Legal
Privacy Policy
- Effective:
- October 1, 2026
- Last updated:
- October 1, 2026
This Privacy Policy describes how Pluto Agent LLC, a Pennsylvania limited liability company doing business as "Pluto Agent" ("Company," "we," "us," or "our"), collects, uses, discloses, and protects personal data in connection with the Pluto Agent platform, including pluto-agent.com, Agent Studio, the Pluto Agent API, and all related services (collectively, the "Service"). Capitalized terms not defined here have the meaning given in our Terms of Service.
This Policy applies globally. Section 10 describes additional rights available to residents of California and the European Economic Area, United Kingdom, and Switzerland.
1. Scope and Roles#
This Policy covers two categories of personal data, which we treat differently:
- Account Holder data — personal data about you, if you register for and use an Account. With respect to this data, Company is the controller (or, in U.S. terms, the business).
- End User data — personal data about your own end customers or users that you or your Agent Build submits to, or that passes through, the Service in the course of an Agent responding to your End Users. With respect to this data, you (the Account Holder) are the controller, and Company acts as a processor / service provider on your behalf. Section 11 describes this relationship in more detail.
If you are an End User interacting with an Agent built by someone else on Pluto Agent, the Account Holder who built and deployed that Agent is responsible for their own privacy practices toward you, and you should direct privacy questions about that specific Agent to them. Company's role with respect to End User data is described in Section 11.
2. Data We Collect#
2.1 Data You Provide (Account Holder Data)#
When you create and use an Account, we collect:
| Data | Source | Notes |
|---|---|---|
| Email address | Collected via our authentication provider | Used for login and account communications. |
| Password | Collected via our authentication provider | We do not store your password ourselves. |
| Name and avatar | Collected via our authentication provider | Optional. |
| Account identifier | Generated by our authentication provider | Used internally as the key for your Account records. |
| Payment details | Collected by our payment processor | We do not receive or store your full card number. |
| Billing identifiers, balance, and usage counters | Pluto Agent | Credits, request counts, and error counts associated with your Account. |
| Agent Build content | Pluto Agent | The purpose, instructions, guardrails, Tool settings, and Tool credentials you configure for an Agent. |
| Support and account correspondence | Pluto Agent | For example, rate-limit increase requests or support emails. |
Company personnel may review and analyze Agent Build content, including in aggregate or de-identified form, to understand how the Service is used and to inform Company's product development decisions, such as what features or capabilities to build next. Company does not use the content of Agent Builds to train or fine-tune any artificial intelligence or machine-learning model, whether Company's own or a third party's.
2.2 Data Processed When an Agent Runs (May Include End User Data)#
When an Agent you configured is called, the following may be processed. Where this data relates to your End Users rather than to you, Section 11 applies.
- The End User's message and any other content submitted in the request to the Agent.
- Any additional context your application attaches to the request (this is the documented mechanism for passing information about an End User to an Agent, and its content is determined entirely by you).
- A conversation/session identifier chosen by your application, and the resulting conversation history, which is stored and replayed on subsequent turns in that conversation.
- If you have configured a Tool that reads from a third-party application you control, the specific records that Tool retrieves in the course of answering a request.
- If you have configured a web search capability, the search query the Agent generates is sent to our Model Provider's or its sub-provider's search functionality.
- Technical logs of each request and response, generated for operating, debugging, and securing the Service, which may contain the content of prompts and responses.
Billing and usage records (charge logs, credit ledgers) are generated from each call but do not include prompt or response content — they contain only technical and billing metadata such as token counts, model identifier, status codes, and timestamps.
2.3 Data Collected Automatically From the Website#
Our website does not use analytics, advertising trackers, or a tag manager, and does not set cookies for anonymous visitors. The following automatic data collection does occur:
- After you sign in, our authentication provider sets first-party session cookies that are strictly necessary to keep you logged in.
- Standard web server and CDN logs (such as IP address, browser type, and request timestamps) are generated by our hosting and content-delivery providers for security and reliability purposes, consistent with their own privacy practices.
- On-site documentation search runs entirely in your browser; no search query is transmitted to us or to any third party.
We do not currently use cookies or similar technologies for advertising or cross-site tracking purposes. If this changes, we will update this Policy and, where required by law, present a cookie consent mechanism before any non-essential cookie is set.
3. How We Use Personal Data#
We use personal data for the following purposes:
- To provide, operate, and maintain the Service, including running Agents, processing payments, and enforcing rate limits and Credit balances.
- To communicate with you about your Account, billing, security, or support requests.
- To monitor, secure, and debug the Service, including detecting and preventing fraud, abuse, and security incidents.
- To enforce our Terms of Service and this Policy, and to comply with applicable law.
- To improve and develop the Service.
For individuals in the European Economic Area, United Kingdom, or Switzerland, we rely on the following legal bases for these purposes: performance of a contract with you (providing the Service you signed up for); our legitimate interests (such as securing the Service and preventing abuse), balanced against your rights; compliance with a legal obligation; and, where applicable, your consent.
4. How We Share Personal Data#
We do not sell personal data, and we do not share personal data with third parties for their own advertising purposes. We share personal data with the following categories of recipients, each acting under contractual obligations consistent with this Policy:
| Recipient | Purpose |
|---|---|
| Cloud infrastructure providers | Hosting compute, storage, logging, and monitoring for the Service. |
| API gateway and portal hosting providers | Hosting the developer portal and routing API requests. |
| Content delivery / network security providers | Sitting in front of our infrastructure for performance and security. |
| Authentication provider | Handling account sign-up, login, and session management. |
| Payment processor | Processing Credit purchases and, if enabled, automatic refills. |
| Transactional email provider | Sending account, billing, and support-related emails. |
| Operational monitoring providers | Internal dashboards used by Company to operate the Service; not customer-facing. |
| One or more AI Model Providers | Processing the content of your Agent Builds and the prompts submitted to your Agents in order to generate Outputs. |
| Third-party applications you connect via a Tool | Only where you configure a Tool to connect to an application or database you control; you determine what that Tool can access. |
The specific providers we use in each category may change over time as the Service evolves. We will keep this list reasonably current, and material changes in how we share personal data will be reflected in an updated version of this Policy.
We may also disclose personal data where required by law, to protect the rights, safety, or property of Company or others, in connection with a merger, acquisition, or sale of assets, or with your consent.
5. International Data Transfers#
The Service is currently operated from the United States, and personal data we process is currently stored and processed in the United States, regardless of where you or your End Users are located. If you access the Service from outside the United States, your personal data will be transferred to, stored, and processed in the United States, where privacy laws may differ from those of your jurisdiction.
Where required by applicable law, we rely on appropriate safeguards for these transfers, such as the Standard Contractual Clauses approved by the European Commission or an equivalent mechanism recognized under UK or Swiss data protection law. You may request further information about these safeguards by contacting us at [email protected].
The Service is architected to support processing in additional regions in the future. If and when we begin processing data outside the United States, we will update this Policy accordingly.
6. Data Retention#
We retain personal data for as long as needed to provide the Service and for the periods described below, after which it is deleted or de-identified in the ordinary course, subject to Section 7 (Account Deletion). Retention periods may be updated from time to time as our infrastructure evolves; the table below reflects our practice as of the date of this Policy.
| Data | Retention Period |
|---|---|
| Conversation / session history | 365 days from the last activity in that conversation (renewed with each new message) |
| Agent Build content (instructions, settings, Tool configuration) | Retained for as long as the Agent Build exists; no automatic expiry |
| Account and billing record (balance, payment identifiers, auto-refill settings) | Retained for as long as the Account exists; no automatic expiry |
| Usage counters shown in the portal | 45 days |
| Lifetime usage totals | Retained indefinitely for as long as the Account exists |
| Per-call billing / charge records | 400 days |
| Settled usage records | 30 days |
| Pending / unsettled usage records | Retained until settled |
| Technical logs that may contain prompt or response content | 2 years |
Backups of certain records may persist for a limited additional period (up to 35 days) beyond the retention periods above, for disaster-recovery purposes, before being fully purged.
7. Account Deletion#
You may delete your Account at any time using the account deletion option in the Service. When you do:
- Your API keys are revoked and API access to the Service stops immediately.
- Records associated with your Account (including Agent Build content, session history, and billing records) are not immediately erased. Instead, they age out under the retention periods described in Section 6, unless you separately request earlier deletion.
- You may request earlier deletion of specific records by contacting us at [email protected]. We will honor such requests except where we are permitted or required to retain data (for example, to complete a transaction, resolve a billing dispute, enforce our agreements, detect fraud, or comply with a legal obligation).
You can also delete individual Agent Builds and remove individual Tools at any time without deleting your entire Account; removing a Tool deletes that Tool's stored settings and credentials.
8. Data Security#
We use administrative, technical, and organizational safeguards designed to protect personal data, including access controls, encryption in transit, and least-privilege access to production systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify you and any applicable authority as required by law.
9. Children's Privacy#
The Service is not directed to, and Account registration is not permitted for, anyone under 18 years of age (see our Terms of Service). We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child in violation of this Policy, we will delete it. If you believe a child has provided us with personal data, contact us at [email protected].
10. Your Privacy Rights#
Depending on your location, you may have rights regarding your personal data. To exercise any of the rights below, contact us at [email protected]. We may need to verify your identity before acting on a request.
10.1 All Users#
- Access — request a copy of the personal data we hold about you.
- Correction — request that we correct inaccurate personal data.
- Deletion — request deletion of your personal data, subject to the limitations described in Section 7.
- Withdraw consent — where we rely on your consent, withdraw it at any time without affecting processing that already occurred.
10.2 California Residents#
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), gives you the right to: know the categories and specific pieces of personal information we have collected about you and the purposes for collection; request deletion of your personal information; request correction of inaccurate personal information; and not be discriminated against for exercising these rights.
We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA. In the preceding 12 months, we have collected the categories of personal information described in Section 2 for the business purposes described in Section 3. We have not disclosed personal information for a business purpose to any category of third party other than those described in Section 4, and we have not sold or shared personal information as described above.
10.3 European Economic Area, United Kingdom, and Switzerland#
If you are located in the EEA, UK, or Switzerland, in addition to the rights in Section 10.1, you have the right to: restrict or object to certain processing of your personal data, including processing based on legitimate interests; receive a copy of the personal data you provided to us as part of your Account profile (such as your name and email address) in a portable format; and lodge a complaint with your local data protection supervisory authority.
Agent Build content (the instructions, settings, and configuration you create for an Agent) is not personal data about you and is not covered by the portability right described above; it is addressed instead by the license and export terms in our Terms of Service.
Our representative for matters relating to this Policy in the EEA is DataRep, 77 Camden Street Lower, Dublin, D02 XE80, Ireland. Our representative in the UK is DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom. When contacting our representative, please address correspondence to "DataRep," not to Company, as communications addressed to Company at these locations may not be received.
11. Our Role as a Processor for End User Data#
Where you configure an Agent Build to interact with your own End Users, you determine what personal data is sent to the Agent and for what purpose. With respect to that End User data, you act as the controller (or business), and Company acts as a processor (or service provider) that processes End User data only as instructed by you through your configuration and use of the Service, and as described in this Policy.
You are responsible for establishing your own lawful basis for collecting and submitting End User personal data, and for providing your End Users with appropriate notice. Company's standard Data Processing Addendum ("DPA"), available at pluto-agent.com/dpa, is incorporated by reference into our Terms of Service and applies automatically whenever you submit End User personal data to the Service.
12. AI-Generated Content and Automated Processing#
Agent Outputs are generated by an AI Model Provider based on the Agent Build's instructions and the prompt submitted. Company does not use Agent Outputs to make decisions about you or your End Users that produce legal or similarly significant effects. If you use Outputs to make such decisions about your own End Users, you are responsible for ensuring that use complies with applicable law, including any rights your End Users may have regarding automated decision-making.
13. Changes to This Policy#
We may update this Policy from time to time. If we make material changes, we will post the updated Policy with a new "Last Updated" date and, where appropriate, notify you by email or through an in-product notice. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
14. Contact Us#
Questions about this Policy or requests regarding your personal data may be directed to:
Pluto Agent LLC d/b/a Pluto Agent
121 S Broad St.
15th Floor PMB 1166
Philadelphia, PA 19107
[email protected]