Legal
Privacy
Last updated 12 August 2026
PLACEHOLDER. REPLACE BEFORE PUBLISHING.
This policy is scaffolding, not legal advice, and it has not been reviewed by a lawyer. Replace it with a policy written for your company, your jurisdiction, and the data you actually collect.
What we collect
Account details you give us: name, work email, company, and billing address. Product data from every call: model, token counts, latency, cost, and error codes. Request and response content only for as long as your retention setting says, which can be nothing at all.
Why we collect it
To route your calls, bill you accurately, and investigate incidents. Aggregate figures that identify nobody tell us what to build next. We do not sell your data and we do not train models on it.
How long we keep it
Request and response content follows your retention setting: zero days, 7 days, or 30 to 90 days. Metadata stays for billing and capacity planning. Deletion means deletion, and backups roll off within 35 days.
Your rights under GDPR and CCPA
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to hello@plinth.dev and we will answer within 30 days. Asking costs nothing and changes nothing about how we treat you.
Cookies
A session cookie to keep you signed in and a preference cookie to remember dashboard settings. First-party analytics that do not follow you off this site. No advertising cookies and no third-party trackers.
International transfers
You choose whether processing happens in the US or the EU. Where data crosses a border we rely on standard contractual clauses. Enterprise plans pin to a single region, traces and backups included.
Changes to this policy
We post the new version here and change the date at the top. If a change affects how we handle your data, account owners get an email before it takes effect.
How to contact us
Write to hello@plinth.dev about anything in this policy, or to security@plinth.dev for questionnaires and vulnerability reports. A person reads both.