Privacy policy
Effective date: October 1, 2026
Pluma is a headless CMS. You keep your site's content in Pluma, and your AI assistant (ChatGPT, Claude, Cursor or another MCP client) can read and edit it for you.
This page says what personal data Pluma keeps, why, who else sees it, and how long it stays.
Who runs Pluma. Pluma is run by Spacebar Company OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia. It's the data controller for the personal data on this page. We call it "Pluma", "we" or "us" on this page. Questions: team@page-bird.com.
The short version
- We keep what you need to sign in and run your sites: your name, email, password (hashed), and the content you put in.
- When you sign in, we save your IP address and browser name with your session.
- We don't use ads, trackers or analytics scripts. We don't sell data.
- When you connect ChatGPT or another assistant, it sees the site content it asks for. That's the point of connecting it.
- Your data stays until you delete it. You can delete your sites and your account yourself.
What we collect
Your account
| Data | Why |
|---|---|
| Name | To show who you are to your team and in the site's activity. |
| Email address | To sign you in, to match team invites, and to reset your password. |
| Password | To sign you in. We store only a one-way hash (bcrypt), never the password itself. |
| Organization name | Groups your sites. If you leave it blank, we use your name. |
Your sign-ins
Each time you sign in, we create a session and save:
- your IP address,
- your browser's user agent (the browser and system name it sends),
- when the session started.
We use these to keep you signed in and to spot sign-ins you don't recognize. A session lasts until you sign out, or until you don't use it for 30 days. Then we delete it, with its IP address and browser name.
Your sites and their content
Everything you or your assistant put in a site: content types, entries, every saved version of each entry, locales, files, alt text, descriptions, and the site's URLs.
This is your content. It can include personal data if you put it there (for example, staff names and photos on an "About us" page). You decide what goes in. You are responsible for having the right to publish it.
Files. You can upload JPG, PNG, WebP, GIF, SVG, PDF, MP4 and WebM files. When you upload a JPG, PNG or WebP, we remove its embedded metadata before storing it: the location a phone saves inside a photo, the camera, the dates. GIF, SVG, PDF and video files are stored as uploaded.
Files are public by link. Every file has a URL with a random piece in it, so it can't be guessed. Anyone who has the link can open it, even if the entry that uses it isn't published yet.
Your team and activity
- Memberships: who is on each site and with which role.
- Invitations: the invited email, the role, and whether the invite was accepted.
- Activity: who did what and when (for example, "Ana published Open House"). The "who" is a person or a connected assistant.
- Version authors: each saved version of an entry records who saved it.
Connected assistants (MCP and OAuth)
When you connect an assistant with Sign in with Pluma:
- The assistant registers itself with a name (for example "ChatGPT") and its return address.
- We record that you approved it, for which site, and when.
- We create an agent for it on that site: a name, its permissions, and when it was last used.
- We give the assistant a token. We store only a hash of it.
The token doesn't expire on its own. It works until you revoke the agent in Agents.
Keys and deploy hooks
- API keys: a name, the kind, and when it was last used. We store only a hash of the key.
- Deploy hooks: the URL you gave us (for example your Netlify or Vercel build hook), a secret we encrypt, and a log of each call we made to it.
Access requests
While sign-up is closed, you can ask for access at /request-access. We keep your name, email, site URL, which assistant you use, and your note. We use them to decide who to invite and to write back to you.
Usage counts
We count API and MCP calls per site per month, and we record which setup steps each site finished. These are counts, not a log of what you did.
Analytics of your sites' visitors
If you add the Pluma snippet (pluma.js) to your site, or report AI crawler visits from your site's server, we collect visits to your site for you. For each page view: the page, the referring site, UTM parameters, country and city, device type, and a visitor code. For each crawler visit: which crawler, the page and the response code.
- No cookies and nothing stored in your visitors' browsers.
- No IP addresses stored. We use the IP once, when the visit arrives, to look up country and city in a database on our own server (IP Geolocation by DB-IP, CC BY 4.0) and to make the visitor code. Then we drop it.
- The visitor code is a hash of the site, IP and browser with a key that changes every day, so a visitor counts once a day and can't be followed from one day to the next or traced back to an IP.
- For this data you're the controller and Pluma processes it for you. Tell your visitors in your own privacy policy.
Google Search Console and Bing Webmaster Tools
If an owner or admin of a site connects Google Search Console or Bing Webmaster Tools in Settings → Integrations, we read that site's search data: which searches and pages showed the site, with clicks, impressions, click-through rate and average position. These are totals; Google and Bing don't tell us who searched.
- What we keep: for Google, a refresh token; for Bing, the API key you paste. Both are encrypted in the database and never shown again, sent to an assistant or written to logs. Also the property or site we read, who connected it, and the search data by day (Google) or week (Bing).
- Google access is read-only (the
webmasters.readonlyscope). We ask for nothing else from your Google account. - Limited use. Pluma's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Search Console data only to show it to the site's team and to the assistants they connect. We don't use it for ads, we don't sell it or share it with anyone else, we don't use it to train AI models, and no person at Pluma reads it unless you ask us to for support, for security, or the law requires it.
- Disconnecting deletes the token or key and that engine's data right away. On Google, it also revokes Pluma's access; you can revoke it yourself at any time in your Google Account.
Server logs
Our server writes a log line for each request. It includes the IP address, the page or endpoint, and the request's parameters. Passwords, emails, tokens, secrets and the content you or your assistant send (entry fields, uploaded files, MCP tool arguments) are masked in the log.
What we don't collect
- No analytics, ad or tracking scripts on any Pluma page. (The analytics above are for your sites, and only if you add them.)
- No payment data. Billing isn't live yet.
- We don't read your content for any purpose other than running the service and fixing problems you report.
Why we use your data
- To run the service: sign you in, store your sites, serve your content and files, run your assistant's requests.
- To keep it safe: limit repeated sign-in attempts, detect abuse, investigate problems.
- To talk to you: answer access requests and support messages, and send password-reset emails.
- To follow the law, when we have to.
The legal basis is the contract with you for your account and content, and our legitimate interest for security logs and access requests.
We don't sell your data. We don't use it for ads. We don't use your content to train AI models.
Who else sees your data
Service providers we use today
| Provider | What it does | What it sees |
|---|---|---|
| Fly.io | Hosts the app, the database and the files. Region: Ashburn, Virginia, USA (iad). |
Everything stored in Pluma, and the server logs. |
| DataForSEO | Only if a site uses AI answers: asks its questions to ChatGPT, Gemini, Claude and Perplexity, and returns how often people ask AI assistants those searches. | The site's questions and its country. No visitor data and no content. |
| OpenAI | Only if a site uses AI answers: asks its questions to ChatGPT through the API, reads the answers, and suggests questions. | The site's questions, its name, address and published content (to compare against the answers). No visitor data. OpenAI doesn't train on API data by default. |
Providers we plan to add
These aren't in use yet. We'll update this page before we turn any of them on.
| Provider | Planned use |
|---|---|
| Cloudflare R2 | Storing files and database backups. |
| Stripe | Billing. Stripe would see your payment details; we would not. |
| Resend | Sending emails (invites, password resets). |
Places you send data to
These receive data because you set them up. They are not our providers. Their own privacy policies apply.
-
Your AI assistant. When you connect ChatGPT, Claude or another MCP client, it receives what its tools return. That can be:
- your site's content, drafts included (if your role allows drafts),
- file names, alt text and public file links,
- the site's activity, with the names of the people and assistants who made each change,
- who saved each version of an entry, by name,
- deploy hook names and URLs, and API key names (never a full existing key).
The assistant's provider (for example OpenAI for ChatGPT) handles that data under its own terms. Pluma never sends your email address, password, IP address or sessions to the assistant.
-
Your deploy hooks. When you publish, we call the URL you set up (Netlify, Vercel or your own). We send the site's slug, what changed (entry and type ids) and when. No names, no emails, no content.
-
Anyone you share content with. Your site's delivery key and file links let your website, or anyone who has them, read published content.
-
Google and Bing. When you connect them, our server calls their APIs with your token or key to read the site's search data. We send them nothing else.
-
Links you ask us to fetch. If your assistant uploads a file by URL, our server downloads it from that address. That site sees our server's IP, not yours.
Legal requests
We share data with authorities only when the law requires it. When the law allows, we tell you first.
How long we keep it
Here's how long each thing stays:
| Data | How long |
|---|---|
| Account (name, email, password hash) | Until you delete it in Account. Your name and email are erased; what you did stays in each site's history as "Deleted user". |
| Sessions (IP, user agent) | Until you sign out, or 30 days without use. Then we delete them. |
| Site content and every entry version | Until an owner deletes the site. Archiving an entry hides it but keeps it. |
| Files | Until you delete them. A file used by an entry can't be deleted until you remove it from that entry. |
| Activity and version authors | Until the site is deleted. |
| Connected assistants and OAuth approvals | The record stays after you revoke it, so the activity still makes sense. The token stops working right away. |
| Deploy hook call log | Until the hook or the site is deleted. |
| Access requests | 12 months after you send them, or sooner if you ask. |
| Visits to your sites (analytics) | 13 months, then deleted every day. Also deleted with the site. |
| Search data from Google and Bing | 13 months, then deleted every day. Deleted right away when the engine is disconnected or the site is deleted. |
| Google refresh token and Bing API key | Until the engine is disconnected or the site is deleted. |
| Server logs | Kept by Fly.io for up to 30 days. We don't send them anywhere else. |
| Backups | Fly.io takes a snapshot of the database and files every day and keeps each one 5 days. |
Your choices and rights
In the dashboard, you can:
- Revoke any connected assistant in Agents. It loses access right away.
- Revoke any API key in Settings → Keys.
- Delete files that no entry uses.
- Delete deploy hooks.
- Disconnect Google Search Console or Bing Webmaster Tools in Settings → Integrations (owners and admins), which deletes their data.
- Remove people from a site in Settings → Team (owners and admins).
- Sign out, which deletes that session.
- Delete a site (owners) at the bottom of its home page.
- Delete your account in Account.
- Export a whole site as JSON (
GET /api/v1/spaces/:space_id/export, or theexport_spacetool).
By email, you can ask us to:
- tell you what data we have about you,
- correct it,
- delete an access request, or anything you can't delete yourself,
- send you a copy of your data.
Write to team@page-bird.com. We answer within 30 days.
If you're a team member on a site someone else owns, the site's owner controls that site's content. We may send your request to them.
You can also object to how we use your data, ask us to limit it, and complain to a data protection authority: in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), or the one where you live. If you're in California, you have the same rights to know and to delete; we don't sell or share personal data as California law defines it.
Cookies
Pluma sets only the cookies it needs to work. No ad or analytics cookies.
| Cookie | What it does | How long |
|---|---|---|
session_id |
Keeps you signed in. Signed, HttpOnly, SameSite=Lax, HTTPS only. |
Until you sign out, or 30 days without use. |
_pluma_session |
Remembers short things between pages: where to return after sign-in, one-time messages, and form protection (CSRF). | Until you close the browser. |
Security
- All traffic uses HTTPS.
- Passwords are hashed with bcrypt. API keys, agent tokens, invite links and OAuth codes are stored only as hashes.
- Deploy hook secrets, Google refresh tokens and Bing API keys are encrypted in the database.
- Sign-in, sign-up, password reset and access requests are rate limited.
- An assistant can never do more than the person who connected it, and loses rights the moment that person's role goes down.
No system is perfect. If we learn of a breach that affects your data, we'll tell you by email within 72 hours of confirming it.
Children
Pluma is not for children under 16. We don't knowingly collect their data.
International transfers
Pluma's servers are in the United States. If you use Pluma from another country, your data goes to the US. The transfer relies on the European Commission's Standard Contractual Clauses.
Changes
When we change this page, we update the date at the top. If a change matters, we'll tell you in the dashboard or by email before it takes effect.
Contact
Spacebar Company OÜ · Sepapaja tn 6, 15551 Tallinn, Estonia · team@page-bird.com