Privacy Policy
Effective September 13, 2026
This Policy explains how Plyry processes personal data when you use its website, accounts, AI-generation tools, payments, and support services.
1. Data we collect
We may collect account and contact details; the IP address used when an account is first created or, for an existing account without one on record, its next successful sign-in; prompts, uploads, generated outputs, and job metadata; wallet and transaction records; support messages; and device, browser, security, and usage data. This IP is recorded once and is not replaced on later sign-ins. Card details are handled by payment providers and are not intended to be stored by Plyry.
2. How we use data
We use data to provide generations, authenticate accounts, process wallet activity, deliver files, provide support, secure the Service, prevent fraud and abuse, comply with law, and understand and improve performance.
3. Sharing and international processing
Data may be shared with hosting, AI-processing, payment, security, analytics, and support providers; professional advisers; authorities where legally required; and a successor in a corporate transaction. Providers may process data in other countries under appropriate safeguards. We do not sell personal data.
4. Generated media and device copies
A completed media file remains on Plyry’s server until an authenticated browser downloads it, commits it to that browser’s IndexedDB storage, reads it back, verifies its SHA-256 checksum, and sends a matching cache receipt. Plyry then deletes the server media file. If device storage, read-back, or verification fails, the server file remains available in the account. Deleting a generation removes the copy stored by the current browser, purges any remaining server media file, and hides the item from the user’s library. Copies saved or cached on other devices are controlled from those devices.
5. Retention schedule
The media file and its job record are separate. Prompts and job records—including media type and model, price, status, checksums, timestamps, errors, and cache or deletion events—remain in the database after the server media file is deleted and after a generation is hidden from the user’s library. The current service does not apply a fixed automatic deletion period to job records; they are retained for account history, billing, support, safety, fraud prevention, disputes, and audit needs, subject to applicable rights and legal obligations. The one-time account IP is retained with the account for security, fraud prevention, and audit purposes. Raw first-party analytics events are configured for a 90-day retention window and are deleted when retention cleanup runs after they are summarized into daily aggregate counts. Account, ledger, payment, support, safety, and audit records may be kept as long as needed for the purposes described in this Policy. Browser-stored copies remain on each device until the user deletes the generation there, clears site data, or otherwise removes the file.
6. Security
We use reasonable technical and organizational safeguards, including authenticated media access, private no-store responses, checksum verification before server-file deletion, and access controls for account and administrative functions. No system is completely secure.
7. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection. You may manage account data, delete eligible library items, and contact us to request deletion of retained prompts or job records. Deletion requests may be limited where records must be kept for legal obligations, payments, disputes, safety, fraud prevention, or security. We may verify your identity before responding.
8. Children and changes
Plyry is not directed to children who cannot legally consent to data processing. Do not submit a child’s personal data without lawful authority. We may update this Policy and will show the current effective date.
9. Privacy contact
Send privacy questions or rights requests to hello@plyry.com.