Privacy Policy

Last updated Sep 28, 2026 · Octa Air LLC (合同会社Octa Air)

PluMap (ぷるまっぷ, "the Service") is a map-first calendar provided by Octa Air LLC (合同会社Octa Air) ("we") that shows where you will be each day, based on your calendar. Because it deals with locations, PluMap follows one rule: collect only what the features need, and let you decide what is shared. This policy describes exactly what we collect, use and send, and how.

The Service collects and stores:

  • Account: username, display name, profile picture URL, the sign-in service you used (Google / Apple / GitHub) with its account ID and email address, when you confirmed you are 13 or older, and when you signed up.
  • Calendar data: if you connect Google Calendar, your calendar list and, for each event, title, time, time zone, location, description and attendees (email address or name). If you import an .ics file, its contents. Events you create or edit in PluMap.
  • Apple Calendar data (iOS only, optional): only if you connect Apple Calendar and allow calendar access, the list of calendars you pick and, for each event, title, time, time zone, location, notes and attendees are sent to and stored on our servers. This is read-only: we never write to your Apple Calendar.
  • Locations derived from your calendar: the cities and areas we infer from event locations, hotels and travel, the home and bases you set, and places you pick. Destinations you add, with conditions such as an arrival deadline, and travel-mode notes.
  • Smart guesses: for events without a location, the place we guess from the title or the events around it (always shown as a guess, such as "Probably around Umeda"), your Confirm / Change / Dismiss choices, the "this title → this place" mappings learned from your confirmations, and "Not now" on home / base suggestions. Travel-time estimates and route suggestions are computed when shown; only your Accept / Dismiss choice on a route suggestion is stored.
  • Current location (iOS only, optional): only if you turn on "Use current location" in Settings, it is used on your device to show where you are on the map. It is never sent to or stored on our servers. It is off by default.
  • Social data: your friends and their share levels, pull requests (proposed changes), comments, branches (trip plans) and their READMEs, public links, blocks and reports.
  • Credentials for integrations: Google Calendar access and refresh tokens, used only to sync (and to write events if you allow write-back).
  • Usage counts (in our own database only): how often actions happen, such as "opened the app", "created an event" or "merged a pull request". Never event titles, places, coordinates or free text (section 5).
  • Technical data: your signed-in sessions (tokens are stored hashed), when they were created and expire, and the browser/app type (user agent). IP addresses are used only in memory, briefly, to rate-limit abuse; they are not stored.
  • To infer where you are each day and show it on the map, timeline and widgets
  • To guess places for events without a location, travel-time estimates, the order of your destinations and home / base suggestions, shown only to you and clearly labelled as guesses (nothing is treated as confirmed until you confirm it)
  • To provide the features you use: sharing with friends, pull requests, comments and public links
  • To sync with Google Calendar (and write to it if you allow it)
  • To prevent abuse, handle reports and keep people safe
  • To improve features using anonymous usage counts (you can opt out)
  • To answer your questions and send important notices

You decide who sees your whereabouts and plans, and how precisely.

  • Friends: the narrower of your share level for that friend (exact place / area / city / country / busy only / private) and each event's own visibility. With a sharing delay (1 hour / after leaving), detailed places stay hidden until then.
  • Public links: none exist until you create one. Anyone with the link can then see that period's trip at city level (at most area level — hotel names and addresses are never shown). Links are served with noindex (not listed by search engines), can have an expiry date and can be deleted at any time.
  • Shared trips: when you accept an invitation to a trip (a trip branch), the participants can see each other's city (city level at most) during that trip's dates, even if they are not friends. Not outside those dates, and not for trips you did not accept. You can leave a trip at any time.
  • Guessed places, travel-time estimates and route or base suggestions are shown only to you; they are never shown to friends, on public links or in stats. A place you confirm is shared like any other event location.
  • Your username, display name and profile picture are shown in user search and to the people you exchange pull requests with.
  • Pull requests and comments you send to someone else's calendar stay in their history. If you delete your account, they are shown as "@ghost (deleted user)".

We do not sell personal data, show ads or use third-party analytics SDKs. The Service talks to these external services only. They may process data outside Japan (for example in the US, the EU or the UK); please see their privacy policies.

  • Google LLC: Sign in with Google, and Google Calendar if you connect it (reading events and the calendar list; adding merged events if you allow write-back). Google profile pictures load from Google's servers.
  • Apple Inc.: Sign in with Apple (iOS). The iOS app uses Apple MapKit for maps, place search, looking up addresses of map points and travel-time estimates, so the visible map area, search terms and the start and end points of an estimate are sent from your device to Apple. On-device guesses (on devices with Apple Intelligence, with "On-device guesses" on) run entirely on your device — event details never leave it; only the guessed place is sent to our server. Apple Calendar is also read on your device.
  • GitHub, Inc.: only if you sign in with GitHub (profile and email address). Profile pictures load from GitHub's servers.
  • OpenFreeMap: map tiles on the web. Your browser sends your IP address and the visible map area when it loads map images.
  • OpenStreetMap Nominatim (OpenStreetMap Foundation): only if we enable online geocoding, our server sends location text that the built-in place list could not resolve (without anything that identifies you).
  • AeroDataBox (via RapidAPI): only if we enable the flight-status API, our server sends a flight number and date. Otherwise flight details come from a built-in sample timetable, which is not live flight status.
  • Apple Maps or Google Maps open only when you tap "Open in Maps" or "Navigate".

We count feature use in our own database only. We record an allow-listed action name (for example app_open, event_created, pr_merged) plus a few fixed values such as the screen, platform or a count. We never record event titles, places, coordinates, free text or your user ID.

Counts are linked to an identifier derived from your user ID with our secret key (not the ID itself), so that we can delete them together with your account.

Turn off "Share usage counts" in Settings and our server records nothing about your use (earlier counts appear in your data export and are deleted with your account). Counts are deleted automatically after 13 months.

  • Your account, events and other content: until you delete your account (then deleted immediately)
  • Events imported from Google Calendar and its credentials: deleted when you disconnect; we also try to revoke our access at Google
  • Events imported from Apple Calendar: events of calendars you stop syncing, and events deleted on your device, are deleted at the next sync; disconnecting deletes everything imported from that device
  • Place guesses and learned mappings: until you delete your account (deleting an event deletes its guess)
  • Sign-in sessions: at most 60 days (deleted immediately when you sign out)
  • Usage counts: 13 months
  • One-time codes that hand a sign-in over to the app: 2 minutes (invalid once used)
  • Account deletion receipts: only a hash of the session that deleted the account, for 30 days (so a repeated deletion request gets the right answer; it does not identify you)
  • Reports: as long as needed to handle them; reports you filed are deleted with your account
  • If we keep database backups, deleted data disappears from them as backups rotate, within 30 days
  • See and correct your data in the app or on the web at any time.
  • Export: download all your data (JSON) and your events (.ics) from Settings.
  • Delete your account from Settings in the app or on the web. Everything is erased — events, branches, friendships, connections, public links, notifications and usage counts (your posts in other people's pull request threads are shown as @ghost).
  • Disconnect Google Calendar at any time; you can also remove our access in your Google Account settings.
  • Opt out of usage counts; change visibility, share levels and sharing delay; block and report people.
  • Smart guesses: places are guessed only by fixed rules on our server (place names in the title, the events around it, and so on) and, on iOS, on your device (Apple Intelligence). Event details are never sent to an outside AI service. You can turn on-device guesses on or off in Settings → Smart guesses. You can Confirm, Change or Dismiss any guess, and hide a home / base suggestion with "Not now".
  • For requests under Japan's Act on the Protection of Personal Information (disclosure, correction, stopping use, etc.), contact us below.

We protect data with encrypted connections (HTTPS in production), hashed session tokens, HttpOnly cookies, access checks on every API and rate limits on sign-in, reports, friend requests and more.

PluMap is for people aged 13 or older. We ask you to confirm you are 13 or older when you create an account; people under 13 cannot create one. If we learn that an account belongs to someone under 13, we delete it.

We announce changes to this policy in the Service, and important changes clearly, in advance or when they take effect.

Octa Air LLC (合同会社Octa Air) — PluMap Support

Email: support@octa-air.co.jp

Operator
Octa Air LLC (合同会社Octa Air)
Contact
support@octa-air.co.jp