plutonium.io Reactor — Privacy Policy
Effective date: 10 October 2026
This policy explains what personal data plutonium.io (“we”, “us”) collects when you use plutonium.io and the plutonium.io Reactor service (“Reactor”), why we collect it, who processes it for us, and the choices you have. Our Terms of Service apply alongside it.
Reactor lets account holders (“customers”) build automated agent workflows (“loops”) that can run on schedules, read websites, publish public pages with forms, embed a chat on the customer’s own website, send email, and connect to other services. That means there are two kinds of data here:
- Data about our customers and their team members, which we control (sections 1-3).
- Data about our customers’ own visitors and end users, which the customer controls and we process on the customer’s behalf (section 4).
1. What we collect
Waitlist
To join the waitlist you give us your name, email address, and optionally your company. If you join through our conversational waitlist instead of the form, we may also record your answers to a few questions: what describes you, your use case, your role, and how you heard about us. We record when you signed up and which route you used.
Signing in with Google
Reactor accounts are created by us; you sign in with Google. When you do, Google shares your
email address, whether Google has verified it, your name, and your profile picture. We
request only the openid email profile scopes. We use the Google access token once to read
that profile and do not store it. We store your email, name, profile picture link, and when you
were last seen.
Your account and its work
When you use Reactor we store what you and your agents create: loops and their versions, pages, collections and their records, workspace files, uploaded documents and search indexes, task and run history (including the conversation with the agent), approvals, and usage and billing records. We keep an audit record of console actions: who acted, which operation, its path parameters and the result — never the request body.
Connected services
If you connect a third-party service, the credential you provide (an API key or OAuth token) is stored in an encrypted secret store and is readable only by the part of the system that runs tools for you, not by the web API.
Invitations
If you invite a team member, we store the email address you invited and send them an invitation email.
Payments
We do not take card payments yet. Adding money by card opens soon; until then, we add credit to your account, and we collect no payment details. We store your wallet balance and the credit we add. When card payments open, Stripe will handle them: you will enter card details on Stripe’s own pages, and we will not receive or store your card number. We will update this policy before then.
Cookies and browser storage
We set only first-party, functional cookies — no advertising or tracking cookies:
| Name | Purpose | Lifetime | Flags |
|---|---|---|---|
session_id | Keeps you signed in (also used during the sign-in handshake) | 7 days, renewed as you use the service | HttpOnly, Secure, SameSite=Lax |
app_grant | A signed token our CDN checks before serving the signed-in app | Same as the session | HttpOnly, Secure, SameSite=Lax |
In your browser’s local storage the app also keeps a few interface preferences (for example whether the assistant panel is open, which pages you have visited, and whether you joined the waitlist). The embedded chat keeps its visitor token in session storage, which is cleared when the browser tab closes.
Usage analytics
We do not use third-party analytics, advertising, or tracking scripts. Our app records first-party product events (which action, on which screen, and how long it took) tagged with a pseudonymous, hashed session and account identifier, not your name or email.
Logs and IP addresses
Our servers write operational logs. We design them to exclude personal values: for example, a rejected waitlist submission logs which field was missing, never what you typed. We use your IP address to enforce rate limits on public endpoints (sign-up, public pages, embedded chats); it is held as part of a short-lived rate-limit counter that is deleted automatically, and we do not write it to our application logs.
Landing-page demos
Our home page runs live demos. Records a demo creates are deleted automatically about one hour after they are created.
2. Why we use it (and our legal bases)
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Run the waitlist and decide who to invite | Waitlist data | Your consent / our legitimate interest in managing access |
| Sign you in and keep your account secure | Google profile, session cookies | Performance of our contract with you |
| Provide Reactor’s features | Account content | Performance of contract |
| Keep your wallet and bill for usage | Billing and usage records | Performance of contract; legal obligations (tax, accounting) |
| Prevent abuse and keep the service up | IP addresses (rate limits), logs, audit records | Legitimate interest in security |
| Improve the product | Pseudonymous product events | Legitimate interest |
| Send service email (invitations, verification codes) | Email address | Performance of contract |
We do not sell personal data, and we do not use it for advertising.
3. Who processes data for us (sub-processors)
| Sub-processor | What it does | Data involved |
|---|---|---|
| Amazon Web Services (region us-east-1, United States) | Hosting, databases, file storage, logs, email sending (Amazon SES), content delivery | All service data |
| OpenRouter | Routes AI model requests to model providers | The content of agent conversations and tasks, documents being indexed, search queries |
| AI model providers, via OpenRouter | Generate model responses and text embeddings | Same as OpenRouter. The models available today are listed on our Pricing page |
| Sign-in | Your Google identity, as described above |
When card payments open, Stripe will process them, as described under Payments above.
Our monitoring dashboards run on our own servers within AWS.
AI processing. When an agent runs, the prompts, conversation, and any content it reads or writes are sent to OpenRouter and the model provider that serves the request. Every request we send to OpenRouter asks it to use only model providers that do not collect the request’s data or train on it. We do not train AI models on your content.
International transfers. Data is stored in the United States. Where the law requires a transfer mechanism (for example, from the EEA or UK), we rely on the European Commission’s Standard Contractual Clauses.
4. Customer data: embedded chats, public pages and forms
Customers use Reactor to talk to their own visitors and users: an agent chat embedded on the customer’s website, public pages with forms, emails a loop sends, and data loops collect or receive. For that data, the customer is the controller and we are a processor acting on the customer’s instructions. That includes:
- what visitors type into an embedded chat or a page form, and the agent’s replies;
- identifiers the customer’s site passes to us to identify its own users;
- email addresses a loop sends to, and addresses a visitor verifies with a one-time code (we store only a salted hash of the code, never the code itself);
- content of websites a customer’s loop crawls, and data the customer’s systems send to their loops by webhook.
If you are a visitor to a customer’s site or page and want to access or delete your data, please contact that customer. We will help the customer respond. Our data processing addendum for customers is available on request at loren@plutonium.io.
Anonymous visitors are given a random visitor ID so a conversation can continue; the ID is held in the browser tab’s session storage, not in a cookie. We use the visitor’s IP address only for the rate limits described above.
5. How long we keep data
| Data | Retention |
|---|---|
| Sign-in sessions | Expire 7 days after last activity |
| Rate-limit counters (including IP addresses) | Deleted automatically after their time window ends, at most 31 days |
| Detailed task event history | 90 days; the run record and conversation archive remain while the account exists |
| Landing-page demo records | About 1 hour |
| Server logs | 90 days |
| Pseudonymous product events | 395 days |
| Waitlist entries | Until you ask us to remove them |
| Account content, workspace files, uploads, transcripts | While your account is active, and deleted on request |
| Billing records | 7 years |
6. Security
We protect data with measures including: HTTPS for all traffic; session cookies marked HttpOnly and Secure; storage buckets that block public access; credentials for connected services held in an encrypted secret store that the web API cannot read; one-time verification codes stored only as salted hashes; and logs designed to exclude personal values. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the authorities as the law requires.
7. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and get a portable copy;
- correct it;
- delete it;
- object to or restrict some processing, and withdraw consent where we rely on it;
- complain to your local data protection authority.
California residents (CCPA/CPRA): you have the right to know what we collect, to delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising.
How to make a request: email loren@plutonium.io. Reactor does not yet have a self-service account deletion button, so deletion of an account and its data is handled on request. We will verify your identity and respond within 30 days. If you are a visitor to a customer’s embedded chat or page, see section 4.
8. Children
Reactor is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
9. Changes to this policy
We may update this policy. If a change is material we will tell account holders by email or in the app before it takes effect, and we will update the effective date above.
10. Contact
plutonium.ioloren@plutonium.io