Plutar logo Plutar
Home How It Works About Pricing Support
Download

Privacy Policy

Last updated: August 22, 2026

This Privacy Policy explains how Plutar collects, uses, stores, and shares information when you visit the website or use Plutar services.

On this page

Information We Collect How We Use Information How We Share Information Artificial Intelligence Services Native App Data Data Retention Your Privacy Rights Contact

1. Information We Collect

  • Contact details you submit such as name, email, business name, and project notes.
  • Subscription status and purchase-entitlement information processed by Apple or other applicable payment providers. Plutar does not receive payment-card details entered directly with those providers.
  • Account, workspace, and software usage information needed to provide services, save progress, restore drafts, and secure accounts.
  • When you choose to use Pluto AI, information you submit for AI processing, such as prompts, messages, business profile information, business goals and plans, relevant task or roadmap information, user-provided revenue or business metrics, and conversation context needed to answer your request.
  • If you grant location permission, location information such as country, state, county, city, postal code, and device coordinates with an accuracy value. A precise coordinate summary may be used when locality lookup is unavailable.
  • If you use voice input in the native app, microphone audio is processed through Apple's speech-recognition service. If you use voice input on the website, a short recording is sent to Plutar's server and processed by OpenAI's transcription service. In both cases, the transcript is returned for your review, and Plutar does not retain the raw microphone recording as account content.
  • If you choose to connect a financial institution through Plaid, Plutar may process institution and account identifiers, account names and types, masked account details, balances, transaction details, and derived revenue or expense summaries. Plaid access credentials are stored encrypted in private service storage.
  • Technical data such as browser type, user agent, device details, request identifiers, service latency, and feature-usage telemetry.
  • Fraud-prevention and trial-protection signals such as IP address, hashed device or browser fingerprint, local trial identifiers, referral or source data, and signup, login, verification, and trial timestamps.

2. Sources of Information

  • Directly from you when you create an account, use forms, update workspace fields, contact support, or make a purchase.
  • Automatically from your device and browser when you use the website or app.
  • From payment, hosting, storage, security, and email-delivery vendors that support the service.
  • From Apple services used for StoreKit subscriptions, speech recognition, location and geocoding, and write-only calendar actions that you initiate.
  • From Plaid only when you choose to start and complete a bank connection.

3. How We Use Information

  • To provide and improve services, software features, and support.
  • To save workspace progress, restore recent work, and sync account data across return visits or devices.
  • With your consent, to process requests and provide responses through Pluto AI using OpenAI-powered services.
  • To communicate about onboarding, billing, and service updates.
  • To monitor performance, prevent abuse, and maintain security.
  • To prevent repeated free-trial abuse, enforce rate limits, detect suspicious signups or logins, and support internal fraud review.
  • To comply with legal obligations and enforce agreements.

4. Fraud Prevention and Trial Protection

Plutar uses technical and behavioral signals to protect free trials, accounts, and infrastructure from abuse. These controls may include IP-based checks, hashed browser or device fingerprinting, local trial identifiers, account email patterns, user agent review, approximate country or region information, and signup, login, verification, and trial activity timestamps.

  • We use these signals to score risk, detect repeated trial creation, enforce rate limits, flag suspicious activity, and block abusive behavior when necessary.
  • Hashed fingerprints are stored instead of raw device fingerprint values where practical.
  • Fraud decisions are logged internally for security review and manual follow-up.
  • We do not publicly expose the internal rules used to make anti-abuse decisions.

5. How We Share Information

  • With service providers that support hosting, storage, payments, email delivery, analytics, security, and customer communications.
  • With OpenAI, our third-party AI provider, only when you have consented to AI processing and use Pluto AI, as described in the Artificial Intelligence Services section below.
  • With Apple when you use Apple-provided services such as speech recognition, StoreKit, location and geocoding, or an action that writes an event to Apple Calendar.
  • With Plaid when you voluntarily start or use the bank-connection and financial-data features.
  • When required by law, legal process, or to protect rights and safety.
  • During business transitions such as mergers, acquisitions, or restructuring.

Third-party service providers that receive user information, including OpenAI when AI processing is enabled, are required to protect it to the same or an equivalent standard described in this Privacy Policy and required by applicable law.

Artificial Intelligence Services

When a user enables and uses Pluto AI, Plutar uses services powered by OpenAI, a third-party artificial intelligence provider, to provide that functionality. OpenAI processes information submitted through Pluto AI so that Plutar can generate a response to the user's request.

In the app, Plutar sends information to OpenAI only after the user explicitly approves AI Data Sharing. On the website, the visitor chooses whether to send a prompt, image, or microphone recording by activating the applicable composer control; content is not submitted for AI processing until the visitor takes that action.

Depending on the request and the information the user chooses to provide, the following categories may be sent to and processed by OpenAI:

  • User prompts and messages sent to Pluto AI.
  • Business profile information voluntarily provided by the user.
  • Business goals and business planning information.
  • Relevant task, roadmap, and review information.
  • Revenue or other business metrics provided by the user when relevant to the request.
  • A locality or, if locality lookup is unavailable, a coordinate summary when location permission is enabled and location is relevant to the request.
  • Recent conversation context and relevant workspace context required to answer the request.

Plutar sends only information relevant to the AI request. These categories are not sent to OpenAI through Pluto AI unless the user has provided consent and uses an AI feature that requires the information.

AI processing is optional. App users may decline AI processing or later withdraw consent in Settings > Privacy > AI Data Sharing. Website visitors may stop using the AI composer or microphone at any time. These choices prevent future submissions but do not reverse processing that was completed before the choice was made.

Plutar may retain signed-in AI conversation history and related workspace information as part of saved account or workspace data under the retention practices described below. Anonymous website conversation continuity is kept only in the current browser tab session and is not saved as account memory by Plutar. Data submitted to AI services may be processed by OpenAI according to its applicable retention and processing practices. Plutar does not claim a fixed retention period for data processed by OpenAI.

Users may withdraw AI consent, stop using AI features, or request deletion of their Plutar account and associated data through the in-app account deletion control or the privacy request process described in this Policy.

Native App Data and Optional Integrations

  • Voice: In the native app, Apple speech recognition may process microphone audio to produce a transcript, and Plutar receives the transcript. On the website, OpenAI's transcription service processes a short user-initiated recording. The website places the resulting transcript in the composer for editing and does not send it to Pluto AI automatically. Plutar does not save an account-level copy of the raw recording.
  • Location: Location access is optional. Plutar requests kilometer-level accuracy for local business guidance, stores the returned jurisdiction and coordinates on the device, and may include a locality or coordinate summary in an AI request after AI Data Sharing consent. Coordinate values can meet Apple's definition of precise location even when requested at reduced accuracy.
  • Calendar: Plutar requests write-only calendar access to add, update, or remove events that you initiate. Plutar does not read or continuously synchronize your calendar.
  • Notifications: Plutar schedules local notifications on the device. This version does not register a remote-push device token with Plutar's servers.
  • Contacts: Contact synchronization is not included in this app version. Leads are entered manually.
  • Plaid: Bank connectivity is optional and is not required to use the rest of Plutar. When enabled, Plaid and Plutar process the financial information needed to show connection state, balances, transactions, and revenue or expense summaries. Disconnecting removes the active Plaid item and Plutar's stored connection record.

6. Cookies and Similar Technologies

Plutar and partner tools may use cookies or similar technologies to keep services functioning, measure performance, improve user experience, and support abuse prevention controls such as trial identifiers, anonymous website AI usage limits, session continuity, and security checks.

7. Data Retention

We retain information only as long as reasonably necessary for the purposes described in this policy, unless longer retention is required by law.

Saved Pluto AI conversation history and related workspace information are handled as account or workspace data under this general retention standard.

Anonymous website Pluto messages are kept in the current browser tab for conversation continuity and are not written to Plutar account memory. A signed, limited-duration cookie is used to enforce anonymous AI usage limits.

Data submitted to AI services may be processed by OpenAI according to its applicable retention and processing practices.

Fraud and abuse monitoring records are generally retained for up to 90 days unless a longer period is needed for security review, dispute handling, legal obligations, or enforcement activity.

8. Your Privacy Rights

Depending on your location, you may have rights to request access, correction, deletion, portability, or limitation of personal data processing. You may also request information about how your data is used.

You may withdraw AI consent in Settings, stop using Pluto AI, and request deletion of your account and associated data using the in-app account deletion control or the privacy request process below.

For account deletion steps, data categories, and the verified web-request method, visit Delete your Plutar account. To make another privacy request, email support@plutar.net with enough information for us to verify your request and locate the right account.

9. U.S. State Privacy Disclosures

If U.S. state privacy laws apply to your information, you may have additional rights and we will handle requests as required by applicable law.

  • We collect identifiers, commercial information, internet or network activity, geolocation (including device coordinates when location permission is enabled), account content, and security-related signals as described above.
  • We use these categories to operate the service, process payments, support users, secure accounts, prevent abuse, and improve the product.
  • Authorized agents may submit requests where applicable, subject to verification.

10. Security

Plutar uses reasonable administrative, technical, and organizational measures to protect data, including security controls around account access, trial abuse monitoring, and internal review tools. No method of transmission or storage is guaranteed to be 100% secure.

11. Children's Privacy

Plutar is intended for business users and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

12. Changes to this Policy

We may update this policy from time to time. Updates are posted on this page with a revised "Last updated" date.

13. Contact

Questions or privacy requests: support@plutar.net.

Related policies Terms of Service Refund Policy Earnings and Results Disclaimer Delete Account Support

© Plutar. Built for calm business execution.

About Terms Refund Privacy Delete Account Disclaimer Support