect: biometric information; sensitive personal information as defined by CPRA (SSN, driver's license, financial account credentials, precise geolocation, race, ethnicity, religion, sexual orientation, health information, contents of communications); or personal information of children under 16.

2. How We Use Information

We use the information described above for the following purposes:

  • Provide the Service — authentication, deal-tracking, rendering parcels, generating scores and memos.
  • Billing & transactions — processing subscriptions, refunds, and tax compliance via Stripe.
  • Customer support — responding to your requests.
  • Security & fraud prevention — detecting bot activity, abuse, unauthorized access.
  • Service improvement — aggregated, de-identified analytics on what features are used.
  • Communications — transactional emails (account confirmations, password resets, billing receipts, deal alerts you subscribe to). Marketing emails only with your opt-in and with a working unsubscribe link in each message (CAN-SPAM compliant).
  • AI processing — your prompts and parcel context may be sent to third-party AI providers (e.g., OpenAI) solely to generate Outputs for you; AI providers are contractually prohibited from using your data to train their general models on our paid tiers.
  • Legal compliance — responding to lawful requests, enforcing our Terms, defending claims.

Automated decision-making.The Service produces algorithmic scores (e.g., Investment Score, Upside, Buildability, Acquirability, Exit, Likely Seller, Why Now, and the “Decision Hero” verdict). These outputs do not make decisions that produce legal or similarly significant effects about you. You decide whether to act on any output.

We do not sell your personal information for monetary consideration. See §6 for the broader CCPA/CPRA definitions of “sale” and “sharing” and our position.

3. Cookies & Tracking

We use first-party and limited third-party cookies. The categories we set are: strictly necessary (authentication, session, security), functional (remembering preferences, saved filters), analytics (aggregated usage; we use PostHog with IP anonymization where supported), and (only if explicitly enabled) marketing.

For the full list of cookies set, retention periods, and your opt-out controls, see our Cookie Notice. We honor the “Global Privacy Control” (GPC) signal as an opt-out of non-essential tracking where US state law requires it.

4. How We Share Information (Subprocessors)

We share information with the following categories of service providers, each acting as our processor under written contract:

  • Stripe Inc. — payment processing, billing, subscription management. stripe.com/privacy
  • Amazon Web Services (AWS) — hosting, database (Amazon RDS), object storage (Amazon S3), email (Amazon SES). US-East / US-West.
  • Mapbox Inc. — base maps and geocoding tiles. mapbox.com/legal/privacy
  • OpenAI (or successor provider) — natural-language generation for memos and summaries. On paid tiers, OpenAI is contractually prohibited from using your data to train its public models.
  • PostHog, Inc. — anonymized usage analytics (opt-in via cookie consent).
  • Sentry, Inc. — runtime error and crash diagnostics; configured to scrub PII.

We may also disclose information when required by lawful process, to protect our rights or others' safety, in connection with a corporate transaction (merger, acquisition, sale of assets), or with your direct consent.

An up-to-date subprocessor list is maintained at plotcipher.com/subprocessors and we will provide reasonable advance notice of material changes.

5. Data Retention

Retention periods, by category:

  • Account records: retained while account is active; deleted within 30 days after account closure, except as required by law.
  • Content you create: retained while account is active; you may export within 30 days of closure.
  • Billing records: retained up to 7 years for tax and audit compliance.
  • Server logs: 90 days, rotated.
  • Backups: up to 35 days after deletion in primary storage.
  • Marketing email lists: retained until you unsubscribe.

Some information may persist in backups or aggregated, de-identified form beyond the periods above; we will not re-identify it.

6. Your Rights Under US State Privacy Laws

The following table summarizes your rights. To exercise any right, use the contact methods in §11.

A. All US users — baseline rights

  • Access: request a copy of the personal information we hold about you.
  • Correction: request that we correct inaccurate information.
  • Deletion: request that we delete your account and associated personal information, subject to legal exceptions.
  • Portability: receive a copy of your data in a portable format (e.g., JSON or CSV).
  • Opt-out of marketing: unsubscribe links in every marketing message; you cannot opt out of transactional emails while you have an active account.

B. California (CCPA / CPRA)

California residents have the rights above plus:

  • Right to know the categories and specific pieces of PI we collect, sources, purposes, and recipients;
  • Right to opt out of “sale” or “sharing” of personal information. PlotCipher does not sell personal information for monetary value; however, certain analytics or marketing cookies may constitute “sharing” (cross-context behavioral advertising) under CPRA. You may opt out via our Do Not Sell or Share My Personal Information page, or by enabling GPC in your browser;
  • Right to limit use of sensitive PI — we do not knowingly collect sensitive PI;
  • Right to non-discrimination for exercising your rights;
  • Authorized agent — you may designate an agent to make a request on your behalf; we will require verification.

We will verify and respond to verifiable consumer requests within 45 days (extendable by another 45 days with notice).

C. Texas (TDPSA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Oregon (OCPA), Delaware (DPDPA)

Residents of these states have the rights to:

  • access the personal data we process about you;
  • correct inaccuracies;
  • delete personal data;
  • obtain a portable copy of your data;
  • opt out of (i) targeted advertising, (ii) sale of personal data, and (iii) certain profiling activities that produce legal or similarly significant effects;
  • appeal a denial of any request (we will provide an internal appeal process within 60 days).

Texas residentsmay also use the Texas Attorney General's consumer privacy enforcement process if we fail to respond.

D. How to exercise rights

Submit a request by:

We may verify your identity by matching the information you provide with what we already hold about you. We will not require an account if you do not have one. We will respond to verifiable requests within the period required by your state's law (typically 45 days, extendable). If we deny your request, we will explain why and how to appeal.

7. Sensitive Personal Information

We do not knowingly collect “sensitive personal information” as defined by California, Connecticut, Virginia, or Colorado law. If you choose to upload such information into a deal note or document, you do so at your own risk and we will treat it with the same security as other Content.

8. Children

The Service is intended for users 18 and older. We do not knowingly collect personal information from children under 16. If you believe a minor has used the Service, contact us and we will delete the data.

9. Property Owner Data (Third-Party Personal Information)

The Service displays public real-property data including the names of property owners (individuals and entities) drawn from county appraisal-district records, deed records, and similar public sources. This is personal information about individuals who are not users of PlotCipher (“Third-Party Subjects”).

Our use of Third-Party Subject data is governed by these principles:

  • The data is sourced from public records lawfully made available by government bodies for the purpose, among others, of supporting real estate transactions and public diligence.
  • We display the data only in connection with the parcel it relates to and do not aggregate it for marketing purposes.
  • We do not append non-public PII (phone numbers, email addresses, mailing addresses for individuals beyond what appears in public records).
  • Property owners who believe their information is displayed incorrectly or should be removed may submit a request to mark@tryplotcipher.com with the parcel account number and the basis for the request. We will respond consistent with applicable law.

Users of the Service must comply with the Acceptable Use Policy when contacting owners, including compliance with the TCPA, CAN-SPAM, state Do-Not-Call lists, fair housing laws, and any state laws restricting use of public record data.

10. Security & Breach Notification

We use industry-standard security practices, including TLS in transit, encryption at rest for the database, bcrypt password hashing, AWS Secrets Manager for credentials, least-privilege IAM, audit logging, regular dependency updates, and bug-bounty disclosure via mark@tryplotcipher.com.

No system is perfectly secure. In the event of a personal data breach, we will notify affected users and applicable regulators within the timeframes required by applicable law (in most US states, without unreasonable delay; for “sensitive” data, typically within 30 days of confirmation).

11. International Transfers

Our infrastructure is located in the United States (AWS US-East-1 / US-West-2). If you access the Service from outside the United States, you consent to the transfer of your information to and processing in the United States, which may have different data-protection laws than your country of residence. We do not currently target the EU or UK; if you reside in those jurisdictions and require GDPR-grade processing, please contact us before subscribing.

12. Marketing & TCPA / CAN-SPAM

We only send marketing communications to users who have opted in. Every marketing email includes a one-click unsubscribe link and our physical mailing address (CAN-SPAM compliant).

If you opt in to text-message alerts (when available), you consent to receive automated messages at the number you provide. Message and data rates may apply. Reply STOP to unsubscribe. Frequency varies. Consent to texts is not required to purchase the Service.

13. Do Not Track

We do not respond to traditional “Do Not Track” (DNT) browser signals because no industry standard for response exists. We do honor the Global Privacy Control (GPC) signal where US state law requires (California, Colorado, Connecticut), treating it as a valid opt-out request for sale or sharing of personal information.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated by email at least thirty (30) days before they take effect. The “Last updated” date at the top will reflect the most recent revision. Continued use of the Service after a change constitutes acceptance.

15. Contact Us

Privacy questions and requests: mark@tryplotcipher.com
General support: mark@tryplotcipher.com
Mailing address: Plot Cipher LLC, Attn: Privacy, 5900 Balcones Drive Ste 100, Austin, Texas 78731
Phone (privacy line): 972-514-6637

Attorney review note. Before launch, a licensed privacy attorney should confirm (i) data broker registration analysis in Texas, California, Vermont, and Oregon given our display of owner PII; (ii) state-by-state DSAR workflow design; (iii) the accuracy of our subprocessor list and the contracts in place with each.

Free forever · No credit card

Start finding deals today.