Privacy Policy
Last updated October 7, 2026
This policy explains what information [Company legal name] (“Plurtex”, “we”) collects when you use Plurtex, how we use and protect it, who it goes to, and the choices you have.
The short version
- We store what you need to work: your account, projects, conversations and files.
- Your content goes to the AI providers you connect, under your own accounts with them.
- We don't train AI models on your data, don't sell it, and don't use advertising or tracking cookies.
- Your API keys are encrypted and never sent back to your browser.
- You can delete your account and its data yourself, at any time.
1. What we collect
- Account details: your name, email address and password (stored only as a salted scrypt hash). If you sign in with single sign-on, the identity your organization's provider shares with us.
- Security information: sign-in sessions (IP address, browser and device description, when they were last active); your two-factor secret (encrypted) and hashes of your recovery codes.
- Your content: projects, instructions, conversations, files and attachments, generated images and artifacts, memories, decisions, checkpoints and code repositories — plus search indexes made from them (text chunks and embeddings).
- Connections: API keys and tokens for AI providers, GitHub and connectors you add (encrypted with AES-256-GCM), and the addresses of servers you connect.
- Usage information: which models handled each request, token counts, costs, timing and errors; plan usage (such as multi-AI runs this month); and an audit log of security-relevant actions.
- Billing information: your plan and subscription status, and the customer and subscription identifiers Stripe gives us. Card details go directly to Stripe — we never see or store them.
- Messages with us: emails you send us and the service emails we send you (such as verification and security alerts).
2. How we use it
We use your information to:
- run Plurtex for you — store your work, build the context each model receives, route requests and run the tools and workflows you choose;
- keep accounts and the Service secure, and prevent abuse and fraud;
- process payments and enforce plan limits;
- send you service and security emails, and respond when you contact us;
- understand reliability and fix problems (for example, which models fail and why);
- meet legal obligations.
We don't use your content to train AI models, we don't sell your personal information, and we don't use it for advertising.
3. AI providers and services you connect
Plurtex sends your content to the AI providers you connect, using your credentials, so they can answer. They receive the project context Plurtex compiles for each request — which can include project instructions, relevant files, memories and recent conversation. Each provider handles that data under its own terms and privacy policy, and your account settings with it; please review them. Some providers' free models may log or train on prompts, which is why Auto never picks them unless you choose to.
Depending on what you turn on, content can also go to:
- another provider you've connected, when Auto routing picks it or a request fails over;
- OpenAI or Google, to create embeddings for semantic search, and to transcribe audio you upload;
- your cheapest connected model, to classify ambiguous requests (smart routing);
- the web search provider you connect (Brave or Tavily), and web pages the AI reads for you;
- MCP connectors you attach, and GitHub when you clone, pull or push.
You can turn these features off in Settings and per message.
4. Companies that process data for us
We use a small number of service providers, who may only use the data to provide their service to us:
- Hosting and database: [Hosting provider, e.g. AWS / Render / Fly.io].
- Email delivery: [Email provider, e.g. Postmark / Amazon SES].
- Payments: Stripe, which processes payments and may act as merchant of record (handling sales tax and VAT). Stripe's own privacy policy covers the payment details it collects.
7. How long we keep it
- Your account and content are kept while your account exists. Archiving a project hides it; its data is deleted when you delete your account.
- When you delete your account, we immediately and permanently delete your account, the projects you own (with their conversations, files and repositories), your keys, connectors, agents and sessions. Projects owned through an organization pass to its next admin instead, and things you added to other people's shared projects stay there, no longer linked to you.
- Sign-in sessions expire after 30 days of inactivity. Single-use email links expire within hours to days.
- We keep limited records longer where we need them for security, to resolve disputes, or to meet legal and tax obligations — for example payment records (kept by Stripe) and a record that an account was deleted.
- Backups, where we keep them, are overwritten on a rolling basis.
8. Security
We protect your data with encryption in transit (HTTPS) and encryption of secrets at rest, hashed passwords, optional two-factor sign-in, strict browser security policies, rate limiting, isolation of code the AI runs, and approval prompts before risky tools act. You can see every device signed in to your account and sign any of them out.
No system is perfectly secure. If you find a vulnerability, please report it to [[email protected]].
9. Your choices and rights
- Access and correct: see and edit your information in the app (Settings, Connections, your projects).
- Delete: delete your account anytime in Settings → Security → Delete account.
- Copy: export a project's repository from the app, or email us for a copy of your data.
- Control sharing: disconnect providers and connectors, turn off features like semantic search, and remove people from projects at any time.
Depending on where you live (for example under the GDPR in the EU/UK, or US state laws such as the CCPA), you may have further rights, such as objecting to or restricting processing, data portability, and complaining to your data protection authority. We don't sell or “share” personal information for cross-context behavioral advertising. To make a request, email [[email protected]]; we'll respond within the time the law requires, and won't treat you differently for exercising your rights.
Where the GDPR applies, we process your data to perform our contract with you (running the Service), for our legitimate interests (security, abuse prevention, improving reliability), to meet legal obligations, and with your consent where we ask for it.
10. International transfers
We and our providers may process your information in countries other than yours, including the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses.
11. Children
Plurtex isn't for anyone under 18, and we don't knowingly collect their information. If you believe a child has given us personal information, contact us and we'll delete it.
12. Changes to this policy
If we make material changes, we'll notify you (for example by email or in the app) before they take effect. The date at the top shows when this policy last changed.
13. Contact
Questions or requests: [[email protected]], or write to [Company legal name], [Business address]. See also our Terms of Service.