Privacy Policy
Last updated: July 16, 2026
Plug Pro is operated by Plug Marketplace LLC, 522 W Riverside Ave STE N, Spokane, WA 99201 (“Plug,” “we,” “us”). This policy explains how we collect, use, and protect your information when you use Plug Pro — our back office for creators.
1. What we collect
We collect the following categories of information:
- Account info — email, password (hashed), display name, niche tags, location city/region/country.
- Profile & storefront content — bio, vibe tags, pinned posts, social account handles and follower counts pulled from public APIs you connect, audience demographics you provide, rates and packages you publish, and reviews.
- Connected platform data (OAuth) — when you choose to connect a social platform through OAuth (YouTube via Google; TikTok; Instagram, Facebook, and Threads via Meta; Twitch; Kick; Pinterest), we read your account’s public statistics (subscriber or follower count) and basic identity (your channel ID, handle, or username) to show a verified follower count on your Plug profile and keep it current. To refresh that count over time, we store the access and refresh tokens the platform issues — encrypted at rest and used only to re-read your public follower or subscriber count on a periodic schedule. These tokens never let us read your private videos, comments, messages, or email, and we never post, change, or delete anything on your connected account. When you disconnect a platform — or close your account — we delete the stored tokens and stop refreshing. Platforms we don’t support through OAuth are self-declared — you enter the handle and follower count yourself.
- Subscription & billing data — we store your plan and tier (including that an account is on the free tier), and, if you subscribe to a paid plan, your Stripe customer and subscription identifiers, your billing status and period dates, your locked founding price (if any), and a record of your paid and failed subscription invoices (amount, currency, status, and a link to the Stripe-hosted invoice). We never store card numbers or bank details — those are handled by Stripe.
- Payment & payout details — since brands pay you directly, we store the identifiers and links needed to run that off-platform: your own connected Stripe or PayPal account identifiers (for the optional “pay online” button, which settles into your account), and the payout links you save to print on invoices (for example PayPal, Venmo, or Cash App). We store identifiers and links, never full card or bank numbers.
- AI inputs & creative data — when you use our AI features (Workbench, deal intake, Assistant, Scam Scanner, Video Analysis, career and outreach tools), we process what you submit: pasted text, uploaded images and documents (such as brand briefs and contracts), and video files. We also store the creative context those tools build on — your learned style guide, saved memory rules, voice tags, briefs, and the concepts, hooks, and scripts they generate. These inputs are sent to our AI providers (see section 3).
- AI usage metering — AI features are metered, so we track your AI usage: on the free tier, a daily counter of the AI actions you’ve used and when the window resets; on a paid plan, how many credits your account holds and has consumed, the per-action cost, your monthly reset date, and any top-ups.
- Deal activity — the deals and offers you log, messages exchanged on a deal, the milestone confirmations you record (such as marking a deal delivered or paid), and reviews and testimonials.
- Contracts & e-signatures — the contract documents you create and send, and, when a brand signs one electronically, the signer’s name and email and the resulting signed PDF, processed through our e-signature provider (see section 3).
- In-person event details — for appearance bookings we store the deal’s logistics and the brand’s on-site host contact (name, phone, email), any credentials or files attached, and your post-event verification photos. Photos may carry embedded location and timestamp (EXIF) data, which becomes part of the deal’s private record.
- Legal name (in-person, optional) — for some in-person bookings you can choose to share your legal name with the brand for entry or credentials; we record that choice.
- Livestream data (livestream bookings) — if a booking includes a livestream, we record that your connected channel went live during the event window and capture stream metadata and periodic frames as proof, stored privately on the deal.
- Phone number (optional) — if you verify your phone, we store a one-way hashed form of it to confirm it’s you. We don’t display it.
- Usage data — pages visited, features used, in-product events recorded against your account with a timestamp (for example, that you reached a free-tier usage limit or started an upgrade), IP address, browser and device info, error logs.
- Login & security records — when you sign up or sign in, we record the event with the IP address and browser/device (user-agent) at that moment. We use these records to detect fraud, abuse, duplicate or coordinated accounts, and Terms violations. They’re kept only as long as needed for security and fraud prevention, then deleted.
- Precise location (in-person deals only) — when you check in at an event venue or capture an event photo, we record your device’s GPS location and the time at that moment to confirm attendance. We collect this only when you actively check in or take a photo, and only for in-person appearance deals. It becomes part of that deal’s private record, visible to you, the brand on the deal, and Plug (for support). The receipt view shows your distance from the venue, not a map or street address.
- Brand contact data — the brands and contacts you save into your outreach workspace, and the business contact details we provide through Brand Radar. Because this can include personal data about people who aren’t Plug users, it is described separately in section 11.
- Push notifications — if you enable them, we store the push subscription your browser issues so we can deliver alerts. You can revoke it any time in your browser or notification settings.
2. How we use it
We use your data to:
- Run your Plug Pro back office — your profile and storefront, your logged deals, invoices, and licensing
- Provide AI features (Workbench, Assistant, Scam Scanner, Video Analysis, career and outreach tools) and meter your AI usage
- Bill your Plug subscription through Stripe, and record that a brand paid you directly when you confirm receipt
- Generate verifiable license certificates for the rights you grant
- Send transactional emails (offer accepted, contract signed, payment reminders, etc.)
- Send product updates and marketing emails — you can opt out any time via the unsubscribe link or your settings; transactional emails about your deals and account are always sent
- Detect and prevent fraud, abuse, and Terms violations — including with automated tools and AI
- Improve the product through aggregated analytics
3. Sharing
We share data only as needed to operate the Service:
- With the brands you deal with — information tied to a specific deal is shared with the brand to complete it: for example your deliverables, the license terms, or (if you choose) your legal name on an in-person booking.
- Publicly, on your storefront — your public profile and storefront (display name, bio, niche tags, social handles, rates, packages, portfolio, and reviews) are visible to anyone who views your page, including brands you pitch.
- With Stripe — for two separate purposes: (1) to bill your flat Plug Pro subscription, where you are the Stripe customer; and (2) where a brand chooses to pay you by card, a direct charge to your own connected Stripe account, which we facilitate but never process, hold, or receive. See Stripe’s privacy policy for how they handle data.
- With PayPal — where you enable it, a brand’s online payment is made to your own PayPal merchant account; Plug never takes custody of the funds.
- With Supabase — our database, authentication, and file-storage provider. They process data on our behalf under their data processing agreement.
- With Vercel — our hosting provider, which handles HTTP traffic and deployment logs.
- With Resend — our email provider, used to deliver transactional email and to maintain a marketing-contact audience (your email and first name) reflecting your marketing-email opt-in choice.
- With Cloudflare — for security, bot detection, and spam prevention, including the verification challenge on signup. This may process your IP address and request metadata.
- With our error-monitoring provider (Sentry) — to capture diagnostic and crash data, which can include IP address and device/browser details, so we can fix problems.
- With our AI providers (Anthropic and Google’s Gemini) — when you use an AI feature, the content you submit — text, images, uploaded documents such as contracts, and video files — is sent to one of these providers to generate the response you asked for. We use these providers through their business APIs and do not use your content to train Plug’s own models; each provider’s handling of data submitted to its API is governed by that provider’s own terms. A video you submit for analysis is uploaded to Google’s file API for processing; we delete it after analysis on a best-effort basis, and it otherwise expires on Google’s side (currently within about 48 hours).
- With DocuSeal — our e-signature provider. When you send a contract for signature, the contract text and the signer’s name and email are processed by DocuSeal, which emails the signer and returns the signed PDF.
- With Bunny — our video hosting and delivery (CDN) provider. Videos on your profile and storefront, and licensed master files, are stored and streamed through Bunny.
- With Brandfetch — when you add a brand by its website, we fetch that brand’s public logo and brand colors from Brandfetch to display on the record.
- With browser push services (such as Apple, Google, or Mozilla) — if you enable notifications, to deliver them to your device.
- With mapping / geocoding providers (Mapbox, with OpenStreetMap / Nominatim as a fallback) — for in-person deals, venue addresses you enter are sent to validate and locate them.
- With the public (license verification) — a content license’s verification page (getplug.io/verify/…) is accessible to anyone who has the link, and only if you choose to publish it. It shows only scoped, public-safe fields (see section 10) — never your messages, payment details, contact info, or IP/device data.
- For legal reasons — when required by law, court order, or to investigate fraud or abuse.
We do not sell your personal data.
4. Cookies and tracking
We keep cookies to a minimum. The cookies Plug itself sets are first-party — set by us, readable only by us:
- Sign-in cookies — issued by our authentication provider (Supabase) to keep you signed in, plus a session-activity cookie that signs you out after a long idle period.
- Security cookies — short-lived tokens that protect flows like connecting a social platform against cross-site request forgery. The Cloudflare bot-detection challenge on signup (see section 3) may also set its own cookie for that check.
- Feature cookies — for example, remembering that a brand unlocked a PIN-protected share link so it doesn’t re-enter the PIN on every page.
- A signup-source cookie — if you arrive through a tagged link (for example a creator’s link-in-bio), we set a 30-day first-party cookie recording that channel so we can attribute your signup to it. It contains a single word like “linktree” — nothing about you.
- A view-count cookie — when anyone opens a public pitch page or a plugd.cc link, we set a 30-minute first-party cookie so refreshes and re-opens aren’t counted as new views. It contains no identifier — just a marker that the view was already counted.
Our analytics (Vercel Web Analytics) is cookieless — it reports aggregate page views without setting cookies, fingerprinting, or following you across sites. We run no advertising trackers and no third-party ad cookies, which is why you don’t see a cookie-consent banner here: we don’t set the advertising or cross-site tracking cookies those banners primarily exist to gate. You can clear or block cookies in your browser settings; blocking the sign-in cookie will sign you out.
5. Data retention
We retain your account data for as long as your account is active. After you close your account, we retain the minimum needed to comply with legal, tax, and dispute obligations — including subscription and invoice records (typically up to seven years for financial records). Deal history may be retained in anonymized form for analytics.
6. Your rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (subject to legal retention requirements)
- Export your data in a portable format
- Object to certain processing
- Withdraw consent for marketing communications
To exercise any of these, email . We'll respond within 30 days.
Deleting your account: you can delete your account yourself any time in Settings → Account → Delete account, or disconnect an individual platform in Profile → Platforms. Deleting your account anonymizes and deactivates it: we scrub your profile PII, remove your public-profile content and profile images, free your handle, unsubscribe you from marketing email, and disable the login. Transaction and financial records are retained in anonymized form where the law requires (see retention above). Some content held by our processors may persist under their own retention — for example videos on our CDN (Bunny) and signed documents (DocuSeal) — and any file you sent to an AI provider expires on that provider’s side as described in section 3. Full step-by-step instructions — including data obtained from connected accounts — are on our Data Deletion page.
7. Children
Plug is not directed to children under 18. We do not knowingly collect personal data from minors. If you believe a minor has signed up, contact us and we'll remove the account.
8. International transfers
Plug operates from the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. We rely on standard contractual clauses or equivalent safeguards where required by law.
9. Security
We use industry-standard safeguards: encrypted connections (HTTPS), encrypted storage for sensitive fields, row-level security on the database, and limited access by Plug staff. No system is perfect; we'll notify affected users in the event of a breach that materially affects their data.
10. Content License Certificate & verification
When a brand licenses your content, Plug creates a Content License Certificate — a record of the agreement plus supporting metadata. This involves some additional data:
- Acceptance log — when you send or a brand accepts a content-license offer, we record who accepted, the server timestamp, the IP address, the browser/device (user-agent), and a hash of the exact terms shown. This is the certificate’s record that both sides agreed. Unlike our short-lived login/security records, this acceptance log is kept as part of the deal’s durable record for as long as the certificate needs to stay verifiable. We never show a raw IP or device to the other party or on the public page — the certificate shows only that a party “accepted in-app” and when.
- File fingerprint — when a licensed master file is delivered, we compute a SHA-256 fingerprint (a checksum) of the file so the certificate is tied to that exact file. It’s a mathematical digest, not personal data, and doesn’t reveal the file’s contents.
- Public verification page — each certificate can have a public page at getplug.io/verify/… that anyone with the link can open, with no login. This page is off by default: it exists only if you (the creator/licensor) choose to publish that specific deal’s link, and you can revoke it at any time from Settings → Shared deals, which takes the public page down. When published, it shows the parties’ display names, the licensed work, the license terms and dates, the current status, the file fingerprint, and the acceptance timeline. It deliberately excludes your messages, payment details, contact information, and raw IP/device data. Treat a published link as shareable.
- Enforcement notices — if a license expires or is revoked for cause and you ask Plug to step in, we may email the brand’s deal contact a notice to remove or renew. If the matter proceeds to a takedown, you (the creator and copyright owner) prepare and send a DMCA notice to the platform hosting the content — in good faith and, we recommend, with your own legal advice. Plug only helps you get ready and does not send or file it for you. A DMCA notice you send includes your name and contact details and the public verification link, and goes to that third-party platform.
- Commissioned UGC — when a brand commissions new footage from you, we store the brief, any creator-written script and the brand’s approval/revision feedback, the watermarked preview, the revision history, and the delivered master files (with their fingerprints). These are visible only to you, the brand, and Plug. We keep them while the deal is active and for a standard retention period afterward — generally up to seven years, in line with common industry practice and our legal, tax, and dispute-resolution obligations — after which we delete or anonymize them; your own files stay accessible to you.
11. Brand Radar and outreach data
To help you find and pitch brands, Plug processes business contact information — some of which is personal data about people who are not Plug users (for example a brand employee’s name, work email, or social handle):
- Brand Radar — a directory of brands to pitch that we curate and serve to creators on Plug Pro. For each brand we may store a name, category, website, and a business contact method (name, work email, or handle), along with where we sourced it and when it was last verified. This is drawn from publicly available business information and our own curation.
- Your outreach workspace — the brands and contacts you add yourself, including any names, emails, handles, and notes you enter, which we store on your account so you can manage your pitching.
This data is provided for legitimate business outreach only, subject to the acceptable-use rules in our Terms of Service. If you are a brand contact and would like your business contact details corrected or removed from Brand Radar, email .
12. Changes to this policy
We may update this Privacy Policy over time. Material changes will be announced via email or in-app notice. Continued use of the Service after a change constitutes acceptance of the updated policy.
13. Contact
Privacy questions? Email , or write to us at Plug Marketplace LLC, 522 W Riverside Ave STE N, Spokane, WA 99201.