plutonium.io Reactor — Privacy Policy

Effective date: 10 October 2026

This policy explains what personal data plutonium.io (“we”, “us”) collects when you use plutonium.io and the plutonium.io Reactor service (“Reactor”), why we collect it, who processes it for us, and the choices you have. Our Terms of Service apply alongside it.

Reactor lets account holders (“customers”) build automated agent workflows (“loops”) that can run on schedules, read websites, publish public pages with forms, embed a chat on the customer’s own website, send email, and connect to other services. That means there are two kinds of data here:

  • Data about our customers and their team members, which we control (sections 1-3).
  • Data about our customers’ own visitors and end users, which the customer controls and we process on the customer’s behalf (section 4).

1. What we collect

Waitlist

To join the waitlist you give us your name, email address, and optionally your company. If you join through our conversational waitlist instead of the form, we may also record your answers to a few questions: what describes you, your use case, your role, and how you heard about us. We record when you signed up and which route you used.

Signing in with Google

Reactor accounts are created by us; you sign in with Google. When you do, Google shares your email address, whether Google has verified it, your name, and your profile picture. We request only the openid email profile scopes. We use the Google access token once to read that profile and do not store it. We store your email, name, profile picture link, and when you were last seen.

Your account and its work

When you use Reactor we store what you and your agents create: loops and their versions, pages, collections and their records, workspace files, uploaded documents and search indexes, task and run history (including the conversation with the agent), approvals, and usage and billing records. We keep an audit record of console actions: who acted, which operation, its path parameters and the result — never the request body.

Connected services

If you connect a third-party service, the credential you provide (an API key or OAuth token) is stored in an encrypted secret store and is readable only by the part of the system that runs tools for you, not by the web API.

Invitations

If you invite a team member, we store the email address you invited and send them an invitation email.

Payments

We do not take card payments yet. Adding money by card opens soon; until then, we add credit to your account, and we collect no payment details. We store your wallet balance and the credit we add. When card payments open, Stripe will handle them: you will enter card details on Stripe’s own pages, and we will not receive or store your card number. We will update this policy before then.

Cookies and browser storage

We set only first-party, functional cookies — no advertising or tracking cookies:

NamePurposeLifetimeFlags
session_idKeeps you signed in (also used during the sign-in handshake)7 days, renewed as you use the serviceHttpOnly, Secure, SameSite=Lax
app_grantA signed token our CDN checks before serving the signed-in appSame as the sessionHttpOnly, Secure, SameSite=Lax

In your browser’s local storage the app also keeps a few interface preferences (for example whether the assistant panel is open, which pages you have visited, and whether you joined the waitlist). The embedded chat keeps its visitor token in session storage, which is cleared when the browser tab closes.

Usage analytics

We do not use third-party analytics, advertising, or tracking scripts. Our app records first-party product events (which action, on which screen, and how long it took) tagged with a pseudonymous, hashed session and account identifier, not your name or email.

Logs and IP addresses

Our servers write operational logs. We design them to exclude personal values: for example, a rejected waitlist submission logs which field was missing, never what you typed. We use your IP address to enforce rate limits on public endpoints (sign-up, public pages, embedded chats); it is held as part of a short-lived rate-limit counter that is deleted automatically, and we do not write it to our application logs.

Landing-page demos

Our home page runs live demos. Records a demo creates are deleted automatically about one hour after they are created.

PurposeDataLegal basis (GDPR)
Run the waitlist and decide who to inviteWaitlist dataYour consent / our legitimate interest in managing access
Sign you in and keep your account secureGoogle profile, session cookiesPerformance of our contract with you
Provide Reactor’s featuresAccount contentPerformance of contract
Keep your wallet and bill for usageBilling and usage recordsPerformance of contract; legal obligations (tax, accounting)
Prevent abuse and keep the service upIP addresses (rate limits), logs, audit recordsLegitimate interest in security
Improve the productPseudonymous product eventsLegitimate interest
Send service email (invitations, verification codes)Email addressPerformance of contract

We do not sell personal data, and we do not use it for advertising.

3. Who processes data for us (sub-processors)

Sub-processorWhat it doesData involved
Amazon Web Services (region us-east-1, United States)Hosting, databases, file storage, logs, email sending (Amazon SES), content deliveryAll service data
OpenRouterRoutes AI model requests to model providersThe content of agent conversations and tasks, documents being indexed, search queries
AI model providers, via OpenRouterGenerate model responses and text embeddingsSame as OpenRouter. The models available today are listed on our Pricing page
GoogleSign-inYour Google identity, as described above

When card payments open, Stripe will process them, as described under Payments above.

Our monitoring dashboards run on our own servers within AWS.

AI processing. When an agent runs, the prompts, conversation, and any content it reads or writes are sent to OpenRouter and the model provider that serves the request. Every request we send to OpenRouter asks it to use only model providers that do not collect the request’s data or train on it. We do not train AI models on your content.

International transfers. Data is stored in the United States. Where the law requires a transfer mechanism (for example, from the EEA or UK), we rely on the European Commission’s Standard Contractual Clauses.

4. Customer data: embedded chats, public pages and forms

Customers use Reactor to talk to their own visitors and users: an agent chat embedded on the customer’s website, public pages with forms, emails a loop sends, and data loops collect or receive. For that data, the customer is the controller and we are a processor acting on the customer’s instructions. That includes:

  • what visitors type into an embedded chat or a page form, and the agent’s replies;
  • identifiers the customer’s site passes to us to identify its own users;
  • email addresses a loop sends to, and addresses a visitor verifies with a one-time code (we store only a salted hash of the code, never the code itself);
  • content of websites a customer’s loop crawls, and data the customer’s systems send to their loops by webhook.

If you are a visitor to a customer’s site or page and want to access or delete your data, please contact that customer. We will help the customer respond. Our data processing addendum for customers is available on request at loren@plutonium.io.

Anonymous visitors are given a random visitor ID so a conversation can continue; the ID is held in the browser tab’s session storage, not in a cookie. We use the visitor’s IP address only for the rate limits described above.

5. How long we keep data

DataRetention
Sign-in sessionsExpire 7 days after last activity
Rate-limit counters (including IP addresses)Deleted automatically after their time window ends, at most 31 days
Detailed task event history90 days; the run record and conversation archive remain while the account exists
Landing-page demo recordsAbout 1 hour
Server logs90 days
Pseudonymous product events395 days
Waitlist entriesUntil you ask us to remove them
Account content, workspace files, uploads, transcriptsWhile your account is active, and deleted on request
Billing records7 years

6. Security

We protect data with measures including: HTTPS for all traffic; session cookies marked HttpOnly and Secure; storage buckets that block public access; credentials for connected services held in an encrypted secret store that the web API cannot read; one-time verification codes stored only as salted hashes; and logs designed to exclude personal values. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the authorities as the law requires.

7. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you, and get a portable copy;
  • correct it;
  • delete it;
  • object to or restrict some processing, and withdraw consent where we rely on it;
  • complain to your local data protection authority.

California residents (CCPA/CPRA): you have the right to know what we collect, to delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising.

How to make a request: email loren@plutonium.io. Reactor does not yet have a self-service account deletion button, so deletion of an account and its data is handled on request. We will verify your identity and respond within 30 days. If you are a visitor to a customer’s embedded chat or page, see section 4.

8. Children

Reactor is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

9. Changes to this policy

We may update this policy. If a change is material we will tell account holders by email or in the app before it takes effect, and we will update the effective date above.

10. Contact

plutonium.io
loren@plutonium.io