Deposit received: pɱ Deposit credited: pɱ Deposit settled: pɱ
Privacy
What we keep, and what we don't.
Version 2 — Last Updated: July 5, 2026
This Privacy Policy describes how Plurnk, LLC ("we," "us," or "our") collects, uses, retains, and discloses your information when you use our services, including plurnk.ai and related APIs (collectively, the "Services").
Use of the Services requires an account, and creating an account requires your acceptance of this Privacy Policy and our Terms of Service. By using the Services, you agree to the terms of this Privacy Policy.
Plain-language summary: We retain the prompts you send and the outputs our models generate, and we use them to train and improve our models. We retain this data indefinitely. We do not sell it. We are under no obligation or agreement to delete it. If that is not acceptable to you, do not use the Services.
1. Our Structure
Plurnk, LLC is the business entity that operates the hosted Services, including the relay, billing, and the proprietary model-training corpus. This policy applies only to the Services operated by Plurnk, LLC. The open-source plurnk runtime is a separate, MIT-licensed project; it is not operated by Plurnk, LLC and is not governed by this policy.
2. Information We Collect
A. Information You Provide to Us
- Account Information: Use of the Services requires a registered account, including for the free tier. You create an account with a username and password, or, where available, via Telegram Login; to create one you must affirmatively accept this Privacy Policy and our Terms of Service. For username accounts we collect the username you choose; for Telegram accounts we collect your Telegram account identifier (handle and user ID). We do not collect your email address.
- Billing and Balance Information: You fund a prepaid balance by depositing Monero, and usage is metered against that balance. To operate this, we assign your account a deposit address and record your deposits, your internal balance, and your metered usage. Deposits are final and can be spent only on the Services. We do not accept, process, or store payment card information.
B. Information Collected Automatically
- Connection Data: When you connect to the Services over the public internet, we may collect your IP address and coarse geolocation. We use this to help enforce the geographic scope of our Services (the Services are offered in the United States only), to meter usage, and for security.
- Usage Data: We collect information about how you interact with the Services, including API request patterns, timestamps, and error logs.
- Attribution Tags: Requests may carry attribution tags identifying the creators or contributors associated with the client or workflow. We record these tags and the traffic associated with them.
- Cookies: We use strictly necessary first-party cookies only — a session cookie to keep you signed in, a security (CSRF) cookie, and a cookie that remembers your language choice. We do not use advertising cookies or third-party analytics, and we do not track you across other websites. Because these cookies are essential to operate the Services, we do not display a cookie-consent banner.
C. The Corpus (Inputs and Outputs)
The core of our Services is a model-training corpus. We capture and store two types of data in separate schemas:
- Prompts (User Inputs): the prompts and content you send to the models.
- Emissions (Model Outputs): the outputs the models generate in response.
We retain both Prompts and Emissions, and we use both to train and improve our proprietary models. This data collection and its use for model training are a fundamental and non-optional part of the Services.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Services.
- Train our models. We use both Prompts (user inputs) and Emissions (model outputs) to train, tune, and refine our proprietary models.
- Process transactions and manage your account.
- Enforce the geographic scope of the Services, ensure security, and prevent fraud or unauthorized access.
- Comply with legal obligations.
4. Data Retention and Security
- Retention: We retain corpus data (Prompts and Emissions) indefinitely for model-training purposes. We are under no obligation, and make no agreement, to delete, remove, or anonymize any data, and we do not commit to honoring data-deletion requests. See Section 6.
- Encryption: Corpus data is encrypted at rest.
- Operational Logs: We do not store plaintext prompts in our operational logs.
- Connection Logs: We retain connection and operational logs, including IP address, for up to twelve (12) months, after which they are deleted or aggregated.
- No Guarantee: No method of transmission or storage is completely secure. While we take reasonable measures to protect your information, we cannot guarantee its absolute security.
5. Data Sharing and Disclosure
We do not sell your personal information, and we do not share corpus data for the independent commercial use of any third party. We share information only in the following circumstances:
- Service Providers: We share data with the third-party providers necessary to operate the Services (e.g., Telegram for optional account login and third-party model providers for inference), under their respective terms.
- Third-Party Model Interaction: Operating the Services requires transmitting your Prompts to third-party model providers (e.g., Fireworks) for inference. When you use the Services, you are also interacting with these third-party models, and that interaction is subject to those providers' own terms and data practices.
- Legal Requirements: We may disclose information where required by law, subpoena, or legal process, or to protect our legal rights, safety, or property.
6. Your Choices and Jurisdiction
- Your Choices: Your primary choice regarding the data described in this policy is whether to use the Services. Because data capture and retention for model training are integral to the Services, we do not offer opt-outs from corpus collection, and we are under no obligation or agreement to honor data-deletion or data-access requests at this time.
- Jurisdiction: The Services are intended for use only by residents of the United States.
- No International Use (EU/EEA/UK and elsewhere): We do not offer the Services to, target, or monitor the behavior of individuals located in the European Union, European Economic Area, United Kingdom, or any other foreign jurisdiction, and we do not intend to bring ourselves within the scope of the GDPR, UK GDPR, or similar foreign data-protection laws. If you are located outside the United States, do not use the Services.
- State Privacy Laws: We currently fall below the applicability thresholds of the California Consumer Privacy Act (CCPA), the Indiana Consumer Data Protection Act (INCDPA), and comparable state privacy laws. As we grow, we will revisit our practices and update this policy to comply with the state privacy laws that apply to us, including as an Indiana business.
7. Children's Privacy
The Services are not directed to, and are not intended for use by, anyone under the age of 18. We do not knowingly collect information from children.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and revising the "Last Updated" date above.
9. Contact Us
If you have questions about this Privacy Policy, contact us at [email protected].