Privacy Policy
Last updated: 28 July 2026 · Effective: 28 July 2026
This Privacy Policy explains how PlugKit, Inc. (“PlugKit”, “we”, “us”, or “our”) collects, uses, stores, shares, and deletes personal data when you use our website, API, SDKs, dashboard, and MCP server (together, the “Services”). It also explains how we handle data we access from connected platforms — including Meta (Facebook, Instagram, Messenger, Threads, and WhatsApp), X, LinkedIn, TikTok, YouTube, Pinterest, Reddit, and others — on behalf of our customers.
In short: PlugKit is infrastructure that lets developers and their AI agents connect social and messaging accounts through official OAuth flows and act on them through a single API. We process Platform Data only to provide those features, we never sell it, and you can disconnect an account or delete your data at any time. See Section 9 — Your Rights & Data Deletion.
1. Who we are
PlugKit, Inc. provides a unified API that allows developers — and the AI agents they build — to publish content, read and reply to messages, and receive events across multiple social and messaging platforms through a single integration.
For personal data relating to our own account holders (for example, the developer or organization that signs up for PlugKit), PlugKit acts as a data controller. For Platform Data and end-user content that our customers process through the Services, PlugKit acts as a data processor acting on the customer’s instructions (see Section 2).
2. Scope & your role
This policy applies to two kinds of people:
- Customers — developers, businesses, and organizations who create a PlugKit account and use our API, SDKs, dashboard, or MCP server.
- End users — individuals whose data is accessed through a connected platform account that a customer has authorized (for example, a Facebook Page’s followers or a person who sends a direct message to a connected Instagram account).
Where PlugKit processes end-user Platform Data on behalf of a customer, the customer is the controller and is responsible for having a lawful basis and a privacy notice covering that processing. PlugKit processes such data only to provide the Services and according to our agreement with the customer.
3. Data we collect
3.1 Account & contact data
- Name, email address, and password (stored only as a salted hash) or federated sign-in identifier.
- Company name, role, and country, where you provide them.
- Billing details processed by our payment provider (we do not store full card numbers).
- Support correspondence and product feedback.
3.2 Connection credentials
- OAuth access and refresh tokens issued by a connected platform when you authorize an account. These are stored encrypted and are refreshed on your behalf so your integration keeps working.
- The platform account identifiers, names, and scopes/permissions you granted.
3.3 Platform Data we access on your behalf
When you connect an account, you direct PlugKit to access only the data covered by the permissions you grant. Depending on the platform and scopes, this may include:
- Account and profile information for the connected business/creator account (name, ID, profile picture, linked Pages or channels).
- Content you publish, schedule, or read through PlugKit (posts, media, captions, threads, comments).
- Messages and conversations in the connected account’s inbox (DMs, Messenger/WhatsApp threads) when you use inbox features.
- Delivery results, insights, and analytics (impressions, engagement, message-delivery events).
3.4 Technical & usage data
- API request metadata: timestamps, endpoints called, status codes, and request IDs (used for rate limiting, debugging, and abuse prevention).
- IP address, browser/user-agent, and basic device information for the dashboard.
- Logs and diagnostic data. We do not retain raw message or post bodies in long-term logs.
Some integrations rely on platforms governed by their own developer terms — including the Meta Platform Terms and Developer Policies. Where we access data from Meta technologies (Facebook, Instagram, Messenger, Threads, WhatsApp) we additionally commit to the following:
- We request only the permissions necessary to deliver the feature you enable, and we use Platform Data solely to provide and improve those features for you.
- We do not sell, license, or rent Platform Data, and we do not use it for advertising, building user profiles, or making eligibility decisions about people.
- We do not transfer Platform Data to any data broker, ad network, or monetization partner.
- We retain Platform Data only as long as needed to provide the Services and delete it on disconnection or request, subject to limited legal retention (see Sections 8–9).
- We maintain administrative, technical, and physical safeguards designed to protect Platform Data, and we will report incidents as required by applicable platform terms and law.
- If you stop using PlugKit, or a platform or we determine that continued processing is not permitted, we will delete the corresponding Platform Data.
If any term of this policy conflicts with a platform’s developer terms regarding that platform’s data, the stricter requirement that protects the individual applies to that data.
4.1 YouTube API Services & Google user data
PlugKit’s YouTube integration uses YouTube API Services. By connecting a YouTube channel to PlugKit you are also agreeing to the YouTube Terms of Service, and Google’s handling of your information is described in the Google Privacy Policy.
- What we access. With your consent we request two Google OAuth scopes:
youtube.readonly, to identify the channel you are connecting and read the status of the videos PlugKit published for you; and youtube.upload, to upload videos to that channel on your instruction. We do not request access to your Gmail, Drive, Contacts, or any other Google product.
- What we store. Your OAuth access and refresh tokens (encrypted at rest), your channel ID, channel title, and thumbnail, and the IDs and status of videos published through PlugKit. We do not download or retain copies of your existing YouTube library.
- How we use it. Solely to provide the features you or the application you authorised have enabled. We do not use Google user data for advertising, we do not sell or transfer it, we do not use it to build user profiles or make eligibility decisions, and we do not use it to train generalised AI or machine-learning models. Humans do not read it except with your explicit permission, to resolve a support issue you raised, for security purposes, or where required by law.
- How to revoke access. You can disconnect a YouTube account at any time from your PlugKit dashboard, or revoke PlugKit’s access directly from your Google Account at myaccount.google.com/permissions (also reachable at security.google.com/settings/security/permissions).
- Deletion. Disconnecting the channel or revoking access revokes and deletes the stored tokens and the associated channel data, as described in Section 8. See Section 9 for how to request deletion of all your data.
5. How we use data
| Purpose | Example |
| Provide the Services | Authenticate accounts, store and refresh tokens, publish content, read/reply to messages, deliver webhooks. |
| Operate & secure the platform | Rate limiting, fraud and abuse prevention, debugging, maintaining uptime. |
| Support | Respond to your requests and troubleshoot integration issues. |
| Billing | Process subscriptions and usage-based charges. |
| Improve the product | Aggregated, de-identified usage analytics. We do not train models on your customers’ private messages or content without your explicit instruction. |
| Legal & compliance | Meet legal obligations and enforce our terms. |
6. Legal bases (GDPR / UK GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Contract — to provide the Services you sign up for.
- Legitimate interests — to secure, debug, and improve the Services, balanced against your rights.
- Consent — for optional cookies/analytics and any marketing communications, which you can withdraw at any time.
- Legal obligation — to comply with tax, accounting, and other laws.
For end-user Platform Data processed on a customer’s behalf, the customer is responsible for establishing the applicable legal basis.
7. How we share data
We do not sell personal data. We share data only with:
- Connected platforms — to carry out the actions you request (e.g., publishing a post to Instagram requires sending it to Meta).
- Sub-processors that help us run the Services under contract and confidentiality obligations: cloud hosting and infrastructure, database and storage providers, error-monitoring and logging, email delivery, and payment processing. A current list of sub-processors is available on request at privacy@plugkit.ai.
- Legal & safety — when required by law, to respond to lawful requests, or to protect the rights, safety, and security of PlugKit, our users, or the public.
- Corporate transactions — in connection with a merger, acquisition, or asset sale, subject to this policy.
8. Data retention
- Account data — for as long as your account is active, then deleted or anonymized within 90 days of account closure unless a longer period is legally required.
- OAuth tokens — until you disconnect the account or close your account, after which they are revoked and deleted.
- Platform Data & message/content data — retained only as needed to provide the feature you use (for example, inbox sync) and deleted on disconnection or request. We do not maintain a long-term archive of message bodies.
- Operational logs — typically retained for up to 30–90 days for security and debugging, then deleted.
- Billing records — retained as required by applicable tax and accounting law.
9. Your rights & data deletion
Subject to applicable law (including the GDPR and the California Consumer Privacy Act), you may request to access, correct, export, restrict, or delete your personal data, and object to certain processing. You may also withdraw consent and lodge a complaint with a supervisory authority.
9.1 Disconnect an account
You can revoke PlugKit’s access at any time from your PlugKit dashboard (Settings → Connections → Disconnect), or from the platform’s own app settings (for Meta: Settings & Privacy → Settings → Business integrations / Apps and Websites). Disconnecting revokes the stored tokens and deletes the associated Platform Data.
9.2 Delete your data
To delete your account and all associated personal data, email privacy@plugkit.ai from your account address, or use Settings → Delete account in the dashboard. We will verify the request and complete deletion within 30 days, except for data we must retain by law.
9.3 Data deletion requests for connected platforms
If you have used PlugKit through a Meta (Facebook/Instagram) login and want the data we processed from that account deleted, you can:
- Remove PlugKit from your Meta Business integrations settings, which sends us a deletion signal, or
- Email privacy@plugkit.ai with the subject line “Data Deletion Request” and the connected account name or ID.
Upon receiving a valid request we delete the corresponding tokens and Platform Data and confirm completion by email, typically within 30 days. We do not charge for these requests.
10. International transfers
PlugKit is operated from the United States, and our sub-processors may process data in the United States and other countries. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and additional technical measures.
11. Security
- Encryption in transit (TLS) and encryption at rest for tokens and sensitive data.
- Scoped, least-privilege access to credentials and short-lived internal access controls.
- Network isolation, audit logging, and continuous monitoring.
- Regular dependency and vulnerability management.
No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected users and authorities of incidents as required by law.
12. Cookies
Our marketing site uses only essential cookies needed to load the page and, where you consent, privacy-respecting analytics to understand aggregate traffic. The PlugKit dashboard uses strictly necessary cookies to keep you signed in. You can control non-essential cookies through your browser or our consent banner where shown.
13. Children
The Services are intended for businesses and developers and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy to reflect changes to the Services or the law. We will revise the “Last updated” date above and, for material changes, provide additional notice (for example, by email or an in-product notice). Your continued use of the Services after an update constitutes acceptance of the revised policy.
For privacy questions, data requests, or to reach our data protection contact:
If you are in the EEA/UK and are not satisfied with our response, you have the right to contact your local data protection authority.