Updated on
Privacy policy
How we handle data on the website, in the apps and in the Plomi service. Your personal memories and the content you choose to share have different purposes and visibility.
Contact supporthelpdesk@bitwe.pt1. Controller and contact
Bitwe Lda, Portugal, is the controller for Plomi data. Contact for privacy, support and reports: helpdesk@bitwe.pt. Postal address: Rua Pires Jorge 5, 1600-577 Lisboa, Portugal.
2. Data and purposes
We process your email, account identifier, sign-in methods, sessions and acceptance records to authenticate and protect your account. Apple or Google provide identifiers and, when available, an email if you choose those methods. We do not receive your password for those services.
We store the places, statuses, notes, lists, visits, ratings and photos you send to provide and synchronise your archive. A local copy for each account helps recover pending changes. Invitee addresses, invitations and permissions are used to carry out sharing you request.
Optional invoice scanning processes issuer/tax identifier, document, date, total, validation status and place association. The scanner does not upload the buyer’s tax identifier, invoice image or raw QR code. A photo you voluntarily attach to a visit is handled as a visit photo. Avoid including unnecessary personal or fiscal details.
3. Private and shared content
Publishing a visit requires confirmation and acceptance of the Plomi Community terms. Its public name, place, date, text, rating and photos become available to other people on Plomi. You can edit, make private or delete the visit. Sharing a list does not automatically publish personal notes, visits or invoices.
Uploaded photos are processed to remove metadata, including location. This does not remove information visible in the image. Stopping sharing revokes new access after server confirmation, but cannot retrieve copies made by others. Invoices and their data remain private.
4. Location and providers
Location is optional and requested after your action, with no background tracking. Authorised searches and coordinates pass through Plomi to the Google services needed for search. Place details and images are stored in a catalogue separate from your archive. Google maps may receive IP addresses, technical device data, diagnostics and map interactions according to configuration and provider policies.
When you request an AI category suggestion, only your chosen name is sent to the server and OpenAI. This feature does not send your archive, notes, visits, photos or invoices. You review a suggestion before applying it. API data is not used for training by default; provider security logs may exist, usually for up to 30 days, so we do not promise zero retention.
Infrastructure, backups and messaging needed for Plomi are managed by Bitwe and technical providers supporting the service. Apple, Google and OpenAI may process data outside the European Economic Area. Transfer arrangements depend on the service, country and applicable terms, including adequacy decisions or contractual clauses where required. Ask our privacy contact for information about recipients and safeguards.
5. Grounds for processing
Your account, archive, synchronisation and requested sharing provide the service you ask for. Optional publication, location and AI text sharing rely on your authorisation, which you may withdraw for future use. Security, abuse and duplicate-invoice prevention and request handling rely on our legitimate interest in protecting the service and people. We comply with legal obligations where applicable. We do not sell your archive or use it for behavioural advertising.
6. Retention and deletion
Content remains associated with your account while you keep it. Confirmed account deletion removes the personal archive, visits, photos, invoices and sessions from active systems. Document fingerprints without an account association may remain to prevent duplicates, along with validation records needed for catalogue integrity. Encrypted material for revoking an Apple connection is removed once revocation finishes.
Support requests and technical records are kept as needed to resolve requests, investigate incidents or meet applicable obligations. Retention depends on purpose, risk and evidential need, not marketing.
Backups have restricted access and are not automatically erased by account deletion. They may contain earlier data while needed for recovery and incident verification. An erasure request includes assessment of those copies and legal exceptions; contact us to clarify the applicable scope and timeframe. We do not promise immediate deletion of every copy.
7. Choices and rights
You can export data, manage visit visibility, leave shared resources, revoke device permissions and delete your account in the app. Signing out does not delete an account. If you cannot sign in, email us; we will check only what is needed to confirm ownership.
You may request access, correction, erasure, restriction, portability or objection, where applicable, and withdraw consent without affecting earlier processing. Email helpdesk@bitwe.pt. You may complain to Portugal’s data protection authority (CNPD) or the competent authority in your country.
8. Website, security and changes
The website does not load advertising or product analytics tools. Its demo contains examples and does not store a personal archive; language is selected in the page address. Servers may log IP, date, route and technical data for operation and security. External links are subject to the destination service’s policy.
We use HTTPS, access controls and account separation. No service can promise absolute security. We do not make solely automated decisions with legal effects about you. Do not include sensitive or other people’s data without need and permission. Contact us if a child has provided data improperly.
Changes are published on this page with an updated date. Changes requiring a new choice or acceptance will be presented through the appropriate app flow.