Privacy
What PlexusX stores, what leaves your machine, and what never does.
ČeskyPlexusX — Privacy
Last updated 2026-09-30. Controller: Lucie Uhlířová. Contact: support@plexusx.lol.
This describes what PlexusX actually does, written from the code rather than from a template. If you find something here that does not match the application's behaviour, that is a bug and we want to hear about it.
There are two halves to it: the application on your PC, and the website at plexusx.lol where you sign in and buy. They store different things, and both are described.
The short version
The application never sends us what you do with it: never your settings, your colours, your crash logs, what you play, or anything on your screen.
It does talk to our server, plexusx.lol, on its own. It checks for updates and installs
them, checks that your version and your licence are still allowed to run, and fetches the
shared looks and crosshairs for the Library. While a licence is on your PC, it also checks in
with us about every half hour, so the server can confirm what your plan includes. That
check-in names your licence and your PC. Each of these is listed below, with exactly what it
sends.
Rating an update is switched off in this version. The What's New window offered a thumbs up and a thumbs down; it does not, in the build you are running, and nothing about an update is sent. The section below says how it would work if it is ever switched back on, because a policy that quietly drops a paragraph is harder to trust than one that says what changed.
It does have an account, because that is how a licence reaches your machine. Signing in happens in your browser, once. After that PlexusX checks your licence on your own computer, and the plan check-in keeps what your plan unlocks up to date.
Part one — the application
What is stored on your PC
| What | Where |
|---|---|
| Your colour settings, theme, hotkeys, crosshair, window position | %APPDATA%\PlexusX\settings.json |
| The shared looks and crosshairs the Library last showed you | %APPDATA%\PlexusX\community-presets.json |
| Your licence | %LOCALAPPDATA%\PlexusX\licence.dat |
| The email you signed in with, shown on the Account page | %LOCALAPPDATA%\PlexusX\account.txt |
| The plan check-in's latest signed answer | %LOCALAPPDATA%\PlexusX\entitlement* |
| Per-game colour profiles | %LOCALAPPDATA%\PlexusX\profiles.json |
| Cached status, switch and revocation checks | %LOCALAPPDATA%\PlexusX\*.json |
| Crash reports, and a log of failed licence checks | %LOCALAPPDATA%\PlexusX\crashes\ |
| Screenshots you take with the screenshot key | Pictures\PlexusX |
PlexusX records nothing about a trial on your PC, because there is no trial: with an account, saturation and the Resolution tab are free, and a plan you buy is held with your account. On this machine there is only the licence and the plan check-in's latest answer.
Uninstalling removes the application. To remove the data as well, delete the two PlexusX
folders above and the Pictures\PlexusX folder if you have taken screenshots.
Settings PlexusX changes on your PC
The Customize tab changes Windows' own appearance settings — dark mode, accent colour,
taskbar alignment and transparency. Those live in the registry under
HKEY_CURRENT_USER\Software\Microsoft\Windows, which is where Windows keeps them and where
the Settings app writes the same values. PlexusX changes only what you switch, and turning
something back changes it back.
If Start with Windows is on, PlexusX adds itself to
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. Turning it off removes
the entry.
What leaves your machine
Checks that run on their own. Each goes to plexusx.lol, apart from the one rare case
named in the first. The first four carry nothing that names you: not your account, your
licence or your PC id. The update and status checks do name the version of PlexusX you are
running, which is how we know how many copies of each version are still in use. The server
sees your IP address, as any server does for any request. The fifth is how your plan reaches
the application, and it does identify your licence.
- Update check — when PlexusX starts, and every two hours while it runs, it asks whether
a newer version exists. If one does, PlexusX downloads it, checks it is exactly the file we
signed, and installs it by itself: straight away while it is starting, or later at a moment
when nothing is running full screen. The What's New window then says what changed. Its text
is built into the application; only a build that shipped without it would read it from
GitHub's public API (
api.github.com) instead, naming the version and nothing else. - Status check — when PlexusX starts, and every two hours while it runs: the oldest version still allowed to run, any build we have stopped, any part of the application we have switched off for everyone, and any notice we want to show. It is how you are told when an old build has been retired.
- Licence revocation list — when PlexusX starts, and every five minutes while it runs, so a licence that has been withdrawn stops working. The list contains only one-way hashes, never anybody's licence key.
- The Library — when PlexusX starts, and every three hours while it runs, it downloads the public list of shared looks and crosshairs.
- Plan check-in —
plexusx.lol, only while a licence is installed: when PlexusX starts, straight after you sign in or enter a key, and then about every half hour while it runs. It sends your licence key, your PC id, the application's version and build, and a fingerprint (a one-way hash) of the program file, so the server can say which features your plan includes on this computer. We keep a note of each check-in for 30 days: a one-way hash of the licence key, the version and build type, a code for which features were granted, the program file's fingerprint, and the time. That fingerprint is the same for every unchanged copy of one release, so on its own it tells us which build checked in, not who you are. It lets us count changed copies of PlexusX that run under a real licence.
Reporting a bug
Settings has a box for reporting a bug. Nothing is sent until you press Send. Then
PlexusX sends plexusx.lol what you typed, the email or Discord name you put in the contact
box if you filled it in, the PlexusX version and build type, and these technical facts: your
Windows version, the make of your graphics card, how many monitors you have, whether HDR is
on, whether NVIDIA's own vibrance is available, whether PlexusX is running as administrator,
how each monitor answered PlexusX's colour, which way PlexusX is drawing colour, whether a
game ran in exclusive full screen, and how often and how slowly PlexusX has re-applied your
colour. It does not send your account, your licence key or your PC id.
The report is stored on our server with a code made from your network address that changes every day, so one machine cannot flood us, and it reaches the developer as a private Discord message.
Signing in
When you press Sign in, PlexusX opens your browser and starts a short-lived web server on
127.0.0.1 — your own machine, reachable only from it — so the browser can hand the result
back to the application. It closes as soon as you are signed in, or after five minutes if
you never finish. Nothing else can reach it and it is not open to the network.
Controlling PlexusX from your phone
This one is open to your home network, which is the whole point of it, and it is the only part of PlexusX that ever is. It is off until you open it, and it exists only while that window is open.
When you press Phone on the Display page, PlexusX starts a small web server on this computer and shows a QR code containing its address and a one-time key. Then:
- It only starts when you press that button. Nothing is listening before you do, and closing the window stops it immediately.
- A fresh key every time. Scanning an old code does not work.
- It only answers your own network. A request from anywhere other than this machine or the network the code advertised is refused, as is any request without the key.
- Nothing leaves your house. Your phone talks to this computer directly. No part of it goes to us or to anybody else, and we never learn that you used it.
- It only changes colour. Saturation, vibrance, brightness, gamma, contrast, temperature, highlights, shadows and the scene presets. Nothing else on the machine can be reached through it.
Windows will ask whether to allow PlexusX to use the network the first time. That prompt is this feature, and nothing else in PlexusX needs it.
Discord
If the Discord app is running on this PC, PlexusX shows "PlexusX" as your activity on your Discord profile, with the preset you picked, which can include the game's name. PlexusX hands this to your own Discord app on this computer, and Discord shows it to the people who can see your activity, the same way it does for a game. None of it comes to us. Discord's own settings decide who can see your activity.
Activating a licence
Once you are signed in, the application asks plexusx.lol for a licence for this computer.
It sends the following when you activate, and again when PlexusX renews a licence that is
about to run out:
| What | Why |
|---|---|
| If you signed in: proof of that sign-in. If you typed in a licence key, or PlexusX is renewing the licence already on this PC: that licence key | To look up which licence you are activating |
| Your PC id — the truncated hash described below | So the licence issued back is bound to this computer |
| The application's version number | So a licence issued for a newer scheme is not sent to an older build |
It sends nothing else: no settings, no colours, no user name, no hardware details beyond the hash. What comes back is your signed licence file, stored locally. From that point on PlexusX checks it on your own machine, alongside the plan check-in above.
Releasing or moving a PC. If you press Release this PC or Move it here, you sign in
first, and the application sends your licence key together with that sign-in to
plexusx.lol, so a machine is unbound only on the word of the account that owns the licence.
With the same sign-in it first asks plexusx.lol which licence your account owns, and whether
it is on a PC, so it never releases a licence that is not yours or one that is already free.
Move it here then activates this computer, as above.
Your PC id
Your licence is tied to one computer. To do that, PlexusX computes a one-way SHA-256 hash of three things:
- your CPU's identifier,
- your first disk's serial number,
- your Windows computer name.
The hash is truncated to 16 characters and shown to you as your PC id. The three inputs are never written to disk and never sent anywhere — only the hash exists, and a hash cannot be reversed back into your computer name or your hardware.
The PC id leaves your machine when you activate or renew a licence, and with the plan check-in. The plan check-in runs in the background while a licence is installed (see Checks that run on their own); none of the other checks sends the PC id. It is embedded in the signed licence so the application can check it is running on the right computer.
Because the computer name is part of the input, renaming your PC changes your PC id, as does changing your CPU or boot drive. If that happens, press Move it here in the application, or release the licence from your dashboard and activate again.
Crash reports
When PlexusX crashes it writes a file locally containing the error, the stack trace, the application version and your Windows version. A separate file records licence checks that failed, for the same reason. Neither is uploaded. If you choose to send one, you are sending it yourself, and you can read it first — they are plain text.
Old crash logs are deleted automatically.
Screenshots
PlexusX has a screenshot hotkey, because an ordinary screenshot does not capture the colour
changes you are looking at. It only fires when you press that key. The image is written to
Pictures\PlexusX and copied to your clipboard, and that is the end of it — it is never
uploaded, and nothing reads the screen at any other time.
Which games you have
PlexusX looks for installed games so it can offer you per-game profiles. It reads Steam's registry entry for its install path and then Steam's local library folders on your own disk. That list stays on your machine and is never sent anywhere.
Rating an update — NOT ACTIVE IN THIS VERSION
The version you are running does not ask this and does not send it. The window has no thumbs and no box, and there is no code path from it to the internet.
What follows describes the feature as it is built and as it would behave if it were switched back on. It is written here in advance rather than afterwards: a rule that exists before the feature does is a rule the feature has to be built to.
After PlexusX updates itself, the What's New window asks whether the update was any good. Two buttons and an optional box for what you would change.
This would be the only thing the application sends that is about your opinion rather than your licence, so the rules around it are narrow on purpose:
- It is sent only if you choose one and press OK. Opening the window sends nothing. Closing it, with the X or with Escape, sends nothing. Typing in the box and then closing sends nothing. Pressing the same thumb twice unchooses it.
- It carries nothing that identifies you. Not your account, not your email, not your licence, not your PC id. The message is three things: the version number, the word "up" or "down", and your note if you wrote one.
- You are counted once per release. To stop one machine voting a hundred times, the server keeps a code made by hashing your IP address and browser-style identifier together with the day and a secret. It cannot be reversed, your IP is never stored, and the code changes every day — which is also why it cannot be used to follow you.
- If it fails to send, nothing happens. No retry, no error, no queue on your disk.
What the application never collects
No browsing history. No keystrokes. No screen contents outside the screenshot key you press yourself. No advertising identifiers. No profiling, and no automated decision-making.
Part two — the website
Signing in, buying and managing your licence happen at plexusx.lol. That is a server we run, so unlike the application it does hold data about you.
What the account holds
| What | Why | Kept |
|---|---|---|
| Your email address | It is your account | Until you delete the account |
| A hash of your password, if you use one | To sign you in. Never the password itself | Until you delete the account |
| Your Discord or Google user id, display name and avatar, if you sign in that way | To recognise you on the next sign-in | Until you delete the account |
| Your licence: its key, plan, expiry, and the PC id it is bound to | It is what you bought | Until you delete the account |
| The network the licence last activated from, and the application version | To spot a key being shared across many machines | With the licence record |
| If we switched an extra feature on for your account: a note of which feature, which account, and the date | So your PC gets that feature when it checks your plan | Until we take it off your account, or you delete the account |
| Whether you ticked "Don't send me offers" when you made the account, and when you were asked | So we keep to your answer | Until you delete the account |
| If you came through a creator's link: that creator's code, the terms it carried on that day, and the time | So the sale counts for the creator who sent you | Until you delete the account |
| IP addresses of recent requests | Rate limiting - to stop somebody guessing passwords or keys | One hour |
| A session cookie | To keep you signed in for twelve hours | Twelve hours |
Your full IP address is not kept with your licence. It is cut down to its network before
it is stored — 203.0.113.47 becomes 203.0.113.0/24 — which is enough to notice one key
being used from several places, and not enough to point at a household. The same cut IPv6
addresses get, at /48.
If you join the waitlist we keep the address you gave until the launch email is sent.
Our server's logs
Like any website, ours writes logs. We keep them short:
| What | Why | Kept |
|---|---|---|
Our web server's log: the time, the page address without anything after ?, your IP address cut to its network (the same cut as the licence record), and how the server answered. No browser details: request headers are not logged | To keep the site running and spot attacks | 14 days |
| Our server's error and event log, which can include your email address or account id (for example when you reset your password) | To find and fix faults | 14 days |
Our API does not keep its own log of requests.
Who else sees it
-
Stripe processes payments, as merchant of record — they charge your card, they appear on your bank statement, and they account for any VAT, while the licence itself is sold to you by Lucie Uhlířová, trading as PlexusX. Your card details go to Stripe and never reach us — we see that a payment succeeded, and an identifier for it. How the charge is described on your statement is shown at the foot of every page on plexusx.lol and in your purchase email. Payments taken before 27 August 2026 went through a different provider; the only thing we hold about either is that same payment identifier.
-
Discord or Google, if you choose to sign in with them. They tell us your email address, your user id, your display name and your avatar, and they learn that you signed in to PlexusX. After that, your dashboard shows your picture straight from their servers, so they see that request. A bug report you send from the application also reaches the developer as a private Discord message, so Discord carries its text.
-
Resend sends our emails — your purchase email and licence, password resets and account messages. To do that it receives your email address and the message itself.
-
Hetzner hosts the server in Germany that plexusx.lol runs on, so everything in the table above is stored on their machines. They host it; they do not use it.
We also use other service providers to run our email, customer support and business tools. They receive what that job needs. Some of these tools are run by companies in the United States. There is no advertising, and no third-party analytics or tracking on the website. Apart from the sign-in picture on your dashboard, nothing you load from us reports to Google, Meta or anyone like them.
Emails we send
- About your account and what you bought — your purchase email and licence, password resets, and messages about a payment or subscription (for example a card that was declined). These are part of the service, so they come regardless of the setting below.
- About PlexusX offers — for example a reminder that a discount you were given is about to end, or that a checkout you started is still waiting. We send these because you have an account with us, and every one carries a one-click unsubscribe link. Press it once and no offer is sent to you again. You can also just reply and ask. When you make an account, you can tick Don't send me offers, and then we send you none at all.
We never sell or share your address, and we do not send anybody else's offers.
We keep a note of each email we send: when, which kind, and the address it went to. We use it to count how many emails go out each day.
Counting
We do keep our own counts, on our own server, so we know whether the thing works: a page opened, a download started, an account created, a licence activated on a PC, a waitlist signup. No third party is involved and no cookie is set for it.
Visits are counted under a key made by hashing your IP address, your browser's user-agent string and today's date together with a secret. The raw IP address is never stored in these counts, the hash cannot be reversed back to you, and the key changes every day — so the counts cannot be joined up into a history of one person. Activations are counted under a hash of the PC identifier described above instead.
The one exception, named plainly: creating an account is counted against your account id, because that is the number the count is about. It goes when your account goes.
Our visit counter. We also run a small visit counter of our own, on our own server. When you open a page, it sends the page address, the address you came from, your screen width, your time zone and the name of the event (for example "pageview"). It does not load at all on a page whose address carries a private code, such as a password reset, an unsubscribe link, a checkout or the app's sign-in, or when the page before it carried one. It also sends nothing when you move to such a page inside the site. It stores nothing in your browser, and if your browser sends Do Not Track or Global Privacy Control, it sends nothing at all. Its records are kept 90 days. Speed measurements (web vitals) are switched off.
How many people are on the site right now. While a page of ours is open and in front of you, it says "still here" to our server every twenty seconds, along with which page you are on. Nothing is written to your device — no cookie, no storage, nothing that survives you closing the tab.
To avoid counting one person as several, the server groups those messages by a short code it works out from your network address and your browser's description of itself, mixed with a secret of ours. That code is one-way: it cannot be turned back into either of the things it was made from, and it cannot be worked out in advance without the secret. Your IP address itself is never stored. The record is deleted after one minute, so there is no history of it to keep, and all we can see is a count.
Pressing refresh does not add a second visitor, and neither does opening the same page in a new tab. What we still cannot do is tell who you are, connect today's visit to yesterday's, or follow you anywhere.
Totals we show on the site
Two lines on plexusx.lol are counted from our own order records. Both show a number about the shop and nothing about any person: no name, no email, no country, no amount.
- How many people bought Lifetime. Rounded down to the nearest ten, and not shown at all below 50. Refunds, test purchases and our own accounts are left out.
- Bought in the last 3 days. How many orders came in over the last three full days, and how many of them were Monthly and how many Lifetime. It appears only once we switch it on; until then nothing is recorded for it. Once it is on, the site keeps a short note of each new order for it — which order and payment it was, the account, the plan and when it was paid — and deletes that note within four days, or at once if the order is refunded, disputed or withdrawn, or the account is deleted.
Reviews and shared looks
If you post a review, or share a look or a crosshair in the Library, part of it is public: your display name, what you wrote, the look itself, the picture if you added one, and the date. Your email address and your account are not shown.
Your display name is the name on your account. If you signed up without giving one, it is the part of your email address before the @, or the name Discord or Google gave us.
A look stays up until you delete it from your dashboard or delete your account. A review stays until you delete your account, or ask us to take it down.
If you report a look, we keep your report: your account, the reason you picked, what you wrote and when. We use it to decide, and to tell you what we decided. It is kept until you delete your account. A report you send by email is kept like any other email to us (below).
If we refuse or take down your look or review, we keep a note of what we did and why, and show it to you in your dashboard. The note goes when the look or review goes.
Creators
If you are one of our creators, we keep your creator code, your name, how to reach you, your channels, your commission and the discount your code gives, and the payouts we have recorded, with their amount and date. We count the sales made with your code from our sales ledger. We need all of this to pay you. Nothing deletes it automatically yet.
Withdrawals
If you use Withdraw from contract on your dashboard, we keep what you sent: your name, your note, your email address, your account, your plan and the time. We email a copy to you and one to ourselves, and we note what we decided. We keep it as a record of what you asked and what we did. Deleting your account does not delete it, and nothing deletes it automatically yet.
Email to support@plexusx.lol
When you email support@plexusx.lol, your email stays in our support mailbox, which our email provider hosts for us. We also keep copies on our own computers to answer you. Nothing deletes either automatically yet.
Lock clicks
If you press a padlock in the application, it opens our site. If you are signed in there, we note which paid feature you pressed, and when. A day later we may send you one email about that feature. It is an offer, so the rules above apply: it carries the unsubscribe link, and you do not get it if you ticked Don't send me offers or unsubscribed. We delete the note 7 days after you pressed.
Cookies, and everything else kept in your browser
This is everything the site can put in your browser. Some of it appears as soon as you arrive through a certain kind of link. "This tab only" means it is gone when you close the tab.
| What | When it appears | How long | What it is |
|---|---|---|---|
access_token | When you sign in | 12 hours | The cookie that keeps you signed in |
plexusx.ref | When you open a creator's link (one with ?ref= and a creator code) | Until you are signed in and our server has read it | The creator's code, waiting for an account to attach it to |
plexusx.ribbon.free-2026-09 | When you close the "PlexusX is free now" strip | Until you clear it | Keeps the strip closed |
plexusx.lock | When the application opens our site from a padlock | This tab only, and removed once you are signed in | Which paid feature you pressed, until we can note it on your account |
plexusx.fromApp | When the application opens our site | This tab only | That you came from the application, so the page remembers it after you make an account |
plexusx.from-free-email | When you arrive from one of our emails about the free version | This tab only | Which of those emails you came from, so the page keeps showing its steps |
plexusx.virusHelper.dismissed | When you close the "Is it a virus?" box | This tab only | Keeps the box closed |
plexusx:chunk-reloaded | Only if part of a page fails to load and the page reloads itself | This tab only | Stops the page reloading more than once |
plexusx-shop-section | Only on our own staff pages | This tab only | Which staff page was open |
The first is strictly necessary — without it you cannot stay signed in. The rest only remember a step you took on the site or where you came from. None of them is used to track you, none is shared, and there are no analytics or advertising cookies at all — so there is no consent banner to click.
The site no longer keeps your look or colour slider in your browser. If your browser still
holds plexusx-theme or plexusx-vibe from an older visit, the site ignores them.
The live visitor count described above was built the same way on purpose. Had it kept an identifier on your computer, it would have needed a banner, and we would rather have a rougher number than a banner.
Fonts and everything else the page loads. Every file a page of ours needs — scripts, styles, images and all four typefaces — comes from our own servers, apart from the sign-in picture on your dashboard. Most websites load their fonts from Google or a similar service, which quietly sends your IP address to that company before the page has even finished drawing. Ours used to do that too, until 30 August 2026. It does not any more.
How long we keep it
| What | How long |
|---|---|
| Your account — email, password hash, Discord or Google id, display name, avatar | While the account exists. Delete the account and it goes. |
| Your licence and the PC id it is bound to | Until you delete the account |
| A note of an extra feature we switched on for your account | Until we take it off your account, or you delete the account |
| Your answer to "Don't send me offers", and the creator's code you came through | Until you delete the account |
| Checkout records — which checkout you opened, and whether it was paid | Until you delete the account |
| Our sales ledger — for each payment: the amount, the currency, the plan, the date, Stripe's identifier for it, and the creator discount if one was used | Nothing deletes it automatically yet, and it stays after you delete your account. Stripe keeps its own records under its own rules. |
| IP addresses used for rate limiting | One hour |
| The cut-down network an activation came from | With the licence record |
| Our web server's log | 14 days |
| Our server's error and event log | 14 days |
| Our visit counter's records | 90 days |
| Plan check-ins from the application — a hash of the licence key, the version and build type, a code for which features were granted, a fingerprint of the program file, the time | 30 days, then deleted automatically |
| Your session cookie | Twelve hours |
| Messages you post in the PlexusX Discord server | 90 days. They are deleted automatically after that. |
| Errors your browser reports from our website | 60 days, then deleted automatically |
| Bug reports you send us from the application | While we are working on the bug. Nothing deletes these automatically yet, and saying so is more use to you than a number we do not keep to. |
| Our own counts — pages opened, downloads started | Only as counts. The key they are grouped under changes every day and cannot be turned back into you. |
| "How many people are on the site right now" | One minute |
| Notes kept for "Bought in the last 3 days", once it is switched on | Under four days, and removed at once after a refund, a dispute, a withdrawal or the account being deleted |
| Which paid feature you pressed in the application | 7 days |
| Looks and reviews you post, and our notes on them | A look: until you delete it or your account. A review: until you delete your account or ask us to take it down |
| Your reports of a look, and what we decided | Until you delete your account |
| A withdrawal you sent from the dashboard | Nothing deletes it automatically yet, and it stays after you delete your account |
| A creator's code, details and payouts | Nothing deletes them automatically yet |
| Emails you send to support@plexusx.lol | Nothing deletes them automatically yet |
| Our note of each email we send you | Nothing deletes it automatically yet, and it stays after you delete your account |
| Your waitlist address, if you joined one | Until the launch email is sent |
Deleting your account deletes your checkout records and your licences. Our sales ledger stays after you delete your account. So do a withdrawal you sent and our notes of the emails we sent you, as the table says. Everything the table keeps "until you delete the account" goes. Our daily database backups still hold a copy for 16 days at the most; then those backups are deleted too. If you ask us to delete your account, we do it for you in the same way.
Children
PlexusX accounts are for people aged 15 or older. In Czechia that is the age at which you can agree to an online service yourself; if you are younger than 15, a parent has to agree and set the account up with you. We ask you to confirm this when you create an account, and we do not knowingly collect anything from a child under 15.
Why we are allowed to use it
- To give you what you signed up for or bought (GDPR Art. 6(1)(b), a contract): the account, any extra feature we switched on for it, the licence, the PC id, sign-in, the plan check-in, receipts and account emails. For a creator, the same basis covers the creator code and paying you.
- To keep a record of sales for tax and accounting law (Art. 6(1)(c), a legal duty).
- To handle reports and explain our decisions about looks and reviews, as the EU's Digital Services Act requires of us (Art. 6(1)(c), a legal duty).
- Our legitimate interests (Art. 6(1)(f)): stopping key sharing and password guessing, keeping short server logs so the site runs and attacks are spotted, counting changed copies of PlexusX that run under a real licence, counting visits on our own server, showing the sales totals above, answering you and your bug reports, keeping a record of a withdrawal and what we did about it, and emailing offers to people who have an account, including the one email after you press a padlock — which you can refuse at any time with the unsubscribe link.
- If you post in the PlexusX Discord server, we read and keep copies of those messages so we can answer support questions and spot bugs (legitimate interest). Discord's own privacy policy covers everything else Discord does.
Data outside the EU
Some of the companies above (Stripe, Resend, Discord, Google) are based in, or use servers in, the United States. Where your data leaves the EU, it does so under the safeguards the GDPR requires — the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses in each company's data processing terms.
Your rights under the GDPR
You can ask us for a copy of what we hold, ask us to correct it, or ask us to delete it. You can also ask us to restrict how we use it, to hand it to you in a machine-readable form, and you can object to any use based on our legitimate interests — including offers, which stop the moment you unsubscribe. You can also delete the account yourself from the dashboard, which removes the account and its licence record.
Everything the application stores is on your own computer, and the files listed above are yours: deleting them deletes all of it.
The PC id in a licence record is a one-way hash. It cannot be turned back into your computer name or your hardware, but it does identify your installation, so we treat it as personal data rather than pretending otherwise.
To ask what we hold, correct it, or have it erased, contact us at support@plexusx.lol. We answer within one month. You also have the right to complain to a data protection authority — in the Czech Republic that is the Úřad pro ochranu osobních údajů (uoou.gov.cz), or the one where you live.
Changes
If this policy changes, the date at the top changes with it. The current version is always at plexusx.lol/privacy. The application carries the version that was current when it was built, under Settings → Legal & licences.