Privacy Policy
Last updated 01 April 2026
If you are in the United States, see the Privacy Policy (US).
1. Categories and Examples of Personal Data Collected
We collect certain personal data when you: (a) create or manage an account, subscribe to, access, or use our Services; (b) communicate with us, including by submitting inquiries, feedback, or support requests via email, post, or telephone; and/or (c)subscribe to or interact with our marketing communications. The categories of personal data we collect, and the circumstances in which they are collected, include the following: a) Email address is collected when you: (i) create an account or subscribe to our Services; (ii) communicate with us via email or contact forms; or (iii) opt in to receive marketing communications or newsletters. b) Other identifiers (such as your name, postal address, or phone number) are collected when you voluntarily provide such information, for example when you: (i) contact our support team or request assistance; (ii) submit feedback, refund requests, or other inquiries; or (iii) include such information in correspondence with us. c) Customer records information collected when you: (i) complete forms, quizzes, or surveys intended to personalize your experience; (ii) provide demographic or preference information in your account profile; or (iii) participate in promotional, research, or feedback initiatives within the Services. d) Device and internet activity information is automatically collected when you access or use the Services. This may include: device type, operating system, and browser type; IP address and device identifiers; advertising identifiers; and usage data such as session duration, accessed features, and interactions with content. This information is collected through cookies, SDKs, analytics tools, and similar technologies to operate, secure, analyze, and improve the Services. e) Inputs and generated content (as defined in the Terms of Service) are collected when you interact with AI-powered features of the Services. Inputs and Generated Content may be processed by third-party AI model providers acting as our data processors or, in limited cases, as independent controllers, depending on the specific service. We implement contractual safeguards to ensure that such providers: (i) process personal data solely for the purpose of providing the requested functionality; (ii) do not use personal data for their own independent purposes, including model training, unless explicitly permitted and disclosed; (iii) apply appropriate technical and organizational security measures. We retain Inputs and Generated Content for as long as your account remains active in order to enable continuity of Service and session recovery. We do not use Inputs or Generated Content to train our own models. Personal data contained in Inputs may be transmitted to providers located outside the EEA, subject to the safeguards described in Section 4. If you delete specific content or close your account, we will delete such data unless retention is reasonably necessary to comply with legal obligations, to enforce our agreements or resolve disputes, or to meet the technical or contractual requirements of third-party AI model providers. You should avoid including personal data in Inputs unless necessary. You may request deletion of Inputs or Generated Content at any time by contacting support@plurius.ai. f) Commercial information that includes records of Services purchased, subscription status, transaction timestamps, and renewal information. We do not collect or store full payment card details. Payment information is processed directly by third-party payment service providers. g) Profiling and Personalization. We may analyze personal data to evaluate certain aspects of your preferences or behavior to personalize the Services (profiling within the meaning of Article 4(4) GDPR). Such profiling does not produce legal effects or similarly significant effects within the meaning of Article 22 GDPR. 1.2. Personal data we receive from third parties. From time to time, we may receive personal data about you from third-party sources, including: a) Google Inc. in case of Google Sign-In or your use of our Services via Google Play: when you use the “Sign in with Google” feature to access our Services, we receive personal data from your Google account, which may include your name, email address, and profile picture. You can manage what data is shared through your Google account settings. Google will also provide detailed privacy information during the Sign in with Google process. b) Apple Inc. in case of Apple Sign-In or your use of our Services via AppStore: when you use the Sign in with Apple feature to download our mobile application and start using our Services, we receive personal data from your Apple ID account, which may include your name and email address. You have the option to share your actual email address or an anonymous email address that utilizes Appleʼs private email relay service. Apple will provide detailed privacy information during the Sign in with Apple process. c) Advertising, Analytics, and Strategic Partners: we may receive data from advertising networks, analytics providers, and other business partners. This data may include mobile advertising identifiers, hashed email addresses, phone numbers, cookie identifiers, and insights regarding your activity on external websites or mobile apps. We use this data to better understand your interests and tailor the Service accordingly. d) Payment Processors: when you make a payment through the Services, you provide your financial details (e.g., credit card number) directly to licensed payment processors (such as Stripe). While we do not collect or store full credit card numbers, we may receive limited payment-related information such as the transaction date, time, amount, and payment method type. e) Other Sources: we may obtain additional personal data from our vendors engaged in facilitating or providing Services, publicly available sources, third-party data providers, or other sources, such as publicly available registries, fraud prevention databases, where permitted by applicable law. 1.3. No Special Categories of Personal Data: we do not knowingly request, collect, or process special categories of personal data within the meaning of Article 9 GDPR. This includes, without limitation, data revealing racial or ethnic origin, religious or philosophical beliefs, genetic or biometric data, health-related data, or data concerning a natural personʼs sex life or sexual orientation. You are explicitly instructed not to include any such sensitive or special category data when submitting Inputs or otherwise interacting with our AI-powered Services. However, if you voluntarily and intentionally include such information in your Inputs, that information will be processed solely at your request and only for the purpose of generating the requested Output. In such cases, In such cases, the processing is based on your explicit consent (Article 9(2)(a) GDPR), which you provide by voluntarily submitting such data. We do not access, use, store, analyze, or retain such sensitive or special category data for any secondary purposes, including profiling, analytics, or model training, unless required by applicable law. 1.4. No Personal Data of Minors: our Services are not directed to children, and we do not knowingly collect or process personal data from individuals under the age of 16, in accordance with Article 8 GDPR. If we become aware that we have collected personal data from an individual under the age of 16 due to false, misleading, or incomplete information, we will take reasonable steps to promptly delete such personal data and suspend access to the Services while the matter is reviewed. If we confirm that an individual under the age of 16 is using the Services, we will permanently disable access in order to comply with applicable data protection laws.
2. Purposes and Legal Bases for Processing and Sharing of Personal Data.
We collect and process personal data for the following business and commercial purposes, in accordance with the principles of lawfulness, fairness, transparency, and data minimization. We collect and use your personal data for the following purposes: 2.1 Purposes of processing We process personal data for the following purposes:
- To provide and operate the Services, including account registration and management, user authentication, subscription administration, payment processing, billing, and customer support.
- To maintain, improve, and personalize the Services, including analyzing usage patterns, troubleshooting, optimizing performance, developing new features, and personalizing content and user experience.
- To promote and grow the Services, including instructing selected marketing and advertising partners (such as mobile measurement partners, social media platforms, and search engines) to create aggregated or look-alike audiences based on user characteristics, where permitted by law and subject to your consent where required.
- To communicate with you, including responding to inquiries, providing service-related notices, updates, security alerts, and other administrative or transactional communications.
- To send marketing communications, where permitted by law, we may send you promotional messages about our Services. You may opt out of marketing communications at any time by using the unsubscribe link included in each message or by contacting us directly.
- To comply with legal obligations, including compliance with tax, accounting, financial reporting, anti-fraud obligations, and lawful requests from courts, regulators, or public authorities.
- To protect rights, safety, and security, including enforcing our Terms of Service, detecting and preventing fraud, misuse, or unlawful activity, and protecting the rights, property, and safety of our users, business partners, and ourselves.
2.2. Sharing of Personal Data. We may share personal data with the following categories of recipients, only to the extent necessary for the purposes described above and subject to appropriate contractual and legal safeguards: Service providers and vendors, including providers of cloud hosting, infrastructure, analytics, customer support tools, IT services, and payment processing (e.g., payment processors such as Stripe). These providers process personal data on our behalf under contractual obligations consistent with Article 28 GDPR. Advertising and analytics partners, including partners that help us measure performance, analyze usage, or deliver personalized advertising, subject to your consent where required under applicable law and as further described in Section 3 (“Cookies and Other Tracking Technologies”). Corporate transactions, in connection with a merger, acquisition, reorganization, sale of assets, or similar transaction, personal data may be disclosed or transferred as part of such transaction, subject to applicable data protection safeguards. Legal and compliance recipients, where disclosure is required by applicable law, regulation, court order, subpoena, or governmental request, or where necessary to establish, exercise, or defend legal claims. The table below summarizes the processing purposes, applicable legal bases, and categories of third parties involved in each processing activity. We encourage you to review the privacy policies of these third parties. We are not responsible for their privacy practices where they act as independent controllers. Summary Table of Processing Purposes, Legal Bases, and Service Providers
| Processing Purpose | Category of Data Processed | Legal Basis / Purpose | Service Providers / Third Parties | Retention Criteria |
|---|---|---|---|---|
| Account creation, service delivery, and subscription management | Identifiers, Customer Records Information | Legitimate interests (Article 6(1)(f) GDPR), namely Services provision and maintenance | Apple Inc. — Apple Privacy Policy; Google LLC — Google Privacy Policy; Stripe, Inc. — Stripe Privacy Policy | Retained for the duration of the account and up to 30 days after deletion (except where retention is required by law) |
| Customer communication and support (including inquiries, feedback, and contact requests) | Identifiers, Customer Records Information | Legitimate interests (Article 6(1)(f) GDPR), namely customer support and Service improvement | Google Workspace (Gmail) — Google Privacy Policy; Zendesk, Inc. — Zendesk Privacy Policy | Retained for up to 12 months after resolution of an inquiry |
| Marketing communications and personalization | Identifiers, Inferences, Customer Records Information | With your opt-in consent (email marketing) or legitimate interest, where permitted | Mailchimp (Intuit Inc.) — Mailchimp Privacy Statement; Google Analytics / Ads — Google Privacy Policy | Retained until you unsubscribe or withdraw consent |
| Analytics, operations, debugging, and service optimization | Device and Internet Activity Information, Inferences | Legitimate interests (Article 6(1)(f) GDPR), namely improving, securing, and optimizing Services | Apple App Analytics — Apple Privacy Policy; Firebase (Google LLC) — Firebase Privacy Policy; Facebook (Meta Platforms, Inc.) — Meta Privacy Policy; Amplitude, Inc. — Amplitude Privacy Notice | Retained for up to 24 months, after which data is deleted or anonymized |
| Payment processing and billing | Identifiers, Commercial Information | Legitimate interests (Article 6(1)(f) GDPR), namely accounting and tax compliance | Stripe, Inc. — Stripe Privacy Policy | Retained for the period required under applicable law |
| AI-powered functionality (Inputs and Generated Content) | Inputs, Generated Content, Device and Internet Activity Information | Legitimate interests (Article 6(1)(f) GDPR), namely provision of AI-powered Services | OpenAI, L.L.C. — OpenAI Privacy Policy; Anthropic PBC — Anthropic Privacy Policy; Google LLC (Gemini) — Privacy hub; DeepSeek — DeepSeek Privacy Policy; Stability AI Ltd. — Stability AI Privacy Policy; Immersive Tech Ltd (Loremax AI) — https://loremax.ai/privacy | Retained while Services are used; deleted upon user request unless retention is required by law or third-party provider policies |
| Disclosure to infrastructure and security providers | Identifiers, Device and Network Data | Legitimate interests (Article 6(1)(f) GDPR), namely secure hosting, performance, and reliability | Amazon Web Services, Inc. (AWS) — AWS Privacy Notice; Cloudflare, Inc. — Cloudflare Privacy Policy | Retained for the duration of the account and up to 30 days after deletion (except where retention is required by law) |
Where we rely on legitimate interests as a legal basis for processing, we ensure that such interests are not overridden by your fundamental rights and freedoms. Our legitimate interests include improving and securing the Services, understanding user behavior, preventing fraud, and maintaining business operations. Where processing is based on consent, you may withdraw your consent at any time as described in Section 6. Where processing is necessary for the performance of a contract, failure to provide the required personal data may result in our inability to provide the Services
3. Cookies and other Tracking Technologies
3.1. What are the Tracking Technologies. When you visit or interact with our Website or use our Services, we and our service providers may use cookies, web beacons, software development kits (SDKs), pixels, and similar tracking technologies (collectively, “Cookies”) to collect certain information automatically. Some of this information may constitute personal data under applicable data protection laws. Cookies are small text files stored on your device that enable us or our partners to recognize your browser or device and remember certain information. Cookies help us operate the website securely and efficiently, understand how the Services are used, personalize content, and support analytics and marketing activities, where permitted by law. Web beacons (also known as “pixels”) are small transparent images embedded in web pages or emails. They help us understand whether content has been viewed or interacted with. For example, we may use pixels in marketing emails to measure open and click-through rates and to improve the effectiveness of our communications. When you use our mobile application (if available in your region), we and our third-party partners may collect and use mobile advertising identifiers, such as Google Advertising ID (GAID) on Android devices; and Identifier for Advertisers (IDFA) on Apple devices. These identifiers are user-resettable identifiers provided by your deviceʼs operating system and may be used for analytics, attribution, fraud prevention, and advertising purposes, subject to your consent where required by law. Although these identifiers do not directly identify you by name, they may constitute personal data under applicable privacy laws. 3.1. Types of Cookies We Use (1) Session and persistent cookies: ● Session cookies last as long as your online session and disappear from your device when you close your browser. ● Persistent cookies stay on your device after you close your browser and last for a time specified in the cookie (unless deleted by you earlier). (2) First-party and third-party cookies: ● First party cookies are set by the website. Only we can read them. ● Third-party cookies are set by someone other than our website. You may adjust your browser settings to prevent the receipt of third-party cookies, or to provide notification whenever such third-party cookies are sent to you. While the cookies that we use may change from time to time, the cookies we use serve the following main purposes: ● Strictly necessary cookies are essential for the operation of the Website, so that you can navigate it and use its features. Without them some parts of the website will not work. ● Functionality cookies allow the Website to remember choices you make to provide better functionality and personalized features. These cookies may be set by us or by third-party services we have added to our pages. If you do not allow them then some or all of these services may not function properly. ● Analytics and performance cookies help us improve the performance of the Website based on the information about how the Website is used, for example, page views and traffic sources. ● Advertising and marketing cookies may be used to build a profile of your interests and show you relevant adverts on other Websites. These cookies can be set through the Website by us or our partners. Analytics, functionality, and advertising cookies are used only where you have provided your consent, unless an exemption applies under applicable law. 3.3. Opt-out from Third-party Tracking Technologies From time to time, we may also use third party tools such as: · Google Analytics and Google Ads – Google Privacy Policy and Ad Settings; · Facebook (Meta) Pixel and Custom Audiences – Meta Privacy Policy; · Apple App Analytics – Apple Privacy Policy; · Firebase Analytics – Firebase Privacy Policy. These third parties may collect or receive information from your device and use it to provide analytics, measurement, attribution, or advertising services, subject to their own privacy policies and applicable legal requirements. Where required by law, we obtain your prior consent before placing or accessing these non-essential cookies. To opt out of these cookies: (i) you can opt out of providing your mobile advertising identifiers through your device settings, including resetting the identifier or opting out of interest-based advertising (for example, by enabling “Limit Ad Personalization” on Android or disabling “Allow Apps to Request to Track” on iOS). (ii) you can delete the cookies installed in the past and manage preferences for cookies in your browser settings. How to manage cookies in the most popular browsers: ● Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac ● Google Chrome: https://support.google.com/chrome/answer/95647?hl=en ● Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer ● Internet Explorer: https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies ● Edge: https://support.microsoft.com/en-gb/help/4027947/microsoft-edge-delete-cookies (iii) manage preferences for third-party cookies via the tools provided by those parties. For example, you can manage Googleʼs cookies by visiting Google Ad Settings or installing Google Analytics Opt-out Browser Add-on. You may also follow the instructions provided by the Network Advertising Initiative (US), the Digital Advertising Alliance (US) or other similar services. Such initiatives allow you to select tracking preferences for most of the advertising tools. (iv) opt out of third-party advertising or analytics cookies at any time by adjusting your preferences in the banner or through the “Cookie Settings” link available in the footer of our Website. When you disable these categories of cookies: (a) we will stop allowing third-party advertising or analytics cookies to collect your data for cross-context behavioural advertising; and (b) we will record and maintain your preference for at least twelve (12) months, after which we may ask you to reconfirm your choice. If your browser or device supports the Global Privacy Control (GPC) signal, we will also treat such signals as a valid request to opt out of sale or sharing of your personal data. Please note that: (a) opting out of advertising or analytics cookies does not affect cookies that are strictly necessary for the operation or security of the Website; (b) if you block or delete cookies in your browser settings, this may mean that the Website preferences will be lost and that you might not be able to access or use some of its features.
4. Where we process and transfer your information
We host and process personal data primarily in the European Economic Area. Due to the global nature of our operations and our use of service providers and AI model providers, personal data may be transferred to and processed in countries outside your country of residence, including outside the European Economic Area (EEA), where data protection laws may differ from those in your jurisdiction. Where personal data is transferred outside the EEA to a country that has not been recognized by the European Commission as providing an adequate level of data protection, we rely on appropriate safeguards in accordance with Chapter V GDPR, including the E.U. Standard Contractual Clauses, where applicable, the UK SCCs, supplementary technical and organizational measures, such as encryption, access controls, and data minimization. These safeguards are designed to ensure that your personal data remains protected in accordance with GDPR requirements, regardless of where it is processed. You may request additional information about international data transfers and applicable safeguards by contacting us using the details provided in this Privacy Policy.
5. How we protect your information
We are committed to protecting your information through robust technical and organizational measures. Our security framework is designed to protect your personal data from unauthorized access, use, disclosure, copying, modification, destruction, and accidental loss or misuse. We implemented industry-standard security controls, including but not limited to:
- Access Controls: we enforce role-based access controls and apply the principle of least privilege, ensuring that access to personal data is limited to authorized personnel and contractors who require such access for legitimate business purposes.
- Data Encryption: to prevent unauthorized access, tampering, or interception of your personal data, we employ strong encryption mechanisms: (i) in transit: we utilize TLS encryption (e.g., TLS 1.2 or higher) to secure data while it is transmitted from us to you; (ii) at rest: all data stored within our infrastructure is encrypted using AES-256 industry standards, ensuring an additional layer of protection; (ii) backups: regular encrypted backups are maintained to ensure data availability and integrity in the event of an incident.
- Regular Security Audits: we conduct regular penetration testing, vulnerability assessments, and security audits to proactively identify and mitigate potential risks.
- Antivirus and Intrusion Prevention Systems (IPS): deployed to monitor and prevent unauthorized access and potential threats in real-time.
- Incident Response and Breach Notification: we maintain documented incident response procedures to address suspected or confirmed security incidents. In the event of a personal data breach, we will assess the risk and, where required by law, notify the relevant supervisory authority and affected individuals within the timeframes prescribed by applicable data protection laws.
6. What are your rights and choices?
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights in relation to your personal data, subject to the conditions and limitations set out in the GDPR.
- Right to request access. You may obtain confirmation as to whether or not we process your information, learn about the details of such processing and obtain a copy of the information that we process.
- Right to request correction. You may request that inaccurate or incomplete personal data be corrected or updated. We may take reasonable steps to verify the accuracy of the information you provide.
- Right to request erasure. You may request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent and no other legal basis applies, where the data has been unlawfully processed, or where erasure is required by law.Please note that we may not be able to comply with your request where retention is necessary for legal obligations or for the establishment, exercise, or defense of legal claims. Where applicable, we will inform you of such reasons.
- Right to object to processing. You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where we rely on legitimate interests (or those of a third party).You also have the right to object at any time to the processing of your personal data for direct marketing purposes. You may unsubscribe from marketing communications by using the unsubscribe link in such emails or by contacting us at the email address below.
- Right to request restriction of processing. You may request the restriction of processing of your personal data where: (a) you contest the accuracy of the data; (b) the processing is unlawful and you oppose erasure; (c) we no longer require the data, but you need it for the establishment, exercise, or defense of legal claims; or (d) you have objected to processing and verification of overriding legitimate grounds is pending.
- Right to data portability. You may request to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, and to have that data transmitted to a third party, where the processing is based on consent or contract and carried out by automated means.
- Right to withdraw consent. Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. If you withdraw consent, we may no longer be able to provide certain products or services, and we will inform you where this is the case.
- Right to lodge a complaint with a supervisory authority. If you are dissatisfied with how we process your personal data, you have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the country of your habitual residence, place of work, or place of the alleged infringement.
To exercise any of your rights, please contact us at support@plurius.ai. We will confirm receipt of your request and respond without undue delay and in any event within one (1) month, which may be extended by up to two additional months, where permitted by law. Before fulfilling your request, we may need to verify your identity using information you provide, and data already associated with your account. If we cannot verify your identity, we may be unable to process your request for security and fraud-prevention reasons. All verified requests are processed free of charge, unless they are manifestly unfounded or excessive.
7. How long do we keep your information
We keep your information for as long as it is necessary for the purposes outlined in section 2 above, based on the nature of the data, the purpose of processing, and applicable legal requirements. We may retain your information if required to do so by law or upon an order of a state authority.
8. Links to third-party resources
Our Services may contain links (including those embedded into the ads distributed via our Services) to third-party resources that are not administered by us and are not governed by this Privacy Policy. We encourage you to familiarize yourself with the privacy policies and security practices of the linked third-party websites before providing them with any personal data.
9. Changes to the Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, regulatory requirements, or to address feedback received from our customers. Any changes will be published on this page, and we encourage you to review it regularly to stay informed about how we protect your information. When we post changes, we revise the "Last Updated" date at the top of this policy. If we make any material changes in the way we collect, use, or share your information, we will notify you by prominently emailing you, and if required by applicable law, we will request your consent for such changes.
10. Language
Any translation of the English version of this Privacy Policy is provided solely for your convenience. In case of any differences between the English version and any other translation, the English version shall prevail and shall be the only legally binding version.
11. Contact Information
If you have questions or comments regarding this Privacy Policy and our privacy practices, or you have any requests to exercise your legal rights, please contact us by email support@plurius.ai.