Privacy Policy
Last updated: April 9, 2026
Plutyx ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at plutyx.com and our API at api.plutyx.com.
1. Information We Collect
We collect the following categories of information:
- Account Information: Name, email address, and profile picture when you register or sign in with Google.
- Usage Data: API requests made, features used, search queries, lead lists created, and automation sequences configured.
- Technical Data: IP address, browser type, operating system, and access timestamps for security and performance purposes.
- Billing Information: Subscription plan and payment status. Payment details are processed exclusively by Stripe and are never stored on our servers.
- Content You Create: Lead lists, sequences, and any data you upload or generate through the platform.
2. How We Use Your Information
- To provide, operate, and improve the Plutyx platform.
- To authenticate your identity and manage your account.
- To process your API requests and deliver lead intelligence results.
- To send transactional emails (account confirmation, password reset, billing receipts).
- To enforce our Terms of Service and prevent fraud or abuse.
- To analyze aggregate usage patterns and improve our services.
3. Google OAuth and Sign-In Data
When you sign in with Google, we request only your name, profile photo, and email address through Google's OAuth 2.0 service. We do not request access to your Gmail, Google Drive, Contacts, or any other Google service.
We use this information solely to create or authenticate your Plutyx account. We do not sell or share your Google account data with third parties.
4. Data Storage and Security
Your data is stored in Google Cloud Firestore (Firebase), a secure, encrypted cloud database hosted in Google's infrastructure. We implement the following security measures:
- All data in transit is encrypted via TLS/HTTPS.
- Authentication tokens are signed with industry-standard JWT (HS256).
- API secrets and credentials are stored in AWS Secrets Manager — never hardcoded.
- Our backend runs in isolated containers (AWS ECS Fargate) with no persistent local storage.
- Passwords are hashed using bcrypt before storage.
5. Data Sharing and Third Parties
We do not sell your personal data. We share data only with the following service providers, strictly to operate the platform:
- Google Firebase / Firestore — database storage.
- Amazon Web Services (AWS) — cloud infrastructure and secrets management.
- Stripe — payment processing. Stripe's privacy policy applies to payment data.
- Anthropic (Claude API) — AI-powered email generation (content only, no personal data).
6. Cookies and Local Storage
We use browser localStorage to store your authentication token and session preferences. We do not use advertising cookies or cross-site tracking. Essential session data is cleared when you sign out.
7. Data Retention
We retain your account data for as long as your account is active. Lead lists and sequences you create are retained until you delete them or close your account. Usage logs are retained for up to 90 days for security auditing.
8. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data.
- Portability: Export your lead lists and sequences in CSV or JSON format.
- Objection: Object to processing of your data for marketing purposes.
To exercise these rights, contact us at privacy@plutyx.com.
9. Children's Privacy
Plutyx is not directed at children under 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify registered users of material changes via email. Continued use of the platform after changes constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions or data requests:
- Email: privacy@plutyx.com
- Website: https://plutyx.com