Legal
Last updated: June 4, 2026
This Privacy Policy describes how Noble Nest sp. z o.o. (“we,” “us,” or “our”), operating the PlutoPro platform at plutopro.ai (the “Service”), collects, uses, shares, and protects your information when you use the Service.
Noble Nest sp. z o.o. is the data controller for the purposes of the EU General Data Protection Regulation (GDPR) and Polish data protection law.
By using PlutoPro, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
The data controller responsible for your personal data is:
For any privacy-related question or request, contact us at support@plutopro.ai with “Privacy Request” in the subject line. We respond within 30 days.
We have assessed whether a Data Protection Officer is required under Article 37 GDPR and concluded it is not — we do not carry out large-scale processing of special category data, nor large-scale systematic monitoring of data subjects. The controller remains directly responsible for all privacy matters.
When you create an account, we collect your name, email address, and authentication credentials managed through our auth provider (Supabase Auth). If you sign up via a third-party provider (e.g., Google), we receive the profile information you authorise that provider to share.
When you connect an ecommerce store (Amazon, Shopify, or Etsy), PlutoPro imports product data including titles, descriptions, bullet points, prices, images, and related metadata. This data is used solely to generate social media content on your behalf. Store connection credentials (OAuth access and refresh tokens) are encrypted at the application layer using AES-256-GCM before storage and are additionally encrypted at rest by our database provider.
If you provide a public store or website URL that is not connected through a supported integration, we may fetch that URL's public pages — via a reader sub-processor listed on our Sub-Processors page — solely to extract your brand identity for your brand brief. We send only the public URL and read only publicly available page content; we do not submit account credentials, and this reader is never used for Amazon or Shopify connections.
When you connect an Amazon Seller account, PlutoPro uses the Amazon Selling Partner API (SP-API) under roles you authorise. Specifically:
Our use of Amazon SP-API data complies with Amazon's Data Protection Policy and Acceptable Use Policy. If a seller's authorisation is revoked (by the seller or by Amazon), we stop processing that seller's data and purge the SP-API refresh token and associated catalog data immediately. We will permanently and securely delete Amazon Information within 30 days of any deletion request from Amazon, in accordance with Amazon's Data Protection Policy.
If you connect Google Drive, we access only the specific folders you authorise. We import image metadata (filenames, dimensions) and image content for the purpose of mapping assets to your products. We do not access other files in your Google Drive.
We collect your interactions with generated content — approvals, rejections, edits, and regeneration instructions — to improve content quality over time through our learning system. These signals are stored per-brand and are never shared across accounts.
Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other sensitive financial information on our servers. We receive only a confirmation of your subscription status and billing metadata from Stripe.
We automatically collect standard log data including IP addresses, browser type, pages visited, and timestamps. We use PostHog for product analytics and Sentry for error monitoring and crash reporting.
Under Article 6 GDPR, we rely on the following legal bases for each category of processing:
We use the information we collect to:
We do not use your product data, store data, Amazon SP-API data, or generated content to train AI models. Your data is processed solely to deliver the Service to you.
PlutoPro uses the sub-processors listed on our Sub-Processors page to deliver the platform. We share only the minimum data each sub-processor needs to perform its function.
Some of these sub-processors are located in the United States. Where data is transferred outside the European Economic Area, we rely on the EU Standard Contractual Clauses (SCCs) published by the European Commission (Decision 2021/914) and, where applicable, the EU–US Data Privacy Framework. We assess each transfer for supplementary technical and organisational measures in line with the Schrems II ruling.
We do not sell your personal data, share it with advertisers, or use it for any purpose other than delivering the Service.
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
When you delete your account, we delete or anonymise your personal data within 30 days. Residual copies may persist in encrypted backups for up to 30 additional days before rolling off, after which they are permanently unavailable.
You have the following rights regarding your personal data:
If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of any sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
You can delete your account directly from the account settings page; this triggers immediate deletion of your personal data in accordance with Section 6. For access requests, data exports, and all other rights, email support@plutopro.ai with “Privacy Request” in the subject line. We respond within 30 days. We may ask you to verify your identity before fulfilling a request.
We implement technical and organisational measures appropriate to the risk, including:
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we continuously improve our controls.
We maintain a written incident-response plan covering preparation, detection, containment, eradication, recovery, and post-incident review, with a designated security point of contact reachable at support@plutopro.ai. In the event of a confirmed personal-data breach we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours (Article 33 GDPR), and affected individuals where the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR). Where a security incident affects data obtained through the Amazon Selling Partner API, we will additionally notify Amazon within 24 hours of confirmation, in accordance with Amazon's Data Protection Policy.
PlutoPro uses cookies to operate the Service. We categorise them as follows:
These cookies are required for authentication and session management. They cannot be disabled.
These cookies are only set if you accept cookies via our consent banner. They help us understand how the Service is used so we can improve it.
We do not use advertising cookies, tracking pixels, or third-party ad networks. We do not sell your data to advertisers. You can change your cookie preference at any time by clearing your browser cookies and revisiting the site.
PlutoPro is a business tool not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes that affect your rights, we will notify you via email.
If you have questions about this Privacy Policy or our data practices, contact us at:
Noble Nest sp. z o.o.
ul. Złota 75A, lok. 7, 00-819 Warszawa, Polska
support@plutopro.ai