PliumPic: Privacy Policy


1. Purpose and scope

1.1 The provider of PliumPic (the "App") and the party responsible for this policy is:

Lukas Usinskas
c/o Postflex PFX-955-773, Emsdettener Str. 10, 48268 Greven, Germany
Phone: +49 151 28169018
Email: info@pliumpic.app

(the "Developer", "we", "us").

1.2 This policy is the information the GDPR requires us to give you (Art. 13 and 14 GDPR). It explains what personal data we process, why, on what legal basis, and what rights you have. For that data, the Developer named in 1.1 is the controller (Art. 4(7) GDPR). This policy does not cover what Apple does when you buy PliumPic+ (Section 9), or what other participants do with what reaches their devices (Section 8). It stands alongside our Terms of Use (https://pliumpic.app/terms) and is not part of them.

2. How PliumPic works, and what happens to your personal data

2.1 There is no PliumPic server and no account. Photos and videos move from one participant's device to another's, over a connection that is encrypted between those two devices. Nothing passes through infrastructure operated by us, because there is none.

2.2 How a trip works. You create a trip, or join one by scanning its QR code. Your device then looks through your own photo library for media taken during that trip's time and place, finds the paired devices near you, checks that each one is the same device you paired with before, and sends the matching media to it. Every one of those steps happens on your device and on theirs. What your device sends to the other participants is set out in full in Section 8.

2.3 Media can also reach a participant by way of another participant's device. A device that has received media belonging to a trip may pass it on to other participants of the same trip, so media does not always travel straight from the device it came from to the device that ends up holding it. The membership record described in Section 8 is passed on in the same way (8.4). Every one of those hops runs between participants' own devices, within the trip concerned; none of it passes through us.

2.4 What reaches us: nothing, unless you write to us. The App contains no code that reports anything back to us: there is no server of ours for it to report to. The only personal data we ever process is what someone sends us if they get in touch, described in Section 3.

3. What information we collect, for what purposes and on what legal bases

3.1 In ordinary use of the App, no personal data about you reaches us. Creating trips, pairing devices, syncing media, and buying PliumPic+ all complete without any personal data being transmitted to us, for the reason given in 2.1.

3.2 If you contact us, we process what you send. Whenever you choose to reach out to us - by email, by exporting and sending diagnostic logs (5.4), or by sharing anything else with us in any other way - we process the personal data contained in what you sent:

We do not ask you for personal data beyond what you decide to send, and you are under no obligation to send us any. If you send us nothing, we simply cannot answer you; there is no other consequence.

3.3 What we do not collect. No analytics, advertising identifiers, location data, contact information, or usage telemetry reaches us. There is no tracking, no advertising, and no sale of personal data. We do not profile you and take no decisions about you by automated means (Art. 22 GDPR).

4. How we collect your personal data

4.1 Every piece of personal data we hold came directly from you, at the moment you chose to send it. We receive none from business partners, service providers, advertising networks, data brokers, or any other third party, and none from the App itself. We operate no sign-up, no web form, and no support portal that could gather anything in the background. The one exception is personal data about you that someone else includes in what they send us; 12.8 covers it.

5. Information stored on your device

5.1 Your content and profile. Your display name, your trips and their settings - including each trip's dates and the place and map area it matches - the devices you have paired, and the photos and videos you sync are stored on your own device.

5.2 Your PliumPic+ status. If you have PliumPic+, your device stores whether the membership is active and, for the annual subscription, the date it is paid through. Your device works this out for itself from the purchase confirmation Apple sends it. It is never sent to us.

5.3 A security key that identifies your device. So that the people you pair with can tell your device apart from every other device, the App gives your device a private security key. iOS holds that key in protected storage on the device, in a form that cannot be copied off it: not by us, not by other apps. Its only job is to prove to the devices you have paired with that yours is still the same device. The App also remembers a matching public identifier for each device you paired with, so it recognises them next time, and those devices remember yours in the same way. None of it is sent to us.

5.4 Diagnostic logs. The App writes technical notes on your device to help work out why a sync failed. They stay on your device, and reach us only if you deliberately export them and send them to us - in which case they are handled as described in 3.2.

5.5 What deleting the App removes - and what survives it. Deleting the App removes your trips, your paired-device list, your display name, and its logs. It does not remove the photos and videos you received: those were saved into your photo library (6.1), and they stay there until you delete them in the Photos app. Two things are deliberately left behind in the device's protected storage: the device identifier described in 8.3 and the security key described in 5.3. They stay so that reinstalling the App does not make your device look like a brand-new one to people you have already paired with; without them, every existing pairing would be stranded. Neither identifies you personally and neither is sent to us. The App offers no way to remove them separately; they are cleared when the device itself is erased.

6. Permissions the App asks for

6.1 Photos: to find media taken during a trip's time and place, and to save media received from other participants.

6.2 Local Network and Wi-Fi Aware: to discover and connect to nearby paired devices for direct transfer.

6.3 Camera: to scan a trip's QR code when joining.

6.4 A permission you give the App is not access you give us. Each permission is granted to the copy of the App running on your own device, and it stops there. Allowing access to your photo library lets that copy look through your photos to find the ones belonging to a trip; it gives the Developer no ability to see them. We cannot open your photo library, view your photos or videos, use your camera, or reach anything else on your device. Neither the permission nor what it unlocks travels to us.

Each permission is used only to provide syncing and can be changed at any time in iOS Settings.

7. Who else receives your personal data

7.1 We disclose your personal data to no one for their own purposes, and we sell it to no one. No analytics processors, advertising networks, or affiliated companies receive data about you: in ordinary use of the App there is none to pass on (2.4).

7.2 The providers we rely on. What you send us passes through the providers we use to receive it: our email provider, which stores and transmits your email, and our mail-handling provider, which receives post sent to the address in Section 1 and scans it for us. A third provider hosts the website where this policy and our Terms are published, and the page a trip invite opens; visiting any of its pages leaves the usual entry in its server logs, including your IP address, kept for a short period so that the pages can be delivered and the site kept secure - our legitimate interest in operating it (Art. 6(1)(f) GDPR). All of them act only on our instructions and for no purpose of their own, under the contracts Art. 28 GDPR requires. We name them on request (Section 15).

7.3 Otherwise your correspondence (3.2) stays with us, unless the law requires us to disclose it or we need it to bring or defend a legal claim.

7.4 Apple is the only company that ends up with data about your use of PliumPic, and only because it sells PliumPic+ and takes the payment. Apple gets that data from you through the App Store, never from us, and we never see it. Section 9 sets out what Apple handles and what we do and do not receive back from it.

7.5 Between participants, you are the one sharing, not us. What travels from your device to the other participants of a trip is set out in full in Section 8. It goes at your initiative and only to the participants of trips you take part in - reaching some of them by way of another participant's device (2.3) - and never through us.

8. What your device sends to the other participants of your trip

8.1 What travels. Two things go from your device to the other participants of a trip: the photos and videos that match that trip's time and place, and your display name, which is how they see who sent what. The trip's own details travel with them: its name, its place and map area, and its dates - so that every participant's device matches the same trip. The media goes as the originals your camera made, which means the information your camera stored inside each one, including where and when it was taken, goes with it. If you have PliumPic+, one further item travels: a small record showing that a membership exists, set out in 8.2 to 8.6. Nothing else leaves your device on its own.

8.2 Why the membership record is shared at all. A trip may hold 5 devices, or 25 if any of its participants has PliumPic+ (Terms, Section 13). With no server, every device has to work that limit out for itself. The only way another participant's device can arrive at the same limit as yours is to know that a membership exists in the trip.

8.3 What the membership record contains. For each trip you take part in, your device sends the other participants a small record - a boost - containing:

Your name is not part of this record. It becomes attached to it only on devices that already know you as a participant of that trip.

8.4 Who receives it, and how far it travels. Only participants of trips you are in. Devices exchange a trip's entire set of these records rather than individual changes, so your record can reach a participant your device never connected to directly, having been passed on by another participant of the same trip. It is never sent to us, and it does not travel outside the participants of that trip.

8.5 What other participants can see. In a trip's device list the App may display "Boosted by" followed by a first name: the first name of the participant whose membership raised that trip's limit, or "you" on that participant's own device. It is shown only where a participant other than the trip's owner is the one raising the limit. The paid-through date and the signature are not displayed to anyone; they are used only for the calculation and the check.

8.6 Ending a membership marks the record inactive - it does not delete it. When your PliumPic+ ends, your device does not remove the record from the trip. It sends a replacement marked inactive. This is a technical necessity rather than a choice: where devices merge each other's data with no central authority, a deletion cannot reliably propagate, whereas a record marked inactive can. In practice the entry - including your device identifier - stays part of that trip's data on the other participants' devices, marked as no longer contributing.

8.7 What you control, and what you cannot take back. You control what you share, which trips you take part in, and whether you hold PliumPic+ at all. You do not control the copies that have already arrived: once a photo, a video, your display name, or the membership record has reached another participant's device, it is on their device and under their control. The App has no message that reaches into someone else's device to delete data, and we have no means of doing so either, because we have no access to their device. Deleting a trip on your own device removes that trip and its participants from your device only, and their copy goes when they delete that trip. The photos and videos the trip brought you stay in your photo library until you delete them there (5.5). This follows directly from having no server, and it is why the Terms describe sharing as trust-based.

9. Purchases and Apple

9.1 Apple processes the purchase, we do not. PliumPic+ is sold through the App Store. When you buy it, Apple handles the transaction using your Apple Account, your payment method, and your purchase history, under Apple's own privacy policy (apple.com/legal/privacy) - not this one.

9.2 What we never receive. We do not receive your payment details, your Apple Account, your name or email address from the purchase, or any identifier that would let us recognise you as an individual buyer.

9.3 What we do receive. Apple provides developers with aggregated sales and subscriber reports: totals such as units sold, revenue, and subscriber counts by country and period. These are statistics, not records about you, and they do not identify you.

9.4 The membership record is not your purchase data. What your device sends to other participants under Section 8 is a record that a membership exists. Apple's purchase data itself stays on your device (5.2) and reaches neither them nor us.

10. International data transfers

10.1 Where our providers process your data. The only personal data we hold is correspondence sent to us (3.2, 12.8), and it passes through the providers described in 7.2. We choose providers established in the European Union or the European Economic Area wherever we can, but we cannot rule out that one of them, or one of their own subprocessors, processes data in a third country. Where that happens, the transfer takes place on the basis of an adequacy decision of the European Commission (Art. 45 GDPR) or of standard contractual clauses together with any additional measures required (Art. 46 GDPR).

10.2 You may ask us at the address in Section 15 which providers we use, where they process, and for a copy of the safeguards that apply.

10.3 Transfers between participants are not ours. Media and the items listed in Section 8 travel between participants' own devices, wherever in the world those participants happen to be. Those transfers are made by you and by them; we neither carry them nor have any means of doing so (2.1).

11. How long we keep your personal data

11.1 On your device, your trips, media, profile, and logs stay for as long as you keep them. We set no retention period for them, because we neither hold them nor can reach them.

11.2 Correspondence you send us is kept for as long as it takes to deal with the matter you raised, and after that only where a legal, tax, or accounting obligation requires it, or where we still need it to bring or defend a legal claim. Once neither applies, it is deleted.

12. Your rights

12.1 Removing your own data. You remove it by deleting trips, unpairing devices, or deleting the App (5.5), and by deleting received photos and videos in the Photos app. What has already reached another participant's device is beyond that reach, for the reasons given in 8.7.

12.2 For your purchase, the controller is Apple. Requests concerning your Apple Account, payment data, or purchase history go to Apple, through privacy.apple.com or Apple's privacy contact.

12.3 For data on other participants' devices, each of those participants holds their own copy. Where they use the App for personal and private purposes, this is generally treated as a household activity (Art. 2(2)(c) GDPR), which takes it outside the GDPR's controller obligations. We cannot act on such data in any event: we have no access to it and no ability to reach it.

12.4 From us, you have the full set of GDPR rights, in respect of the only personal data we ever hold, which is your correspondence (3.2):

For the reasons set out in this policy, we hold nothing else. Write to us at the address in Section 15.

12.5 Your right to object. We process your correspondence on the basis of our legitimate interest (3.2). You may object to that processing at any time, on grounds relating to your particular situation. We then stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless we still need the data to bring or defend a legal claim (Art. 21(1) GDPR). We send no direct marketing.

12.6 How we handle your request. Exercising these rights costs you nothing (Art. 12(5) GDPR). Because we run no accounts, we may ask for what we need to satisfy ourselves that a request comes from the person whose data we hold, and no more (Art. 12(6) GDPR).

12.7 Consent and automated decisions. We rely on no consent, so there is none for you to withdraw (Art. 7(3) GDPR); the permissions the App asks for are given to iOS, not to us (6.4). We take no automated decisions about you and do not profile you (3.3).

12.8 If your data appears in someone else's message to us. Where what someone sends us contains personal data about you - in the text, in an attachment, or in a diagnostic log - the rights above are yours as well. We process it for the same purpose and on the same basis as the rest of the message: answering the person who wrote to us, on our legitimate interest (3.2). We normally have no way of reaching you to tell you that we received it, which is why Art. 14(5)(b) GDPR replaces that duty with publishing this notice. The data goes when the correspondence it arrived in is deleted (11.2).

12.9 Complaints. You may complain to a data protection supervisory authority - in the Member State of your habitual residence, of your place of work, or of the place where you consider the infringement to have occurred (Art. 77 GDPR).

13. Children

13.1 PliumPic is not directed to children under 16, and our Terms of Use require you to be at least 16 years old to use the App. As set out in Section 3, the App collects no personal data from anyone, children included.

13.2 Ask to Buy. If a child in a Family Sharing group tries to buy PliumPic+, Apple sends the request to the family organiser for approval and the purchase completes only if it is approved. That flow belongs to Apple; we receive no information about the request, the approval, or the people involved. The App only ever learns that a purchase is awaiting approval on that device.

14. Changes to this policy

14.1 We may update this policy when the App changes or when the law requires it. The current version is always available at https://pliumpic.app/privacy and in the App under Settings → Privacy & Terms. Where a change is material, the App presents it together with the amended Terms of Use and asks you to confirm it before you can continue; the App as a whole stays unavailable until you do (Terms 19.2). This policy informs you about what happens to your data; it is not a contract term. Confirming it creates no obligation for you and does not affect the rights in Section 12, which you may exercise at any time.

15. Contact us

Questions about this policy, and any request concerning your data, should be sent to info@pliumpic.app. We are not required to appoint a data protection officer (Art. 37 GDPR, § 38 BDSG) and have not appointed one.


Contact: Lukas Usinskas · c/o Postflex PFX-955-773, Emsdettener Str. 10, 48268 Greven, Germany · +49 151 28169018 · info@pliumpic.app

This document was drafted with AI assistance and reviewed, approved and assumed responsibility for by a human reviewer.