Privacy

Privacy policy

Last updated: 2026-08-13

Who we are

Plurism is operated by The Gentle Equation Pty Ltd, registered in Victoria, Australia. Contact: hello@plurism.dev.

What we collect

  • Account data: email and project-level metadata you create in the portal.
  • Content you ingest: support threads, feedback, waitlist entries, files — whatever you send to the API.
  • Operational logs: method, path, status, duration, a hashed IP subnet (first 64 bits of SHA-256 of a /24), user-agent, and a correlation ID.
  • Visits to this site: we run our own analytics on plurism.dev — the same tracker we sell, on the same snippet we hand customers. Each pageview records the path, the hostname of the site that referred you (never the full referring URL, and same-site referrals are dropped entirely), any UTM parameters in the link, and a country. It runs in cookieless mode: it sets no cookie and writes nothing to your device — and if you still carry a _pa cookie from before we made that switch, it deletes it. Your IP address is never stored. It is used twice, in memory: to look up a country, and as one input to a visitor id computed as a hash of your IP, your user-agent and a salt that rotates at midnight UTC and is discarded within 48 hours. Once that salt expires the id cannot be traced back to you by anyone, including us — the accepted cost being that a return visit tomorrow counts as a new visitor. We honour Do Not Track and Global Privacy Control: with either set, the tracker exits before recording anything at all.
  • Security audit log: for account-level changes only — who added or removed a member, changed a role, minted or revoked an API key, created or deleted a project or organisation. Each entry records the acting account and the full IP address the change came from, because an audit trail that can't identify the source of a change is not an audit trail. This is the one place we keep an unhashed IP.

What we don't collect

  • No third-party analytics or ad trackers on this site.
  • No cross-site tracking, no fingerprinting.
  • Request logs never hold a full client IP — only a truncated, salted subnet hash. The single exception is the security audit log described above, which records the full IP of account-level changes.
  • Cookies: the only cookies on this site are strictly-necessary Cloudflare ones (e.g. bot protection). No consent banner is needed because there's nothing to consent to.

How long we keep it

  • Operational request logs, webhook delivery logs, and inbound-email drop records: 30 days, pruned automatically.
  • Sign-in tokens: 7 days. Billing event records: 90 days.
  • Security audit log: 365 days. It is low-volume — a handful of rows per account — and it is the record we'd need to investigate a compromised account, so it outlives the operational logs.
  • Transactional email send log (recipient, subject and delivery status — never the message body): 90 days.
  • Do-not-send list (addresses that hard-bounced, complained, or asked not to be mailed): kept indefinitely, as a salted hash. Deleting it would mean mailing those addresses again, which is the opposite of what it's for.
  • Content you ingest (threads, entries, files): kept until you delete it or close your account.
  • Analytics: raw events 90 days; daily aggregates roughly 15 months; the revenue ledger is kept until you close your account.
  • Encrypted database backups: 30-day rolling window.

Where data lives

Application data lives in Cloudflare D1 + R2 (primary region: North America). The operational plane runs on Cloudflare Workers. Because we're an Australian company storing data on overseas infrastructure, this is a cross-border disclosure under Australian Privacy Principle 8 — we only use providers with strong contractual data-protection commitments.

Subprocessors

We use these providers to deliver the service. We'll update this list before adding new ones:

  • Cloudflare, Inc. (US/global) — compute, database, file storage, networking.
  • Amazon Web Services, Inc. (Sydney, ap-southeast-2) — sending transactional email on your behalf, via Amazon SES.
  • Resend, Inc. (US) — support notification email and inbound email routing.
  • Stripe, Inc. (US) — payments, once paid tiers launch.

Your users' data (controller / processor)

Data your application sends to Plurism about your users — support reporters, waitlist signups, feedback authors, analytics visitors — is processed on your behalf and on your instructions: you are the controller, we are the processor. If your users are in the EEA/UK, GDPR rights requests for that data should go to you; we'll assist. The processing commitments are in our terms.

This includes analytics. If you use Plurism Analytics, the data you send us about your visitors is: a pseudonymous visitor ID, page URLs and referrers, UTM tags, and a country code derived at our edge. By default the tracker sets one first-party cookie (_pa) on your site to recognise a returning visitor; a cookie-less mode is available in which the tracker stores nothing in the visitor's browser and sends no ID at all — instead we derive a pseudonymous visitor ID at ingest from a one-way salted hash whose inputs include the visitor's IP address and browser user-agent, with a salt that rotates every UTC day and is discarded within 48 hours, so the ID cannot identify the same visitor across days and cannot be reversed to an address. In both modes the tracker sends nothing at all when a visitor's browser signals Do Not Track or Global Privacy Control. Analytics records never contain an IP address itself. Two stored values are computed from it, and this is the whole list: the country code, derived at our edge before the address is discarded, and — in cookie-less mode only — the visitor ID described above, a truncated one-way hash whose daily salt is deleted within 48 hours. If you pass us an email or your own user ID, we use it to stitch a visitor's activity into one profile. If you connect your Stripe account, we record revenue events (amounts and Stripe customer IDs) against those profiles. Raw events are deleted after 90 days and daily aggregates after roughly 15 months; the revenue ledger is kept so your numbers stay accurate over time. Your end users should send access or deletion requests to you — you're the controller — and we'll assist as processor.

Your rights

You can download everything in a project as a single JSON file from its Settings page, at any time — it works even if your account is over a limit or has lapsed, because an export you can only run while paying isn't a real one. Deletion requests, and anything the self-serve export doesn't cover, go to hello@plurism.dev. Soft-delete is first-class in every Plurism service; hard-delete is in active development. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. If you're unhappy with how we've handled your data, contact us first — and you can complain to the OAIC (oaic.gov.au).

Changes

If this policy changes materially, we'll notify account holders by email at least 30 days before the change takes effect.