Legal
PLYNX - PRIVACY POLICY
Last updated: July 6, 2026
This Privacy Policy (“Policy”) describes how Plynx (“Plynx”, “we”, “us”, or “our”) collects, uses, discloses, and protects your information when you use the Plynx mobile application (“App”) and related services (collectively, the “Services”).
We are committed to protecting your privacy and handling your data with transparency. Please read this Policy carefully.
SUMMARY
In brief:
- We collect minimal personal data: email address and password hash for authentication
- We collect technical data: IP addresses, device tokens, push notification tokens (APNs), widget/dashboard configurations
- We do NOT collect your name, phone number, physical address, or payment information (unless you provide it)
- We do NOT sell your data to third parties
- We do NOT use third-party analytics in the App (only App Store standard statistics)
- We do NOT share your data for marketing purposes
- You can request deletion of your data at any time
TABLE OF CONTENTS
- Who We Are
- What Information We Collect
- How We Use Your Information
- How We Store Your Information
- How We Share Your Information
- Data Retention
- Your Rights and Choices
- Data Security
- International Data Transfers
- Children’s Privacy
- Third-Party Links and Services
- California Privacy Rights (CCPA)
- European Privacy Rights (GDPR)
- Changes to This Policy
- Contact Us
1. WHO WE ARE
Plynx is developed and operated by:
Niccolo Pagano (NickP005)
Email: plynx.cc@gmail.com
Website: https://plynx.cc
For GDPR purposes, Niccolo Pagano is the Data Controller for personal data collected through the Plynx Cloud Server (plynx.cc).
If you use a self-hosted server, the operator of that server is the Data Controller.
2. WHAT INFORMATION WE COLLECT
2.1 Information You Provide
When you create an account or use the Services, we collect:
| Data Type | Purpose | Required |
|---|---|---|
| Email Address | Account identification, login, password recovery, service communications | Yes |
| Password | Authentication (stored as cryptographic hash, not plaintext) | Yes |
We do NOT require or collect:
- Full name
- Phone number
- Physical address
- Date of birth
- Payment information (the app is free)
- Government ID numbers
2.2 Information Collected Automatically
When you use the Plynx Cloud Server, we automatically collect:
| Data Type | Purpose | Stored |
|---|---|---|
| IP Address | Security, fraud prevention, abuse detection | Yes (registration IP and last login IP) |
| Last Login Timestamp | Account security, activity monitoring | Yes |
| Device Tokens | Hardware authentication | Yes |
| App Identifier | Distinguish between different client applications | Yes |
| Region | Server optimization (if applicable) | Yes |
| Push Notification Token (APNs) | Deliver push notifications to your iOS device; the token is issued by Apple, and Apple (APNs) acts as a technical recipient of the notifications | Yes |
2.3 IoT Device Data
When your hardware devices connect to the Plynx platform, we may collect and store:
| Data Type | Purpose | Stored |
|---|---|---|
| Authentication Tokens | Device authentication | Yes |
| Widget Data | Display values on dashboards (sensor readings, states, etc.) | Yes |
| Historical Data | Time-series data for graphs and charts (if you use SuperChart widgets) | Yes |
| Device Connection Status | Show online/offline status | Temporarily |
| Device Last IP | Security and debugging | Yes |
2.4 Information Stored Locally on Your Device
The Plynx App stores certain information locally on your device using secure storage (Keychain on iOS):
- Email address
- Password (encrypted)
- Server configuration (host, port)
- Access tokens
- Dashboard preferences
This data is stored locally and is not transmitted to us except as necessary to authenticate and use the Services.
2.5 Information We Do NOT Collect
We want to be clear about what we do NOT collect:
- Location data (GPS)
- Contacts
- Photos or media files
- Microphone or camera access
- Advertising identifiers
- Third-party analytics (no Firebase Analytics, Google Analytics, etc.)
- Browsing history
- Social media profiles
3. HOW WE USE YOUR INFORMATION
We use the information we collect for the following purposes:
3.1 To Provide the Services
- Create and manage your account
- Authenticate your login
- Connect your hardware devices
- Display your dashboards and widget data
- Store historical data for charts
3.2 To Maintain and Improve the Services
- Monitor service performance
- Debug technical issues
- Improve user experience
3.3 To Communicate with You
- Send password reset emails
- Notify you of important service updates
- Respond to your support requests
3.4 To Ensure Security
- Detect and prevent fraud
- Identify unauthorized access
- Protect against abuse
3.5 To Comply with Legal Obligations
- Respond to lawful requests from authorities
- Comply with applicable laws and regulations
We do NOT use your information for:
- Advertising or marketing
- Selling to third parties
- Profiling for commercial purposes
- Automated decision-making that affects your rights
4. HOW WE STORE YOUR INFORMATION
4.1 Storage Location
If you use the Plynx Cloud Server (plynx.cc):
- Your data is stored on servers located in Europe
- We take reasonable and appropriate security measures
If you use a self-hosted server:
- Your data is stored on your own infrastructure
- You are responsible for data security and compliance
4.2 Data Security Measures
We take reasonable security measures appropriate to the risk, including:
- Password hashing (not stored in plaintext)
- Encrypted connections (TLS/SSL)
- Access controls
5. HOW WE SHARE YOUR INFORMATION
5.1 We Do NOT Sell Your Data
We do NOT sell, rent, or trade your personal information to third parties for marketing or any other purpose.
5.2 Limited Sharing
We may share your information only in these limited circumstances:
| Recipient | Purpose | Type of Data |
|---|---|---|
| Service Providers | Infrastructure hosting | Technical data |
| Apple Inc. (APNs) | Delivery of push notifications (technical recipient) | Push notification tokens and notification content |
| Legal Authorities | When required by law or legal process | As legally required |
| Successors | In case of merger, acquisition, or sale of assets | All data (with notice) |
5.3 Aggregated Data
We may share aggregated, anonymized data that cannot identify you (e.g., total number of users, general usage statistics).
6. DATA RETENTION
6.1 Active Accounts
We retain your data for as long as your account is active or as needed to provide the Services.
6.2 Account Deletion
When you delete your account:
- Your personal data (email, password hash) is deleted
- Your dashboards and widget configurations are deleted
- Historical data is deleted
- Some anonymized logs may be retained for security purposes
6.3 Retention Periods
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Historical/chart data | Until account deletion |
| Server logs | Up to 90 days |
| Backup copies | Backups may be retained for a limited period for disaster-recovery purposes, after which they are deleted or overwritten |
7. YOUR RIGHTS AND CHOICES
You have the following rights regarding your personal data:
7.1 Access
You can request a copy of your personal data.
7.2 Correction
You can update or correct inaccurate data.
7.3 Deletion
You can delete your account and all associated data directly from the app:
- Open the app and go to Settings
- Tap Delete Account
- Enter your password to confirm
- Your account and associated data will be deleted without undue delay
What gets deleted:
- Your user profile and email
- All dashboards and widget configurations
- All device tokens and authentication data
- All historical data (SuperChart, reports)
- Push notification tokens
Important: Deletion requests are processed without undue delay, in accordance with the GDPR. Residual copies of your data may temporarily persist in backups retained for disaster-recovery purposes until those backups are deleted or overwritten.
You can also request deletion by contacting us at: plynx.cc@gmail.com
7.4 Data Portability
You can request your data in a portable format (JSON export).
7.5 Restriction
You can request that we limit how we use your data.
7.6 Objection
You can object to certain processing of your data.
7.7 Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us at: plynx.cc@gmail.com
We will respond to your request within 30 days (or as required by applicable law).
8. DATA SECURITY
We implement reasonable administrative, technical, and physical security measures to protect your information, including:
- Cryptographic hashing of passwords
- Encrypted data transmission (TLS)
- Secure authentication mechanisms
However, no system is completely secure. We cannot guarantee absolute security of your data. You are responsible for:
- Keeping your password confidential
- Securing your devices and tokens
- Reporting any security incidents
9. INTERNATIONAL DATA TRANSFERS
If you access the Services from outside the country where our servers are located, your data may be transferred internationally.
9.1 For EU Users
The Plynx Cloud Server (plynx.cc) is located in Europe. Your data remains within the European Economic Area (EEA).
If we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Your explicit consent
9.2 For Non-EU Users
If you access the Services from outside the European Union, your data is transferred to and stored on our servers in Europe.
10. CHILDREN’S PRIVACY
Consistent with our Terms of Service, an account may be created only by persons who are at least 18 years of age. The Services are not directed to minors: minors may use dashboards and Devices connected to the Services only under the supervision and responsibility of the adult account holder.
We do not knowingly collect personal information directly from minors. If we discover that we have collected personal data directly from a minor, we will delete it promptly.
If you believe we have inadvertently collected data from a minor, please contact us immediately at plynx.cc@gmail.com.
11. THIRD-PARTY LINKS AND SERVICES
The Services may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties.
We recommend reviewing the privacy policies of any third-party services you use.
12. CALIFORNIA PRIVACY RIGHTS (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
12.1 Right to Know
You can request information about:
- Categories of personal information collected
- Purposes for collecting the information
- Categories of third parties with whom we share information
12.2 Right to Delete
You can request deletion of your personal information.
12.3 Right to Opt-Out
You can opt out of the “sale” of personal information. However, we do NOT sell your personal information.
12.4 Right to Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.
12.5 Categories of Personal Information Collected
| Category | Collected | Sold | Business Purpose |
|---|---|---|---|
| Identifiers (email) | Yes | No | Account management |
| Internet activity (IP, tokens) | Yes | No | Service provision, security |
| Geolocation (IP-based only) | Yes | No | Security |
| Inferences | No | No | N/A |
To exercise your CCPA rights:
Email: plynx.cc@gmail.com
Subject: “CCPA Request”
We will verify your identity before processing your request.
13. EUROPEAN PRIVACY RIGHTS (GDPR)
If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):
13.1 Legal Bases for Processing
We process your data based on:
| Legal Basis | Processing Activity |
|---|---|
| Contract | Account creation, service provision |
| Legitimate Interest | Security, fraud prevention, service improvement |
| Legal Obligation | Compliance with laws |
| Consent | Where specifically requested |
13.2 Your GDPR Rights
- Access (Art. 15) - Request a copy of your data
- Rectification (Art. 16) - Correct inaccurate data
- Erasure (Art. 17) - Request deletion (“right to be forgotten”)
- Restriction (Art. 18) - Limit processing
- Portability (Art. 20) - Receive data in portable format
- Object (Art. 21) - Object to processing based on legitimate interest
- Withdraw Consent (Art. 7) - Withdraw consent at any time
13.3 Data Controller
Data Controller:
Niccolo Pagano
Email: plynx.cc@gmail.com
13.4 Supervisory Authority
You have the right to lodge a complaint with your local data protection authority.
For Italy: Garante per la protezione dei dati personali
Website: https://www.garanteprivacy.it
13.5 Data Protection Impact Assessment
Given the limited nature of data we collect and the absence of high-risk processing activities, a formal DPIA is not required. We keep our data practices under review.
14. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. When we do:
- We will update the “Last updated” date at the top
- For material changes, we will notify you via:
- Email to your registered address
- Notice in the App
Your continued use of the Services after changes become effective constitutes acceptance of the updated Policy.
Language. This Policy is made available in English and Italian. In the event of any inconsistency between the two versions, the English version shall prevail, it being understood that you retain all rights and protections granted by mandatory provisions of applicable data protection and consumer law, including any rules on language more favorable to you.
15. CONTACT US
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Niccolo Pagano (NickP005)
Email: plynx.cc@gmail.com
Website: https://plynx.cc
Response Time:
We aim to respond to all privacy-related inquiries within 30 days.
APPENDIX: DATA PROCESSING SUMMARY
Data We Collect
| Data | Source | Purpose | Legal Basis | Retention |
|---|---|---|---|---|
| You provide | Account ID, login | Contract | Until deletion | |
| Password hash | You provide | Authentication | Contract | Until deletion |
| IP Address | Automatic | Security | Legitimate interest | 90 days |
| Device tokens | Automatic | Hardware auth | Contract | Until deletion |
| Widget data | Your devices | Service function | Contract | Until deletion |
| Historical data | Your devices | Charts/graphs | Contract | Until deletion |
| Push notification token | Automatic (issued via Apple APNs) | Push notifications | Contract | Until deletion or token invalidation |
Data We Do NOT Collect
- Name, phone, address
- Payment data
- Location (GPS)
- Contacts, photos
- Analytics/tracking data
- Advertising identifiers
BY USING PLYNX, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.
CHANGELOG
| Date | Changes |
|---|---|
| November 26, 2025 | Initial version |
| July 6, 2026 | Clarified storage location (Europe); added push notification tokens (APNs) to collected data and recipients; aligned minors section with the Terms of Service (18+ account holders); replaced fixed backup/recovery timeframes with retention criteria; updated contact email; added prevailing-language clause |
Copyright 2025 Plynx / Niccolo Pagano.