Skip go di main content

Legal

Privacy Policy

Last update: 5 October 2026

Dis policy dey explain which personal data we dey collect when you visit plutonapps.com, talk to us, or use di Plutonapps Control Room, why we dey collect am, and wetin you fit ask us to do with am. We write am for simple language. If anything no clear, email us.

Who we be

Plutonapps na trading name of Bose and Turing Innovations FZCO ("Plutonapps", "we", "us"), company wey dem incorporate for United Arab Emirates (company for IFZA free zone), trade licence number 54549 (IFZA trade licence), wey dem register for IFZA Properties, A1 - 3641379065, Dubai Silicon Oasis, Dubai, United Arab Emirates. Na we be di controller of di personal data wey dis policy describe.

For anything about your data, email hello@plutonapps.com.

Which laws dey apply: we dey based for UAE, so di UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) dey apply. Because we dey offer our services to people and businesses for EU and EEA (including Norway) and UK, di EU General Data Protection Regulation (GDPR, Article 3(2)) and di UK GDPR also dey apply to dat processing. We write dis policy to meet all of dem.

If you dey for EEA or UK, you fit contact us about your rights for hello@plutonapps.com.

We never appoint Data Protection Officer. Our processing no be large-scale monitoring or large-scale special-category data, so GDPR Article 37 no require one.

Where our customers dey use us to build and run their products, we dey process their end users data for di customer behalf. Na our Data Processing Agreement cover dat one, no be dis policy; di customer na di controller and na their privacy policy dey apply.

Wetin we dey collect and why

WetinWhere e come fromWhy (and legal basis)
Your account: name, email address, and, if you sign in with Google, di name, email and profile picture wey Google shareYou, through our sign-in provider ClerkTo give you account and keep am secure (contract, Art. 6(1)(b))
Your company and project details: organisation, team members wey you invite, onboarding answers (for example which compliance rules you need to meet), project settings and profile pictureYou and your team, inside di Control RoomTo deliver di service wey you sign up for (contract)
Wetin you send us: requests, messages with your Product Owner and their attachments, chat messages, meeting bookings, meeting notes, approvals and your answers to di team decisionsYou and your team; our staffTo do di work and keep record of wetin we agree (contract; legitimate interest to keep correct project records, Art. 6(1)(f))
SOS calls: who call, which emergency e concern, who answer, when e ring, when dem answer and when e end, how long e last, and whether e use your emergency allowance. Di call itself na live audio between your browser and our own and we no dey ever record or store am; e fit pass, encrypted, through relay wey Cloudflare dey operateYou and our staff, when you start or answer SOS callTo answer emergencies and keep di same record wey we dey keep for requests (contract; legitimate interest to keep correct project records)
Google Calendar connection, if you choose to connect one: di Google account email address, encrypted refresh token, and di busy times and events wey we dey read or write for calls wey you book with usYou, when you connect your Google Calendar inside di Control Room; GoogleTo put your calls for your calendar with Meet link and offer only times wey fit you (contract)
Contact and enterprise enquiries: name, email, company and your messageDi forms for /contact and /enterprise-requestTo answer you (steps before contract / legitimate interest)
Production-readiness check: your email, di name and app address wey you give (we keep am as text; we no dey ever visit am), your answers, your score, whether you tick di box for updates, and di campaign tags for di link and di page wey send you come (none of di two if your browser dey send Do Not Track or Global Privacy Control). Only when you ask for di report by email; di check itself dey run inside your browserDi form for /tools/production-readiness-checkTo send you di report wey you ask for and tell our team (steps wey you ask for / legitimate interest). Emails about our work once in a while only if you tick di box, and you fit withdraw am anytime (consent, Art. 6(1)(a))
One-way, salted hash of your IP address when you submit enquiry or ask for readiness reportYour browser connectionTo stop spam and abuse of di forms. We dey store di hash, no be di address (legitimate interest)
Billing: plan, billing period, subscription status, renewal and cancellation dates, amounts wey you pay, and di Stripe customer referenceStripeTo bill you and show your plan (contract; legal obligation to keep accounting records, Art. 6(1)(c))
Payment card detailsYou, for Stripe own checkout pageStripe dey handle am as im own controller for payment processing. Your card details dey go Stripe and dem no dey ever touch our servers
Lovable connection: connection token wey you create to send work from Lovable come meet us (we dey store only hash of am) and di content wey you choose to sendYou, from your Lovable workspaceTo receive work wey you send us (contract)
Technical data: IP address, browser, pages wey you request and error logs, wey our hosting and network providers dey keepYour browserTo run di site securely and fix faults (legitimate interest)
Site analytics: di page wey you view, di site wey send you come (referrer) and any campaign tags for di link, your device type, browser, operating system, screen size and language, your country (wey we calculate from your IP address, wey we no dey store), and some site actions like to open di chat, choose plan or complete paymentYour browser, wey Umami dey measure, analytics tool wey we dey host by ourselvesTo see which pages and campaigns dey work and improve di site (legitimate interest, Art. 6(1)(f)). No cookies, and never your name, email address or anything wey you type
Staff access records: which Plutonapps staff member open read-only view of your dashboard, and whenOur systemsAccountability for staff access to your data (legitimate interest)

Our analytics no dey use cookies and na we dey host am. We dey run Umami for our own server, so we no dey share di data with analytics company. E no dey set cookies and e no dey store your IP address. E dey count visits with one-way hash of your IP address and browser details, mixed with value wey dey change every month, so e no fit recognise you for other sites or from one month to the next. E no dey build profile of you. If your browser dey send Do Not Track or Global Privacy Control signal, di site no go load am at all. We no dey ever measure di areas wey you need sign in for (your dashboard and our staff area), except say we dey count completed sign-up or payment once, without anything wey fit identify you.

We no dey use advertising or tracking tools for dis site, and we no dey sell personal data or use am for automated decisions wey get legal effect.

We no dey ask for special-category data (health, religion and so on). Abeg no put am inside messages unless di work need am.

Who we dey share am with

We dey use small number of service providers (processors) to run Plutonapps. Each one dey process data only on our instructions. Di current list, with wetin each one dey do and where, dey our Sub-processors page.

Stripe dey process payments as independent controller for fraud prevention and im own legal obligations; see stripe.com/privacy.

We fit disclose data if di law require am, or to protect our rights, and to buyer if dem sell Plutonapps or merge am (we go tell you).

Our team dey work from Norway, United States, United Arab Emirates and India, and dem fit access your data from any of those places to do di work.

International transfers

If you dey for EU, EEA or UK, your data go comot from there: we be UAE company, our team also dey work from United States and India, and our main providers (Clerk, Supabase, Stripe, Resend and DigitalOcean) dey process data for United States; Supabase dey host our database for AWS us-east-1 (North Virginia, USA). UAE and India no get EU adequacy decision.

Where we transfer personal data outside EEA or UK, we dey rely on correct safeguards, like di European Commission Standard Contractual Clauses (with di UK Addendum for UK data) or di EU–US Data Privacy Framework where di provider get certification.

Data wey you give us directly from EU/EEA or UK, na we dey collect am for UAE under GDPR Article 3(2) and di UK GDPR, and we dey apply di protections for dis policy to am anywhere wey dem handle am. Di same safeguards cover access by our staff for UAE, United States and India.

You fit ask us for copy of di safeguards wey dey apply.

How long we dey keep am

  • Account and project records: as long as you be customer, then 12 months unless you ask us to delete dem before. When we remove project we dey archive am instead of to delete am sharp-sharp, so we fit restore am if di removal na mistake.
  • Messages with your Product Owner: we dey keep dem with di account. You or we fit remove attachments anytime; we dey keep message text as record of wetin we agree until we delete di account data.
  • Billing and invoices: as long as accounting law require (at least 5 years under UAE tax law).
  • Enquiries: 24 months after our last contact, unless e become customer relationship.
  • Production-readiness check requests: 24 months after you ask for di report, unless e become customer relationship.
  • Server and security logs: our hosting providers dey keep dem for their standard periods.
  • Site analytics: 24 months, then we go delete am.
  • Google Calendar connection: until you disconnect am or we delete di account data; to disconnect dey cancel our access for Google and delete di token.

For now, na we dey delete data at di end of account when you request am, e no dey happen automatically. Email us, or ask from di app or di account deletion page, and we go do am.

Your rights

Under di GDPR, di UK GDPR and di UAE PDPL you fit ask us to: give you copy of your data; correct am; delete am; restrict or object to how we dey use am; and give am to you for portable format. Where we rely on consent you fit withdraw am anytime. We go answer inside one month.

Email hello@plutonapps.com. We fit need confirm who you be first.

You fit also complain to data protection authority: for Norway, Datatilsynet (datatilsynet.no); for UK, di ICO (ico.org.uk); for EU, di authority where you dey live or work; for UAE, di UAE Data Office. We go appreciate am if you give us chance to fix things first.

If you dey for US state wey get consumer privacy law (for example California), you get similar rights to know, correct and delete your data. We no dey sell or share personal information for cross-context behavioural advertising.

Security

Database access need credentials wey only our servers and small number of named engineers dey hold, and row-level security also dey protect customer data; Clerk dey handle sign-in; only Stripe dey handle card data; and we dey record staff access to customer dashboards. No system dey perfectly secure, and we go tell you and di authorities without undue delay if breach put your data for risk.

Cookies

We dey use only cookies and browser storage wey di site need to work, like to keep you signed in. Our analytics no dey set cookies. See our Cookie notice.

Children

Plutonapps na business service and e no dey meant for anybody wey never reach 16.

Changes

If we change dis policy for way wey matter, we go update di date for top and tell customers by email before e start to work.