Privacy Policy

Last updated October 7, 2026

This policy explains what information [Company legal name] (“Plurtex”, “we”) collects when you use Plurtex, how we use and protect it, who it goes to, and the choices you have.

The short version

  • We store what you need to work: your account, projects, conversations and files.
  • Your content goes to the AI providers you connect, under your own accounts with them.
  • We don't train AI models on your data, don't sell it, and don't use advertising or tracking cookies.
  • Your API keys are encrypted and never sent back to your browser.
  • You can delete your account and its data yourself, at any time.

1. What we collect

  • Account details: your name, email address and password (stored only as a salted scrypt hash). If you sign in with single sign-on, the identity your organization's provider shares with us.
  • Security information: sign-in sessions (IP address, browser and device description, when they were last active); your two-factor secret (encrypted) and hashes of your recovery codes.
  • Your content: projects, instructions, conversations, files and attachments, generated images and artifacts, memories, decisions, checkpoints and code repositories — plus search indexes made from them (text chunks and embeddings).
  • Connections: API keys and tokens for AI providers, GitHub and connectors you add (encrypted with AES-256-GCM), and the addresses of servers you connect.
  • Usage information: which models handled each request, token counts, costs, timing and errors; plan usage (such as multi-AI runs this month); and an audit log of security-relevant actions.
  • Billing information: your plan and subscription status, and the customer and subscription identifiers Stripe gives us. Card details go directly to Stripe — we never see or store them.
  • Messages with us: emails you send us and the service emails we send you (such as verification and security alerts).

2. How we use it

We use your information to:

  • run Plurtex for you — store your work, build the context each model receives, route requests and run the tools and workflows you choose;
  • keep accounts and the Service secure, and prevent abuse and fraud;
  • process payments and enforce plan limits;
  • send you service and security emails, and respond when you contact us;
  • understand reliability and fix problems (for example, which models fail and why);
  • meet legal obligations.

We don't use your content to train AI models, we don't sell your personal information, and we don't use it for advertising.

3. AI providers and services you connect

Plurtex sends your content to the AI providers you connect, using your credentials, so they can answer. They receive the project context Plurtex compiles for each request — which can include project instructions, relevant files, memories and recent conversation. Each provider handles that data under its own terms and privacy policy, and your account settings with it; please review them. Some providers' free models may log or train on prompts, which is why Auto never picks them unless you choose to.

Depending on what you turn on, content can also go to:

  • another provider you've connected, when Auto routing picks it or a request fails over;
  • OpenAI or Google, to create embeddings for semantic search, and to transcribe audio you upload;
  • your cheapest connected model, to classify ambiguous requests (smart routing);
  • the web search provider you connect (Brave or Tavily), and web pages the AI reads for you;
  • MCP connectors you attach, and GitHub when you clone, pull or push.

You can turn these features off in Settings and per message.

4. Companies that process data for us

We use a small number of service providers, who may only use the data to provide their service to us:

  • Hosting and database: [Hosting provider, e.g. AWS / Render / Fly.io].
  • Email delivery: [Email provider, e.g. Postmark / Amazon SES].
  • Payments: Stripe, which processes payments and may act as merchant of record (handling sales tax and VAT). Stripe's own privacy policy covers the payment details it collects.

5. Other sharing

  • People you work with: members of projects you share and organizations you join can see the content in them, including your name and email and what you added.
  • Legal reasons: when required by law, or to protect the rights, safety and security of our users, the public or Plurtex. Where allowed, we'll tell you first.
  • Business changes: if Plurtex is part of a merger, acquisition or sale of assets, your information may transfer as part of it, still covered by this policy.

6. Cookies

Plurtex uses only cookies that are strictly necessary for it to work:

  • a sign-in session cookie, which keeps you logged in (up to 30 days, extended while you use the app);
  • short-lived cookies (10 minutes) that protect single sign-on and “Sign in with OpenRouter” from being tampered with.

We don't use analytics, advertising or cross-site tracking cookies. Stripe's checkout and billing pages, which run on Stripe's own website, set their own cookies.

7. How long we keep it

  • Your account and content are kept while your account exists. Archiving a project hides it; its data is deleted when you delete your account.
  • When you delete your account, we immediately and permanently delete your account, the projects you own (with their conversations, files and repositories), your keys, connectors, agents and sessions. Projects owned through an organization pass to its next admin instead, and things you added to other people's shared projects stay there, no longer linked to you.
  • Sign-in sessions expire after 30 days of inactivity. Single-use email links expire within hours to days.
  • We keep limited records longer where we need them for security, to resolve disputes, or to meet legal and tax obligations — for example payment records (kept by Stripe) and a record that an account was deleted.
  • Backups, where we keep them, are overwritten on a rolling basis.

8. Security

We protect your data with encryption in transit (HTTPS) and encryption of secrets at rest, hashed passwords, optional two-factor sign-in, strict browser security policies, rate limiting, isolation of code the AI runs, and approval prompts before risky tools act. You can see every device signed in to your account and sign any of them out.

No system is perfectly secure. If you find a vulnerability, please report it to [[email protected]].

9. Your choices and rights

  • Access and correct: see and edit your information in the app (Settings, Connections, your projects).
  • Delete: delete your account anytime in Settings → Security → Delete account.
  • Copy: export a project's repository from the app, or email us for a copy of your data.
  • Control sharing: disconnect providers and connectors, turn off features like semantic search, and remove people from projects at any time.

Depending on where you live (for example under the GDPR in the EU/UK, or US state laws such as the CCPA), you may have further rights, such as objecting to or restricting processing, data portability, and complaining to your data protection authority. We don't sell or “share” personal information for cross-context behavioral advertising. To make a request, email [[email protected]]; we'll respond within the time the law requires, and won't treat you differently for exercising your rights.

Where the GDPR applies, we process your data to perform our contract with you (running the Service), for our legitimate interests (security, abuse prevention, improving reliability), to meet legal obligations, and with your consent where we ask for it.

10. International transfers

We and our providers may process your information in countries other than yours, including the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses.

11. Children

Plurtex isn't for anyone under 18, and we don't knowingly collect their information. If you believe a child has given us personal information, contact us and we'll delete it.

12. Changes to this policy

If we make material changes, we'll notify you (for example by email or in the app) before they take effect. The date at the top shows when this policy last changed.

13. Contact

Questions or requests: [[email protected]], or write to [Company legal name], [Business address]. See also our Terms of Service.