Skip to content

Legal

Privacy Policy

Last updated: 29 September 2026

This policy explains what personal data we collect when you visit plutonapps.com, talk to us, or use the Plutonapps Control Room, why we collect it, and what you can ask us to do with it. We have written it in plain language. If anything is unclear, email us.

Who we are

Plutonapps is a trading name of Bose and Turing Innovations FZCO ("Plutonapps", "we", "us"), a company incorporated in the United Arab Emirates (an IFZA free zone company), trade licence number 54549 (IFZA trade licence), registered at IFZA Properties, A1 - 3641379065, Dubai Silicon Oasis, Dubai, United Arab Emirates. We are the controller of the personal data described in this policy.

For anything about your data, email [email protected].

Which laws apply: we are based in the UAE, so the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies. Because we offer our services to people and businesses in the EU and EEA (including Norway) and the UK, the EU General Data Protection Regulation (GDPR, Article 3(2)) and the UK GDPR also apply to that processing. This policy is written to meet all of them.

If you are in the EEA or the UK, you can contact us about your rights at [email protected].

We have not appointed a Data Protection Officer. Our processing is not large-scale monitoring or large-scale special-category data, so GDPR Article 37 does not require one.

Where our customers use us to build and run their products, we process their end users' data on the customer's behalf. That is covered by our Data Processing Agreement, not by this policy; the customer is the controller and their privacy policy applies.

What we collect and why

WhatWhere it comes fromWhy (and legal basis)
Your account: name, email address, and, if you sign in with Google, the name, email and profile picture Google sharesYou, via our sign-in provider ClerkTo give you an account and keep it secure (contract, Art. 6(1)(b))
Your company and project details: organisation, team members you invite, onboarding answers (for example which compliance rules you need to meet), project settings and profile pictureYou and your team, in the Control RoomTo deliver the service you signed up for (contract)
What you send us: requests, messages with your account manager and their attachments, chat messages, meeting bookings, meeting notes and approvalsYou and your team; our staffTo do the work and keep a record of what was agreed (contract; legitimate interest in keeping accurate project records, Art. 6(1)(f))
Contact and enterprise enquiries: name, email, company and your messageThe forms on /contact and /enterprise-requestTo answer you (steps before a contract / legitimate interest)
A one-way, salted hash of your IP address when you submit an enquiryYour browser's connectionTo stop spam and abuse of the forms. We store the hash, not the address (legitimate interest)
Billing: plan, billing period, subscription status, renewal and cancellation dates, amounts paid, and the Stripe customer referenceStripeTo bill you and show your plan (contract; legal obligation to keep accounting records, Art. 6(1)(c))
Payment card detailsYou, on Stripe's own checkout pageHandled by Stripe as its own controller for payment processing. Your card details go to Stripe and never touch our servers
Lovable connection: a connection token you create to send work from Lovable to us (we store only a hash of it) and the content you choose to sendYou, from your Lovable workspaceTo receive work you send us (contract)
Technical data: IP address, browser, pages requested and error logs, kept by our hosting and network providersYour browserTo run the site securely and fix faults (legitimate interest)
Staff access records: which Plutonapps staff member opened a read-only view of your dashboard, and whenOur systemsAccountability for staff access to your data (legitimate interest)

We do not use analytics, advertising or tracking tools on this site, and we do not sell personal data or use it for automated decisions with legal effect.

We do not ask for special-category data (health, religion and so on). Please do not put it in messages unless it is needed for the work.

Who we share it with

We use a small number of service providers (processors) to run Plutonapps. Each only processes data on our instructions. The current list, with what each one does and where, is on our Sub-processors page.

Stripe processes payments as an independent controller for fraud prevention and its own legal obligations; see stripe.com/privacy.

We may disclose data if the law requires it, or to protect our rights, and to a buyer if Plutonapps is sold or merged (you will be told).

Our team works from Norway, the United States, the United Arab Emirates and India, and may access your data from any of those places to do the work.

International transfers

If you are in the EU, EEA or UK, your data leaves it: we are a UAE company, our team also works from the United States and India, and our main providers (Clerk, Supabase, Stripe, Resend and DigitalOcean) process data in the United States; our database is hosted by Supabase in AWS us-east-1 (North Virginia, USA). The UAE and India do not have an EU adequacy decision.

Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (with the UK Addendum for UK data) or the EU–US Data Privacy Framework where the provider is certified.

Data you give us directly from the EU/EEA or UK is collected by us in the UAE under GDPR Article 3(2) and the UK GDPR, and we apply the protections in this policy to it wherever it is handled. The same safeguards cover access by our staff in the UAE, the United States and India.

You can ask us for a copy of the safeguards that apply.

How long we keep it

  • Account and project records: for as long as you are a customer, then 12 months unless you ask us to delete them sooner. When a project is removed we archive it rather than delete it straight away, so it can be restored if the removal was a mistake.
  • Messages with your account manager: kept with the account. Attachments can be removed by you or us at any time; message text is kept as a record of what was agreed until the account's data is deleted.
  • Billing and invoices: as long as accounting law requires (at least 5 years under UAE tax law).
  • Enquiries: 24 months after our last contact, unless they become a customer relationship.
  • Server and security logs: kept by our hosting providers for their standard periods.

Deleting data at the end of an account is currently done by us on request rather than automatically. Email us and we will do it.

Your rights

Under the GDPR, the UK GDPR and the UAE PDPL you can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; and give it to you in a portable format. Where we rely on consent you can withdraw it at any time. We answer within one month.

Email [email protected]. We may need to confirm who you are first.

You can also complain to a data protection authority: in Norway, Datatilsynet (datatilsynet.no); in the UK, the ICO (ico.org.uk); in the EU, the authority where you live or work; in the UAE, the UAE Data Office. We would appreciate the chance to fix things first.

If you are in a US state with a consumer privacy law (for example California), you have similar rights to know, correct and delete your data. We do not sell or share personal information for cross-context behavioural advertising.

Security

Our database is not reachable from the public internet except through our own server code; sign-in is handled by Clerk; card data is handled only by Stripe; and staff access to customer dashboards is recorded. No system is perfectly secure, and we will tell you and the authorities without undue delay if a breach puts your data at risk.

Cookies

We use only cookies and browser storage that the site needs to work, such as keeping you signed in. See our Cookie notice.

Children

Plutonapps is a business service and is not meant for anyone under 16.

Changes

If we change this policy in a way that matters, we will update the date at the top and tell customers by email before it takes effect.