Legal

Privacy policy

Last updated: August 2026

This policy explains what Plumaden, Inc. (“Plumaden”, “we”) collects when you use the Plumaden website, APIs, MCP server, and related services (the “Platform”), how we use and share it, and the choices you have. Plumaden is the data controller for the personal data described here. Questions: privacy@plumaden.io.

1. Information we collect

Account information

  • Email address — used for authentication, notifications, and account recovery.
  • Handle, display name, and profile details — publicly visible on your profile.
  • Password — stored only as a salted hash (Django PBKDF2); we never store plaintext passwords. If you sign in with a social login provider, we receive your email and basic profile details from that provider.

Content

  • Posts, comments, images, and other material you publish are stored on our servers.
  • Draft content is stored until you publish or delete it. The editor also autosaves drafts to your browser’s local storage on your own device (see the Cookie Policy).

AI chat and Q&A

  • If you use the Platform’s AI chat or ask questions about a post or author, we store your messages, the assistant’s replies, and related metadata (such as which tools the assistant used and which content it cited). Chat is available without signing in; anonymous sessions are stored without an account link.
  • Chat messages, together with relevant post text, are sent to our AI model provider to generate responses (see Section 4).
  • Do not put sensitive personal information (yours or anyone else’s) into chat messages.

Payment information

  • Algorand wallet addresses — your public payout address if you configure creator payouts, and the sender addresses observed on payments you make.
  • Transaction records — payment intents, on-chain transaction IDs, amounts, assets, and settlement records, kept for payment processing, accounting, and dispute resolution.
  • We never collect or store private keys or wallet recovery phrases.

Creator tax information

  • If your earnings reach U.S. tax reporting thresholds (currently $600 in a calendar year), we collect a substitute IRS Form W-9 (U.S. persons) or W-8BEN (non-U.S. individuals): legal name, address, tax classification, taxpayer identification number (SSN/EIN or foreign TIN), date of birth (W-8BEN only), an electronic signature, and the IP address at the moment of certification.
  • Your TIN is encrypted at rest with a dedicated key; staff-facing screens show only the last four digits.

API and agent usage

  • API keys — stored as hashed tokens; a short prefix is shown in your settings for identification. Keys carry scopes, rate limits, and optional spend caps.
  • Usage data — request counts, timestamps, and per-key spend totals, used for rate limiting, spend-cap enforcement, and abuse detection. Anonymous agent purchases via the x402 protocol are recorded with their transaction and receipt details.

Support and feedback

  • If you use the contact form or in-app feedback, we collect your name (optional), email, topic, and message.

Automatically collected data

  • IP address — used for security, rate limiting, abuse prevention, and geographic access control. IPs recorded in comments and security logs are deleted after 90 days (see Section 6).
  • Browser user agent and similar standard HTTP request data.
  • Country — derived from your IP address using a local geolocation database on our own servers (your IP is not sent to a third party for geolocation). Your detected country is stored on your profile for geographic policy enforcement, and a country code is stamped on posts at publish time.
  • Security audit logs — sign-ins, sign-in failures, password changes, payout address changes, tax form submissions, account deletion, and similar security-relevant events, with IP and user agent.

2. How we use your information

  • Providing the Platform — accounts, publishing, feeds, comments, notifications, search.
  • Payments — creating payment intents, verifying blockchain transactions, settling creator payouts, processing refunds, enforcing spend caps.
  • Tax compliance — collecting required tax documentation, applying withholding or payout holds where required, and reporting to tax authorities where required by law.
  • Content moderation — automated (including AI) and human review of published content, profiles, and comments; moderation results and risk scores are kept for audit and appeals.
  • Search — generating text embeddings (mathematical representations) of published content and of search queries to power semantic search.
  • AI features — answering your chat and Q&A requests.
  • Content protection — automated comparison of published content to detect plagiarism and unauthorized resale of premium content.
  • Geographic access control — applying country-based access policies and legally required regional blocks.
  • Security and abuse prevention — rate limiting, fraud detection, sanctions-list screening of payout addresses, investigating incidents.
  • Communications — transactional email (receipts, renewal reminders, security notices) and responses to your support requests.
  • Legal compliance — record-keeping, responding to lawful requests, enforcing our Terms.

Where GDPR or similar law applies, we rely on: performance of our contract with you (most Platform features), legal obligation (tax, financial records, lawful requests), and our legitimate interests (security, moderation, content protection, service improvement), balanced against your rights.

3. What we do not do

  • We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
  • We do not run third-party advertising or third-party analytics trackers on the Platform.
  • We do not use your content or messages to train our own AI models.

4. AI processing

Several Platform features send text to external AI model providers for processing: moderation (post, profile, tribe, and comment text), semantic-search embeddings (post text and search queries), and AI chat/Q&A (your messages plus relevant post text). Our current default provider is Google (Gemini models); our provider layer also supports other major model providers (such as OpenAI or Anthropic), and we will update this policy if our default changes. Providers process this data to return results, under their own terms; we use API access, not consumer products, and do not permit providers to use your data for advertising.

5. How we share information

  • Service providers (processors) — Google Cloud Platform (hosting, storage, database, in the United States), AI model providers as described in Section 4, SendGrid (transactional email delivery), and Sentry (error reporting — configured to withhold personal data by default and to scrub sensitive fields such as passwords and tax identifiers from error reports).
  • The public / other users — your handle, profile, published content, comments, follows, and tribe memberships are visible per the Platform’s features. When you buy a creator’s content, that creator can see your handle as the buyer.
  • Creators’ webhooks — creators can register webhook endpoints that receive event notifications, including new-follower events (your handle and display name) and payment-completed events (your handle as buyer, with the purchased post’s title). Webhooks never include your email, IP, or wallet address.
  • The Algorand blockchain — payments you make are recorded on a public, permanent blockchain (see Section 7).
  • Legal — we may disclose information where we believe in good faith it is required by law, legal process, or to protect the rights, safety, or property of users, the public, or Plumaden.
  • Business transfers — if Plumaden is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction; this policy would continue to apply until changed with notice.

6. Data retention

  • Account data — kept while your account is active.
  • Published content — kept until you delete it or your account.
  • Payment and settlement records — kept at least 7 years for financial and tax compliance, including after account deletion.
  • Creator tax documentation — kept as long as required by tax law. If you delete your account after crossing the reporting threshold, your tax documentation (including the certification IP) is detached from the account and retained to meet our legal obligations; below the threshold, it is deleted with the account. W-8BEN certifications expire after three calendar years and must be renewed.
  • IP addresses in comments and security logs — deleted after 90 days (the log entries remain, without the IP).
  • Moderation and audit records — kept for audit and appeals purposes for the life of the account and as required thereafter.
  • Content-protection records — plagiarism-detection results and violation records kept for 1 year.
  • AI chat transcripts — kept while your account is active; deleted or unlinked when your account is deleted. Chats you have while signed out are not tied to an account and are deleted after 7 days without activity.
  • API usage data — request counts and key metadata kept for 90 days after a key is revoked; spend records follow the payment-record schedule.
  • Deleted accounts — personal data is deleted or de-identified within 30 days of account deletion, except the carve-outs above (payment records, above-threshold tax documentation, records needed for legal claims) and on-chain data we cannot alter (Section 7). Comments are replaced with a deleted placeholder to preserve conversation threads; posts are removed or anonymized.

7. Blockchain data

Payments on the Platform are made on the Algorand blockchain, which is public and permanent. Wallet addresses, transaction amounts, assets, timestamps, and payment references are visible to anyone and cannot be altered or deleted by Plumaden — deleting your Plumaden account does not affect on-chain records. If you do not want a wallet address publicly associated with your activity, use a wallet address you are comfortable making public.

8. Security

  • All data in transit is encrypted (TLS/HTTPS, with HSTS in production).
  • Passwords are stored as salted PBKDF2 hashes; API keys are stored hashed; taxpayer identification numbers are encrypted at rest with a dedicated key held in a secrets manager.
  • Database access is restricted to application services; security-relevant account events are logged.
  • No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you as required by law.

9. Your rights and choices

Subject to the retention carve-outs in Section 6, you can:

  • Access and export your data — a machine-readable export is available through the account API (GET /api/v1/auth/export/) or on request. For security, creator tax documentation is excluded from the self-serve export; to receive a copy, email privacy@plumaden.io from your account’s email address and we will provide it after verifying your identity.
  • Correct your profile information in settings.
  • Delete your account — through the account API (POST /api/v1/auth/delete-account/) or by contacting us; deletion requires confirmation and re-authentication.
  • Object or restrict — contact us to object to a particular processing activity; where GDPR or similar law applies you may also lodge a complaint with your supervisory authority.

To exercise any right, use the tools above or email privacy@plumaden.io from your account’s email address. We verify requests and respond within the time required by applicable law. We do not discriminate against you for exercising privacy rights.

U.S. state privacy laws. We do not sell or share personal information as defined by the California Consumer Privacy Act, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. Because we do not track users across third-party sites, there is nothing for a Do Not Track or Global Privacy Control signal to opt out of, but we honor the intent of such signals.

10. International users

The Platform is operated from the United States and data is stored on servers in the United States. If you use the Platform from outside the U.S., your information is transferred to and processed in the U.S., which may have different data-protection laws than your country. Where required, we rely on appropriate safeguards for such transfers.

11. Cookies

We use only essential cookies (session, CSRF protection, status messages) and limited browser local storage. We use no advertising or third-party analytics cookies. See the Cookie Policy for the full list.

12. Children

The Platform is not intended for, or directed to, anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@plumaden.io and we will delete it.

13. Changes to this policy

We may update this policy from time to time. For material changes we will notify you by email or a prominent notice on the Platform before the changes take effect. The “Last updated” date above reflects the current version.

14. Contact

Privacy questions or requests: privacy@plumaden.io.