pliuzv0.1.x

Legal · Privacy

Privacy Policy

Placeholder. This page is a structural placeholder while we work with counsel on the formal document. We do not fake legal text. Full document available on request: founder@pliuz.com.

Pliuz processes minimal personal data: account email, optional name, optional profile photo. Our marketing site measures traffic with Google Analytics, which sets analytics cookies only if you accept them in the cookie banner — the product itself (app.pliuz.com) carries no analytics at all. We do not sell, share, or use personal data for advertising. We never train AI models on customer payloads. We respect both EU/UK (GDPR) and US (CCPA/CPRA) privacy rights, and we host your data in the EU wherever you are based — we serve teams worldwide, including the US.

  • Personal data we collect as controller: account email (required), name (optional), avatar (optional), Slack workspace mapping (when you connect Slack), founder@pliuz.com correspondence, and — if you join the pre-launch waitlist — your corporate email, company name and role (plus optional product context).
  • Personal data we process as processor (for Customer tenants): approval payloads (tool args), context messages (agent reasoning), approver identities, decisions + execution outcomes. Customer is the controller; Pliuz processes under DPA Art 28.
  • Audit log captures end-user PII of Customer tenants (third-party data subjects). SDK-side redaction primitives let Customer remove sensitive fields BEFORE they reach Pliuz. Tenant is responsible for identifying and instructing redaction.
  • Analytics: Google Analytics 4, on the marketing site only — never on app.pliuz.com. There are two states with two different legal bases, and we state both rather than simplify. If you accept in the cookie banner, analytics cookies (_ga) are set so returning visits can be told apart — basis: your consent, GDPR Art 6(1)(a). Before you choose, or if you decline, no analytics cookie is set and Google reads nothing from your device — the only thing stored is your own choice, listed in our cookie policy — but a single measurement signal carrying your IP still reaches Google — basis: legitimate interests, Art 6(1)(f), balanced against you by storing nothing on your device, creating no identifier and building no profile. We deliberately do not call that state anonymous. Declining and not answering are treated identically, and advertising storage stays denied in both — we run no ads and no remarketing.
  • Cookies: essential session cookies (Supabase Auth) in the product, plus optional Google Analytics cookies on the marketing site if you accept them. No marketing cookies, no advertising cookies, no cross-site tracking. Full detail and the switch to change your mind at any time: /legal/cookies.
  • Withdrawing consent (GDPR Art 7(3)): you can change your analytics choice at any time at /legal/cookies — one click, no account and no email needed. Withdrawal takes effect immediately for future measurement; it does not undo aggregate data already collected, which cannot be traced back to you.
  • Waitlist (pre-launch): if you opt in, we use your details only to tell you when Pliuz launches and to offer early access — legal basis is your consent (GDPR Art 6(1)(a)), via an unticked, unbundled checkbox with double opt-in confirmation. We pass your email to Resend (our email provider, EU region — Ireland) solely to send these messages. This is consent-based and uses no tracking cookies. One-click unsubscribe in every email; we delete unconverted leads within 12 months (or 6 months after launch, whichever is earlier).
  • Sharing: never sold, rented, or shared. Sub-processors only per /legal/subprocessors with 30-day notice on changes.
  • Data residency: your data is stored in the EU (Supabase Frankfurt, Vercel Frankfurt) wherever you are based — including for US-based users, whose personal data is sent to and stored in the EU. Two flows leave the EU and both are listed at /legal/subprocessors: Slack notifications use Slack US infrastructure when Customer opts in, and marketing-site analytics reach Google in the US. Both rely on the EU-US Data Privacy Framework with SCCs Module 2 as fallback. No Customer Data — audit events, approval payloads, decisions — is ever sent to Google.
  • Retention: account data deleted within 30 days of account closure on request. Audit event data per Customer-configured tenant policy (default per tier 7d / 90d / 1y / 10y). Retention enforcement implementation in progress.
  • Rights (GDPR): access (Art 15), rectification (Art 16), erasure (Art 17), portability (Art 20), restriction (Art 18), objection (Art 21). For data we control, email founder@pliuz.com — response within 30 days. For data of Customer end-users, contact the Customer (controller) first.
  • Rights (US / California — CCPA/CPRA): the right to know what personal information we collect, to delete it, and to correct it; and to opt out of the "sale" or "sharing" of personal information — moot here because we do not sell or share it. We do not discriminate against you for exercising these rights. Email founder@pliuz.com — response within 45 days; we verify your identity by control of the email on file.
  • No AI training, no payload reading for non-execution purposes — mechanically enforced (no ML pipeline; SDK-side redaction architecture) and contractually committed in the DPA.
  • No automated decision-making about humans (GDPR Art 22) — Pliuz exists to ENABLE human review, never to replace it.
  • Data controller for Pliuz-controlled data: Pliuz (founder@pliuz.com). Update to incorporated entity contact once entity is formed.

Last updated: 2026-09-05 (analytics section rewritten: Plausible removed, Google Analytics declared, consent banner added). Reviewed internally; independent counsel review pending. Material changes will be emailed at least 30 days in advance.