Privacy Policy
Last updated: August 8, 2026
Plug Pro is operated by Plug Marketplace LLC, 522 W Riverside Ave STE N, Spokane, WA 99201 (“Plug,” “we,” “us”). This policy explains how we collect, use, and protect your information when you use Plug Pro — our back office for creators.
1. What we collect
We collect the following categories of information:
- Account info — email, password (hashed), display name, niche tags, location city/region/country.
- Profile & storefront content — bio, vibe tags, pinned posts, social account handles and follower counts pulled from public APIs you connect, audience demographics you provide, rates and packages you publish, and reviews.
- Connected platform data (OAuth) — when you choose to connect a social platform through OAuth (YouTube via Google; TikTok; Instagram, Facebook, and Threads via Meta; Twitch; Kick; Pinterest), we read your account’s public statistics (subscriber or follower count) and basic identity (your channel ID, handle, or username) to show a verified follower count on your Plug profile and keep it current. To refresh that count over time, we store the access and refresh tokens the platform issues — encrypted at rest and used only to re-read your public follower or subscriber count on a periodic schedule. These tokens never let us read your private videos, comments, messages, or email, and we never post, change, or delete anything on your connected account. When you disconnect a platform — or close your account — we delete the stored tokens and stop refreshing. Platforms we don’t support through OAuth are self-declared — you enter the handle and follower count yourself.
- Subscription & billing data — we store your plan and tier (including that an account is on the free tier), and, if you subscribe to a paid plan, your Stripe customer and subscription identifiers, your billing status and period dates, your locked founding price (if any), and a record of your paid and failed subscription invoices (amount, currency, status, and a link to the Stripe-hosted invoice). If you make a one-time purchase (an AI credit pack, or a Plug tap card), we record it too. We never store card numbers or bank details — those are handled by Stripe.
- Shipping details (tap card) — if you claim or buy a physical Plug tap card, we store the name and postal address you give us to ship it, as part of the order record.
- Payment & payout details — since brands pay you directly, we store the identifiers and links needed to run that off-platform: your own connected Stripe or PayPal account identifiers (for the optional “pay online” button, which settles into your account), and the payout links you save to print on invoices (for example PayPal, Venmo, or Cash App). We store identifiers and links, never full card or bank numbers.
- AI inputs & creative data — when you use our AI features (Workbench, deal intake, Assistant, Scam Scanner, Video Analysis, negotiation and pitch drafting, career and outreach tools), we process what you submit: pasted text, uploaded images and documents (such as brand briefs and contracts), and video files — plus, to personalize the output, relevant context from your account: your profile (name, niche, rates), your learned style guide and writing/voice samples, and, for deal-aware tools, the deal’s brand name, amount, deliverables, and messages (for example, the negotiation helper reads the deal’s message thread to draft a reply, and the daily brief summarizes your deals and calendar on a schedule). We also store what these tools build and generate — style summaries, briefs, concepts, hooks, scripts, and pitch drafts. These inputs are sent to our AI providers (see section 3).
- AI usage metering — AI features are metered, so we track your AI usage: on a paid plan, how many credits your account holds and has consumed, the per-action cost, your monthly reset date, and any credit packs you buy; for the limited assists available on any account, a daily counter that enforces their caps.
- Support messages — messages you send to our in-product help are stored with the automated triage result and reply, so we can follow up and improve support.
- Deal activity — the deals and offers you log, messages exchanged on a deal, the milestone confirmations you record (such as marking a deal delivered or paid), and reviews and testimonials.
- Contracts & e-signatures — the contract documents you create and send, and, when a brand signs one electronically, the signer’s name and email and the resulting signed PDF, processed through our e-signature provider (see section 3).
- In-person event details — for appearance bookings we store the deal’s logistics and the brand’s on-site host contact (name, phone, email), any credentials or files attached, and your post-event verification photos. Photos may carry embedded location and timestamp (EXIF) data, which becomes part of the deal’s private record.
- Legal name (in-person, optional) — for some in-person bookings you can choose to share your legal name with the brand for entry or credentials; we record that choice.
- Livestream data (livestream bookings) — if a booking includes a livestream, we record that your connected channel went live during the event window and capture stream metadata and periodic frames as proof, stored privately on the deal.
- Usage data — pages visited, features used, in-product events recorded against your account with a timestamp (for example, that you reached a free-tier usage limit or started an upgrade), IP address, browser and device info, error logs.
- Signup-funnel measurement — on our marketing pages we record first-party events (for example, typing in the homepage handle claim or viewing an offer screen) keyed to a random identifier stored in a 90-day first-party cookie, so we can measure which pages lead to signups. If you sign up, those events are linked to your account. Details are in our Cookie Policy. No advertising or cross-site tracking is involved.
- Tap-card scans — when someone taps a Plug card or scans its QR code, we log the tap with its time, browser details (user agent), referrer, and approximate country, and show aggregate tap counts to the card’s owner. The tap log itself stores no IP address or identity; the visitor’s IP is used separately in a rate-limit counter to prevent fake taps.
- Login & security records — when you sign up or sign in, we record the event with the IP address and browser/device (user-agent) at that moment. We use these records to detect fraud, abuse, duplicate or coordinated accounts, and Terms violations. They’re kept for about 180 days, then deleted.
- Precise location (in-person deals only) — when you check in at an event venue or capture an event photo, we record your device’s GPS location and the time at that moment to confirm attendance. We collect this only when you actively check in or take a photo, and only for in-person appearance deals. It becomes part of that deal’s private record, visible to you, the brand on the deal, and Plug (for support). The receipt view shows your distance from the venue, not a map or street address. Separately, the brand-directory map’s optional “Use my location” button reads your device location once to suggest your metro area — we store only the metro name, never your coordinates.
- Brand contact data — the brands and contacts you save into your outreach workspace, and the business contact details we provide through Brand Radar. Because this can include personal data about people who aren’t Plug users, it is described separately in section 11.
- Push notifications — if you enable them, we store the push subscription your browser issues so we can deliver alerts. You can revoke it any time in your browser or notification settings.
2. How we use it
We use your data to:
- Run your Plug Pro back office — your profile and storefront, your logged deals, invoices, and licensing
- Provide AI features (Workbench, Assistant, Scam Scanner, Video Analysis, career and outreach tools) and meter your AI usage
- Bill your Plug subscription through Stripe, and record that a brand paid you directly when you confirm receipt
- Generate verifiable license certificates for the rights you grant
- Send transactional emails (offer accepted, contract signed, payment reminders, etc.)
- Send emails you direct us to send to a contact you provide — for example a deal share link, an invoice or payment reminder, a vouch request, or a license notice. Recipients can opt out of non-essential messages, and we stop emailing addresses that bounce or mark our mail as spam
- Track delivery and engagement of the email we send (delivered, bounced, complained, opened, clicked) so we can debug delivery problems and honor suppression
- Send product updates and marketing emails — you can opt out any time via the unsubscribe link or your settings; transactional emails about your deals and account are always sent
- Detect and prevent fraud, abuse, and Terms violations — including with automated tools and AI
- Improve the product through aggregated analytics
3. Sharing
We share data only as needed to operate the Service:
- With the brands you deal with — information tied to a specific deal is shared with the brand to complete it: for example your deliverables, the license terms, or (if you choose) your legal name on an in-person booking.
- Publicly, on your storefront — your public profile and storefront (display name, bio, niche tags, social handles, rates, packages, portfolio, and reviews) are visible to anyone who views your page, including brands you pitch.
- With Stripe — for two separate purposes: (1) to bill your flat Plug Pro subscription, where you are the Stripe customer; and (2) where a brand chooses to pay you by card, a direct charge to your own connected Stripe account, which we facilitate but never process, hold, or receive. See Stripe’s privacy policy for how they handle data.
- With PayPal — where you enable it, a brand’s online payment is made to your own PayPal merchant account; Plug never takes custody of the funds.
- With Supabase — our database, authentication, and file-storage provider. They process data on our behalf under their data processing agreement.
- With Vercel — our hosting provider, which handles HTTP traffic and deployment logs.
- With Resend — our email provider, used to deliver transactional email and to maintain a marketing-contact audience (your email and first name) reflecting your marketing-email opt-in choice. Resend reports delivery and engagement events back to us (delivered, bounced, spam complaints, opens, clicks), which we keep to debug delivery and stop emailing addresses that bounce or complain. Where reply-by-email deal threads are available, Resend also receives email replies sent to a deal’s Plug address (including attachments) so we can post them into the deal conversation.
- With Cloudflare — for security, bot detection, and spam prevention, including the verification challenge on signup and sign-in. This may process your IP address and request metadata.
- With our error-monitoring provider (Sentry) — to capture diagnostic and crash data, which can include IP address and device/browser details, so we can fix problems.
- With our AI providers — Anthropic, Google (Gemini), and OpenAI. When an AI feature runs, the content involved — text you submit, uploaded images and documents such as contracts, video files, and the account and deal context described in section 1 (profile, style guide, and for deal-aware tools the deal’s details and messages) — is sent to one of these providers to generate the response. Roughly by task: Anthropic powers the Assistant, Scam Scanner, negotiation analysis, support triage, and the daily brief; Google (Gemini) powers creative drafting, deal intake from briefs, and Video Analysis; OpenAI powers pitch, outreach, and reply drafting (text only — we don’t send it images or video). Some processing is automatic rather than per-request: for example, an inbound offer (including the sender’s message, email address, and attached documents) may be scanned for scam signals, and the daily brief summarizes your deals on a schedule. We use all three providers through their business APIs and do not use your content to train Plug’s own models; each provider’s handling of data submitted to its API is governed by that provider’s own terms. A video you submit for analysis is uploaded to Google’s file API for processing; we delete it after analysis on a best-effort basis, and it otherwise expires on Google’s side (currently about 48 hours, per Google). Other content travels inside the API request itself and is retained only per the provider’s API data policy.
- With DocuSeal — our e-signature provider. When you send a contract for signature, the contract text and the signer’s name and email are processed by DocuSeal, which emails the signer and returns the signed PDF.
- With logo and brand-identity providers (Brandfetch, logo.dev) — when you add a brand by its website, or when we enrich a brand-directory listing, we send the brand’s public website domain and fetch its public name, logo, colors, description, and social links to display on the record (cached on our side; as a fallback we read the same details from the brand’s own website).
- With post-verification providers (Microlink, ApiFlash, Thum.io) — on paid plans, when you submit a live post link as a deal deliverable, we send that public URL to these services to read the post’s public caption/preview and capture a screenshot as delivery evidence; captured screenshots are stored with the deal (some preview images may be served from the provider’s CDN). We also use them to read a brand website’s public metadata when adding a brand.
- With browser push services (such as Apple, Google, or Mozilla) — if you enable notifications, to deliver them to your device.
- With mapping / geocoding providers (Mapbox, with OpenStreetMap / Nominatim as a fallback) — venue addresses and location or city searches you type are sent to return suggestions and locate them. When you view the brand-directory map, the map imagery loads in your browser from OpenStreetMap’s tile servers, which receive your IP address and the map area you view.
- With Google Fonts — some public storefront and pitch-page themes load a display font from Google’s font CDN, so a visitor’s browser (yours or a brand’s) sends its IP address and browser details to Google when such a themed page loads. The Plug app itself serves its fonts from our own servers.
- With the public (license verification) — a content license’s verification page (getplug.io/verify/…) is accessible to anyone who has the link, and only if you choose to publish it. It shows only scoped, public-safe fields (see section 10) — never your messages, payment details, contact info, or IP/device data.
- For legal reasons — when required by law, court order, or to investigate fraud or abuse.
We do not sell your personal data.
4. Cookies and tracking
We keep cookies to a minimum, and the cookies Plug itself sets are first-party — set by us, readable only by us. The complete list — every cookie name, what it does, and how long it lasts — is in our Cookie Policy. In summary:
- Sign-in cookies — issued by our authentication provider (Supabase) to keep you signed in, plus a session-activity cookie that signs you out after about 14 days of inactivity.
- Security cookies — short-lived tokens (about 10 minutes) that protect flows like connecting a social platform or Stripe account against cross-site request forgery. The Cloudflare bot-detection challenge on signup and sign-in (see section 3) may also set its own cookie for that check.
- Feature cookies — for example, remembering that a brand unlocked a PIN-protected share link (30 days), holding a handle you claimed during signup (30 minutes), or remembering your pipeline layout choice.
- A signup-source cookie — if you arrive through a tagged link (for example a creator’s link-in-bio), we set a 30-day first-party cookie recording that channel so we can attribute your signup to it. It contains a single word like “linktree” — nothing about you.
- A measurement cookie — a first-party cookie holding a random identifier (90 days) that lets us count signup-funnel events on our own marketing pages and connect them to your account if you sign up (see section 1). It is not shared with anyone and does not track you across other sites. It is not set, and not read, for visitors in the EU/EEA or UK.
- View-count cookies — when anyone opens a public pitch page, a plugd.cc link, or a shared deal/invoice link, we set a 30-minute first-party cookie so refreshes and re-opens aren’t counted as new views. It contains no identifier — just a marker that the view was already counted. For visitors in the EU/EEA or UK we set no cookie and de-duplicate on our own servers instead.
Our page-view analytics (Vercel Web Analytics) is cookieless — it reports aggregate page views without setting cookies, fingerprinting, or following you across sites. We run no advertising trackers and no third-party ad cookies, and we don’t use cookies for cross-site tracking of any kind. We also use browser storage (localStorage) for preferences, drafts, and — if you followed a creator’s invite link — that invite code, so the person who invited you is credited when you sign up; that data stays in your browser except where the Cookie Policy notes otherwise. You can clear or block cookies and site data in your browser settings; blocking the sign-in cookie will sign you out. Because we suppress every non-essential cookie for EU/EEA and UK visitors, this site shows no cookie consent banner — see the Cookie Policy.
5. Data retention
We retain your account data for as long as your account is active. When you close your account we scrub your profile as described in section 6, and what remains is kept linked to the anonymized account record: deal records (terms, timelines, messages, and delivery evidence), subscription, invoice, and order records (typically up to seven years, for legal, tax, and dispute obligations), license certificates and their acceptance logs (for as long as a certificate needs to stay verifiable), and reviews you left or received. Content you created in the product (briefs, drafts, outreach notes) may also persist against the anonymized record until routine cleanup removes it — email us (section 6) if you want specific content erased sooner.
Some data expires on a schedule regardless of account status: login/security records after about 180 days; quarantined inbound email within 30 days; abandoned video uploads within hours; expired license offers and their vaulted files after 90 days. On some plans, delivery-evidence files are retained for 90 days — current limits are shown in the product where they apply.
6. Your rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (subject to legal retention requirements)
- Export a copy of your key data — profile, deal history (with a CSV), AI profile, connected accounts, and import history — from Settings → Account → Export my data
- Object to certain processing
- Withdraw consent for marketing communications
To exercise any of these, email support@getplug.io. We’ll respond within 30 days.
Deleting your account: creators can delete their account any time in Settings → Account → Delete account, or disconnect an individual platform in Profile → Platforms; a brand account can request deletion by emailing us from its account address. Deleting your account anonymizes and deactivates it: we scrub your profile PII, remove your public-profile content, profile and portfolio images, and stored platform tokens, take down your published pitch and license-verification pages, free your handle, unsubscribe you from marketing email, stop any active subscription from renewing, and disable the login. We keep your account email in our authentication system (login disabled) to prevent account reuse and fraud. Transaction and financial records are retained in anonymized form where the law requires (see retention above). Some content held by our processors may persist under their own retention — for example signed documents (DocuSeal) — and content sent to an AI provider is retained per that provider’s API data policy as described in section 3. Full step-by-step instructions — including data obtained from connected accounts — are on our Data Deletion page.
7. Children
Plug is not directed to children under 18. We do not knowingly collect personal data from minors. If you believe a minor has signed up, contact us and we'll remove the account.
8. International transfers
Plug operates from the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. We rely on standard contractual clauses or equivalent safeguards where required by law.
If you are in the EEA or UK: Plug Marketplace LLC is the controller of your personal data. We process it to perform our contract with you (running your account and deals), for our legitimate interests (securing the Service, preventing fraud, measuring and improving the product, and inviting prospective users), with your consent where we ask for it (marketing email), and to meet legal obligations. You have the rights listed in section 6, plus the right to lodge a complaint with your local supervisory authority.
9. Security
We use industry-standard safeguards: encrypted connections (HTTPS), encryption at rest for sensitive fields such as connected-platform tokens (AES-256-GCM), row-level security on the database, and limited access by Plug staff. No system is perfect; if a security breach affects your personal information, we will notify you — and regulators where required — as applicable law requires, without undue delay.
10. Content License Certificate & verification
When a brand licenses your content, Plug creates a Content License Certificate — a record of the agreement plus supporting metadata. This involves some additional data:
- Acceptance log — when you send or a brand accepts a content-license offer, we record who accepted, the server timestamp, the IP address, the browser/device (user-agent), and a hash of the exact terms shown. This is the certificate’s record that both sides agreed. Unlike our short-lived login/security records, this acceptance log is kept as part of the deal’s durable record for as long as the certificate needs to stay verifiable. We never show a raw IP or device to the other party or on the public page — the certificate shows only that a party “accepted in-app” and when.
- File fingerprint — when a licensed master file is delivered, we compute a SHA-256 fingerprint (a checksum) of the file so the certificate is tied to that exact file. It’s a mathematical digest, not personal data, and doesn’t reveal the file’s contents.
- Public verification page — each certificate can have a public page at getplug.io/verify/… that anyone with the link can open, with no login. This page is off by default: it exists only if you (the creator/licensor) choose to publish that specific deal’s link, and you can revoke it at any time from Settings → Shared deals, which takes the public page down. When published, it shows the parties’ display names, the licensed work, the license terms and dates, the current status, the file fingerprint, and the acceptance timeline. It deliberately excludes your messages, payment details, contact information, and raw IP/device data. Treat a published link as shareable.
- Enforcement notices — if a license expires or is revoked for cause and you ask Plug to step in, we may email the brand’s deal contact a notice to remove or renew. If the matter proceeds to a takedown, you (the creator and copyright owner) prepare and send a DMCA notice to the platform hosting the content — in good faith and, we recommend, with your own legal advice. Plug only helps you get ready and does not send or file it for you. A DMCA notice you send includes your name and contact details and the public verification link, and goes to that third-party platform.
- Commissioned UGC — when a brand commissions new footage from you, we store the brief, any creator-written script and the brand’s approval/revision feedback, the watermarked preview, the revision history, and the delivered master files (with their fingerprints). These are visible only to you, the brand, and Plug. We keep them while the deal is active and for a standard retention period afterward — generally up to seven years, in line with common industry practice and our legal, tax, and dispute-resolution obligations — after which we delete or anonymize them; your own files stay accessible to you.
11. Brand Radar and outreach data
To help you find and pitch brands, Plug processes business contact information — some of which is personal data about people who are not Plug users (for example a brand employee’s name, work email, or social handle):
- Brand Radar — a directory of brands to pitch that we curate and serve to creators on Plug Pro. For each brand we may store a name, category, website, and a business contact method (name, work email, or handle), along with where we sourced it and when it was last verified. This is drawn from publicly available business information, third-party business-data providers (including Google Places for local-business discovery and Hunter.io for business contact emails), and our own curation. We may use AI providers to generate a listing’s description and category tags from its business name and industry (never its contact details).
- Your outreach workspace — the brands and contacts you add yourself, including any names, emails, handles, and notes you enter, which we store on your account so you can manage your pitching.
This data is provided for legitimate business outreach only, subject to the acceptable-use rules in our Terms of Service. If you are a brand contact and would like your business contact details corrected or removed from Brand Radar, email support@getplug.io — we honor removals with a suppression list so re-imports can’t re-add you.
12. Invitations to prospective creators
We sometimes invite creators to join Plug before they have an account. If we think Plug would fit your work, we may assemble a preview profile from your publicly available creator presence — your name or handle, photo, social accounts and follower counts, niche, and a contact email — and publish it as an unlisted page at the profile address you could later claim, excluded from search engines and not linked from anywhere on Plug. We may then contact you (by email or DM) to show it to you. This program is limited to adults; if we learn a preview concerns a minor, we remove it immediately.
- Your contact email is never shown on the page, and we record only an aggregate open count and when the page was first and last opened — never who opened it.
- An unclaimed preview expires and is permanently deleted (including any photo) about 14 days after we last work on the invitation — and always once our outreach to you stops.
- If you claim the page, its details pre-fill your new account — from then on this policy’s normal terms apply.
- If you’d rather not hear from us, reply to the invitation or email support@getplug.io and we’ll take the page down and stop contacting you.
Where EU/UK law applies, we rely on legitimate interests for this processing, and you can object at any time using the contact above.
13. Changes to this policy
We may update this Privacy Policy over time. Material changes will be announced via email or in-app notice. Continued use of the Service after a change constitutes acceptance of the updated policy.
14. Contact
Privacy questions? Email support@getplug.io, or write to us at Plug Marketplace LLC, 522 W Riverside Ave STE N, Spokane, WA 99201.