Plainscone

Privacy Policy

Effective date: September 1, 2026

Overview

Plainscone is a private messaging app. Messages and photo attachments are protected with end-to-end encryption where supported by the app. We collect and process only the data needed to provide account access, messaging, push notifications, attachments, abuse reporting, safety controls, and support.

Data We Collect

  • Account identifiers: user handles, account IDs, passkey-related account records, and profile display names.
  • Device identifiers: APNs device tokens and device registration records used to deliver push notifications.
  • Contacts and social graph: friends, room membership, blocked contacts, and related metadata needed for chat features.
  • User content: messages, photos, attachment metadata, thumbnails, and other content you choose to send or share in the app.
  • Location you choose to share: when you share your location in a chat, the app reads your device's position once, at that moment, and sends it as a message. It is protected the same way other message content is, so we cannot read it. There is no continuous or background location tracking: the app never requests your location while it is in the background, keeps no location history of its own, and asks for nothing until you tap.
  • Reports and safety data: report reason, selected user or room context, and any user-provided report details.
  • Crash and error diagnostics from the app: crash reports, app-hang and unexpected-termination reports, and counters for handled errors. These carry no message content and no account identifiers.
  • Server operational telemetry: traces, metrics, and logs from our servers. Metrics are aggregate counts and timings with no per-user attributes. Logs can include a shortened fragment of an account identifier and the IP address a connection came from.

End-to-End Encryption

Normal chat message content and photo attachment content are designed to be protected with end-to-end encryption. The server routes encrypted data and stores only the information needed to deliver the service. Some metadata, such as account identifiers, device tokens, room membership, delivery state, and attachment transfer metadata, is processed to operate the service.

How We Use Data

  • To create and secure accounts, including passkey-based sign-in.
  • To send, receive, sync, and display messages and attachments.
  • To send a location you choose to share, once, as a message.
  • To deliver push notifications and notification previews.
  • To support blocking, reporting, moderation, and abuse prevention.
  • To troubleshoot errors, protect the service, and respond to support requests.

Crash Reports and Operational Telemetry

The app sends crash reports, app hangs, and unexpected terminations to Sentry, which we use to find defects in the field. These reports are configured to exclude message content and identity: no screenshots, no view hierarchy, no session replay, no user record, no IP address, and no automatic breadcrumbs. Handled errors are reported as a fixed error name and an occurrence count, never the underlying text, handles, or room identifiers. If a build ships without a crash-reporting key, the SDK never starts and no connection is opened.

Our servers send traces, metrics, and logs over OpenTelemetry to Grafana Cloud, which we use to keep the service running. This telemetry is about server operation — connection counts, delivery latency, database timings, error rates. It never contains message content, which the server cannot read. Server logs can include a shortened fragment of an account identifier and the network address a request or connection arrived from.

Tracking and Advertising

Plainscone does not use data for third-party advertising or cross-app tracking. We do not sell personal data.

Sharing

We do not share message content with advertisers, and message content is end-to-end encrypted before it reaches any of the providers below. We use these processors to operate the service:

  • Apple — push notification delivery (APNs).
  • Cloudflare — encrypted attachment storage and site delivery.
  • Fly.io — server hosting.
  • Sentry — crash and error diagnostics, as described above.
  • Grafana Labs (Grafana Cloud) — server traces, metrics, and logs sent over OpenTelemetry.

We may disclose information if required by law or to protect users and the service.

Reports and Moderation

Because normal messages are end-to-end encrypted, Plainscone cannot review ordinary message plaintext unless a user submits a report or otherwise provides content to support. When you report abuse, the selected report reason and relevant user-provided context may be sent for review.

Retention and Deletion

We keep data for as long as needed to provide the service, comply with legal obligations, resolve disputes, prevent abuse, and maintain security. You can request account deletion or support assistance by contacting us at support@plainsc.one.

Contact

Questions about privacy can be sent to support@plainsc.one.