Privacy Policy
Last updated: February 8, 2026
This Privacy Policy explains how PlumAI ("we," "us," or "our"), operated by a company registered under Portuguese law, collects, uses, and protects your personal data when you use our AI content creation platform at plumai.io ("the Service"). We comply with the EU General Data Protection Regulation (GDPR) and Portuguese data protection law.
1. Data We Collect
Data you provide
- Account data: Name, email address, and profile picture from your Google account when you sign in via Google OAuth.
- Payment data: Processed and stored by Stripe. We do not store your credit card number. We receive your Stripe customer ID and subscription status.
- Content: Topics, articles, translations, images, and other content you create through the Service.
- Support messages: Emails or messages you send to our support team.
Data collected automatically
- Usage data: Features used, articles generated, topics researched, and general interaction patterns.
- Device data: Browser type, operating system, screen size, and language preference.
- Log data: IP address, access times, pages viewed, and referring URL.
- Cookies: Session cookies to keep you signed in and preference cookies to remember your settings.
2. How We Use Your Data
- Provide, operate, and maintain the Service
- Process payments and manage your subscription
- Generate articles, images, and translations using AI providers
- Send transactional emails (account confirmation, billing receipts, subscription changes)
- Respond to your support requests
- Monitor usage to enforce plan limits and prevent abuse
- Improve the Service based on aggregated, anonymized usage data
- Comply with legal obligations
Legal basis (GDPR): We process your data based on (a) performance of a contract (providing the Service you subscribed to), (b) our legitimate interests (improving the Service, preventing fraud), and (c) your consent where required.
3. Third-Party Services
We share data with the following categories of third parties, only as necessary to provide the Service:
| Service | Purpose | Data shared |
|---|---|---|
| Google OAuth | Authentication | Name, email, profile picture |
| Stripe | Payment processing | Email, subscription plan |
| OpenAI | Article and image generation | Topic prompts, article content |
| Hosting provider | Infrastructure | All data (encrypted at rest) |
We do not sell your personal data. We do not use your content to train our own AI models.
4. Data Security
- All data in transit is encrypted via HTTPS/TLS
- Database access is restricted and password-protected
- Authentication tokens are short-lived and cryptographically signed
- Payment data is handled entirely by Stripe (PCI DSS compliant)
No system is 100% secure. We cannot guarantee absolute protection, but we take reasonable measures to safeguard your data.
5. Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Ask us to correct inaccurate data
- Erasure: Ask us to delete your personal data
- Portability: Request your data in a machine-readable format
- Restriction: Ask us to restrict processing while a complaint is being resolved
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Portuguese data protection authority (CNPD) or your local supervisory authority.
6. Cookies
We use the following types of cookies:
- Essential cookies: Required to keep you signed in and to operate the Service. These cannot be disabled.
- Preference cookies: Remember your settings (e.g. sidebar state, language). You can clear these in your browser.
We do not use advertising or third-party tracking cookies.
7. Data Retention
- Account data: Retained while your account is active.
- Content: Retained while your account is active. Deleted within 30 days of account closure.
- Payment records: Retained for 7 years as required by Portuguese tax law.
- Log data: Retained for 90 days, then automatically deleted.
8. International Transfers
Your data may be processed by third-party providers located outside the EEA (e.g. OpenAI in the United States). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
9. Children
PlumAI is not intended for anyone under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has created an account, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
11. Contact
For privacy-related questions or to exercise your data rights:
Email: [email protected]
General support: [email protected]