Privacy Policy
Last updated: 9 August 2026
Last updated: 9 August 2026
1. Who we are (Controller)
1.1. This Privacy Policy explains how Individual Entrepreneur Daniil Kudinov (ინდივიდუალური მეწარმე დანიილ კუდინოვ) (Registration No. (NAPR): B26394689, Taxpayer ID: 345848782, Selim Khimshiashvili St. 20, Batumi, Georgia) (“Plumar”, “we”) processes personal data when you use plumar.ai and app.plumar.ai (the “Service”). We are the controller of your personal data.
1.2. Contact for privacy matters: legal@plumar.ai.
1.3. EU representative (Art. 27 GDPR): we are in the process of appointing a representative in the European Union. Until then, and at any time thereafter, EU/EEA users may contact us directly at legal@plumar.ai regarding any matter relating to the processing of their personal data.
2. Data we collect
2.1. Account data — name, email, phone (if provided), password (hashed), profile details.
2.2. Content you submit — your prompts, uploaded images/audio/video (“Inputs”) and the results you generate (“Outputs”), stored in your library.
2.3. Usage & device data — actions in the Service, log data, IP address, approximate location (country), browser/device information, cookies and similar technologies.
2.4. Payment data — processed by our payment provider; we receive transaction status and limited card metadata (e.g., last four digits), not full card numbers.
3. How we use data & legal bases (GDPR)
3.1. To provide the Service, your account and AI generations — performance of a contract.
3.2. To operate, secure, debug and improve the Service, prevent abuse and fraud — legitimate interests.
3.3. To process payments and keep accounting/tax records — legal obligation and contract.
3.4. For optional marketing emails and non-essential cookies — consent, which you can withdraw at any time.
4. AI processing & model training
4.1. To generate Outputs, your Inputs are processed by third-party AI Providers (foundation-model providers) acting as our sub-processors.
4.2. We do not use your Inputs or Outputs to train our own AI models. Third-party AI Providers process your Inputs solely to return a result to you. Their own retention and model-improvement practices are governed by their respective terms, which differ between providers and may change. A current list of our AI sub-processors, with links to their terms, is available on request at legal@plumar.ai.
4.3. Identity verification (face assets). To use a real person’s face lawfully, the Service offers an identity check: you open a page hosted by the AI Provider and complete a liveness check (a guided selfie). We never receive or store the biometric template produced by that check — the Service only receives the result (passed / failed) and the identifier of the created asset.
4.4. Frames you upload for a verified face are stored in the Provider’s library for as long as your consent lasts, and are used solely for your own generations — or, where you explicitly chose that option, for the studio’s productions. We store the asset identifier, the link to the source frame, the document version you accepted, the timestamp, IP address and browser details as evidence of consent.
4.5. Processing of facial images is based on your explicit consent (Art. 9(2)(a) GDPR). You may withdraw it at any time in the Service or by writing to legal@plumar.ai. On withdrawal the face is no longer used in generations and the materials are deleted including from the Provider’s library. The record that consent was given, and when, is retained as proof that earlier processing was lawful.
5. Sharing & sub-processors
5.1. We share personal data only with service providers that process it on our behalf under contract, including: cloud hosting and storage, AI foundation-model providers, the payment provider, email delivery, and analytics/error monitoring. We do not sell your personal data.
5.2. We may disclose data where required by law or to protect our rights, users and the Service.
6. International transfers
6.1. We are established in Georgia, and our AI Providers and infrastructure providers may process data outside the EU/EEA. Georgia is not covered by a European Commission adequacy decision. Where personal data of EU/EEA users is transferred, we rely on Standard Contractual Clauses adopted by the European Commission (Art. 46 GDPR) together with supplementary measures where required, or on another lawful transfer mechanism under Chapter V GDPR.
7. Retention
7.1. We keep account and content data while your account is active and as needed to provide the Service. After account deletion we delete or anonymise personal data within a reasonable period, except where retention is required by law (e.g., accounting records) or to resolve disputes.
8. Your rights
8.1. Subject to applicable law (including the GDPR where it applies), you may request: access to your data; rectification; erasure; restriction of processing; portability; objection to processing based on legitimate interests; and withdrawal of consent. You may also lodge a complaint with your local data-protection authority.
8.2. To exercise your rights, contact support@plumar.ai. We may need to verify your identity.
9. Cookies
9.1. We use strictly necessary cookies to run the Service and, with your consent, analytics/preference cookies. You can manage non-essential cookies via your browser or our cookie controls.
10. Security
10.1. We use technical and organisational measures to protect personal data (encryption in transit, access controls, hashed passwords). No method of transmission or storage is fully secure; we cannot guarantee absolute security.
11. Children
11.1. The Service is not directed to persons under 18, and we do not knowingly collect their personal data.
12. Changes & contact
12.1. We may update this Policy; material changes will be notified via the Service or email. Questions or requests: support@plumar.ai.
© 2026 Plumar · Individual Entrepreneur Daniil Kudinov (ინდივიდუალური მეწარმე დანიილ კუდინოვ). All rights reserved.