# Privacy policy

Source: https://v2.plugster.ai/en/privacy

## Privacy policy

This page covers the account holder’s own data. Visitors of a client site are never tracked by Plugster: no cookie, no identifier, no profile is built about them, and no identifier of theirs is written to the database. When they question a site through an AI assistant, the call journal keeps the question as it arrives (a search, a product asked about), with no identifier that ties it to a person. A caller’s address is held in memory for a few minutes, to cap how often the same caller may call, and never stored by the service itself. The web server in front of it (nginx) does keep its access logs, which carry the address of every request, including a visitor’s browser loading the script of a client site: they are kept 14 days for security only, neither analysed nor tied to an account or a visitor, and deleted past that.

## Data controller

TooLooLoo, Raphaël Hue, 29 rue des Trois Rois, 44000 Nantes, France. Contact: hello@plugster.ai.

## Data collected

Account email and a hashed password; the language and the promotion code the account signed up with; the Stripe customer and subscription identifiers and the subscription’s status; the sites declared and their crawl results; a journal of the tool calls made against a site (date, tool, transport, agent family rather than its raw header, parameters as received, result count, latency), never the full content returned.

## Purposes and legal bases

Each processing has its legal basis (GDPR, article 6). Performance of the contract: running the account, the crawl, the tools and the dashboard, showing an owner what AI assistants search for on their site, and sending the email the account needs (password reset, address confirmation, end of a discount, suspension of a site and the reminder before its deletion, loss of ownership of a site). Legal obligation: billing and keeping invoices, held by Stripe. Legitimate interest: the security of the service (the web server’s logs, the caps on call frequency) and the cookieless audience measurement described below.

## Cookies

Four cookies, all exempt from consent: the session cookie that keeps an account signed in (thirty days), the language cookie set by the language switch (one year), and two about promotion codes (thirty days), one holding the code a campaign link carried so that it can be applied at payment, the way a basket holds what was put in it, the other remembering that the banner announcing it was closed. None is set by a third party, none is used for tracking or advertising, and none serves to build a profile.

## Audience measurement

The pages of the service are counted with Umami, an open-source tool hosted on the same server as the service, not by a third party. It sets no cookie and keeps no identifier of a visitor: a page view is recorded with the page (without the parameters of its address), the referring site, the browser family and the country. The visitor’s address is only combined with a salt that changes every day into a hash that tells two views of the same day apart; the address itself is never stored, and no visit can be followed from one day to the next or tied to a person. This measurement is exempt from consent. Nothing is shared or sold.

## Processors

Three providers see part of an account holder’s data. OVHcloud (OVH SAS, France) hosts the server, the database and its backups, in the European Union. Stripe (Stripe Payments Europe, Ireland) sells the subscription in its own name, as reseller of the service, and handles payment, invoicing and VAT: it receives the account email and its billing details, as an independent controller for those, under its own privacy policy; Plugster never sees or stores a card number. Resend (Resend Inc., United States) sends the transactional email and receives the recipient address and the message. Stripe and Resend may process data outside the European Union, under the standard contractual clauses their terms carry. No other third party receives anything, and nothing is ever sold or used for advertising.

## Retention

The web server’s access logs and the system log are kept 14 days. The tool-call journal is kept 90 days and purged past that age. Account and site data are kept for as long as the account exists; those of a site suspended because the account’s plan no longer covers as many, and that its holder has not kept, are purged 60 days after the suspension. All are purged immediately, with no grace period, when the account is deleted, the subscription being cancelled at the same moment. Two copies outlive that purge for a while: the database backups, kept 14 days on the server and 60 days in an encrypted copy off the server, after which the deleted account is gone from them too; and the customer Stripe holds (email, invoices), which Stripe keeps for as long as its own legal obligations require, ten years for invoices.

## Rights

An account holder can access, correct or delete their data from the profile page at any time, and download it as a JSON file (account, sites, settings, calls counted per day) (portability). They can also object to a processing based on legitimate interest, or ask for one to be restricted. For anything the page does not cover, write to hello@plugster.ai; a complaint can also be lodged with the CNIL (France’s data protection authority).

## Contact

hello@plugster.ai

---

Agent-ready by Plugster. Any site, readable and actionable by AI agents: https://plugster.ai
