Privacy

Updated April 19, 2026

Privacy Policy

This policy explains what Pluria collects, why each category is collected, whether it is required or optional, what may be public, and how deletion, consent, and GDPR-related rights work.

Account and sign-in data

  • What: Email address, password credentials handled by our authentication providers, phone number, linked Google or Apple provider data, session metadata, and sign-in method history.
  • Why: Create and secure accounts, let you sign in again, recover access, send security notices, and prevent abuse.
  • Required or optional: Email is required only for email-password sign-in. Phone is required only for phone sign-in or when you later choose to link it. Google and Apple data are collected only if you choose those methods.
  • Public or private: Private. Sign-in and recovery data is not shown on your public profile.
  • GDPR / legal basis: Contract to provide the account you request, legitimate interests in keeping accounts secure, and legal obligations where required.

Profile and content data

  • What: Username / handle, display name, avatar, bio, website, social links, published polls, comments, takes, reposts, saves, follows, and creation metadata.
  • Why: Run public profiles, publishing tools, profile search, creator attribution, moderation, and public poll pages.
  • Required or optional: Username is required because Pluria needs a stable public identifier. Display name, avatar, bio, website, and social links are optional and can be skipped or edited later.
  • Public or private: Content you publish and profile fields you choose to populate can be public. Moderation notes, drafts, abuse signals, and internal review data stay private.
  • GDPR / legal basis: Contract to provide profile and publishing features, plus legitimate interests in moderation, safety, and integrity.

Demographic and eligibility data

  • What: A 13+ eligibility attestation, age range, country of residence, and gender if you choose to provide it.
  • Why: Confirm age eligibility, support regional result views, apply country-specific product logic, improve demographic reporting, and help integrity / weighting controls where offered.
  • Required or optional: The 13+ attestation, age range, and country of residence are required to create and use an account. Gender is optional and can be skipped. Pluria does not require your full birth date for signup.
  • Public or private: The 13+ attestation stays private. Country, age range, and gender stay private unless you explicitly enable them on your public profile.
  • GDPR / legal basis: Contract and legitimate interests for age eligibility, regional functionality, and integrity reporting. Where local law treats a field as sensitive, optional collection depends on your explicit choice and is not required for account creation.

Notifications, contact, and support data

  • What: Push notification tokens, notification preferences, support emails, account-help requests, and public contact settings such as website or public email if you enable them.
  • Why: Deliver alerts you request, send account-related messages, respond to support cases, and let you control what contact details appear on your public profile.
  • Required or optional: Notification permissions and marketing-related notifications are optional. Support messages are optional, but we process them when you contact us.
  • Public or private: Support requests stay private. Public contact fields are only public if you turn them on.
  • GDPR / legal basis: Contract for account notices, consent for optional push permissions and certain marketing flows, and legitimate interests in support and service operations.

Purchases and billing data

  • What: Product identifier, subscription status, billed platform, purchase token or transaction references, restore attempts, management URL, account or page billing scope, and support records related to purchase issues.
  • Why: Validate Premium access, apply it to the correct person or page, restore eligible purchases, prevent fraud, respond to billing support, and meet tax, accounting, or dispute obligations where applicable.
  • Required or optional: Collected only if you start a purchase, restore a purchase, receive manual Premium support, or contact us about billing.
  • Public or private: Private. Billing and purchase records are not shown on public profiles or public pages.
  • GDPR / legal basis: Contract to provide the subscription you request, legitimate interests in fraud prevention and support, and legal obligations for financial records where required.

Device, diagnostics, analytics, and advertising data

  • What: Device and app identifiers, installation ID, IP / network signals, app version, crash / diagnostic logs, locale, coarse environment data, product interaction analytics, advertising identifiers where the platform makes them available, and limited ad-delivery or measurement signals shared with advertising providers when ads are enabled.
  • Why: Keep the app reliable, understand performance issues, reduce fraud, operate limited in-app or web advertising, measure ad delivery where enabled, and improve product quality.
  • Required or optional: Basic diagnostics and anti-abuse signals are generally required to operate the service. Optional analytics or advertising processing may depend on local consent requirements, platform controls, browser settings, or region-specific ad-choice prompts.
  • Public or private: Private. This data is not shown on your public profile.
  • GDPR / legal basis: Legitimate interests and contract for reliability, security, and measurement, plus consent where required for analytics or advertising.

Web storage, cookies, and browser state

  • What: Browser cookies for web sessions, session storage for temporary browser-approval state, local storage for visitor identifiers or saved browser choices, and third-party browser storage used by advertising providers when ads are enabled.
  • Why: Keep signed-in browser sessions secure, remember temporary web login state, support public-site measurement, remember ad choices, and deliver or measure ads where enabled.
  • Required or optional: Security and session cookies can be required for account-bound browser actions. Ad-related storage is optional and depends on your ad choice plus provider behavior.
  • Public or private: Private. Browser storage is not itself public, but it can affect how public pages are personalized or measured in that browser.
  • GDPR / legal basis: Contract and legitimate interests for secure sessions, plus consent or comparable user choice where required for optional advertising or measurement technologies.

What is public and what is not

Usually private

Sign-in credentials, 13+ eligibility attestation, phone number, verification media, support messages, internal moderation notes, device / anti-abuse signals, and export requests.

Can be public

Username, display name, avatar, website, social links, public creator identity, published content, and public result pages.

Conditionally visible

Country, age range, and gender on your public profile only if you enable them. Aggregate cohort views are suppressed when privacy thresholds are too low.

Identity verification and biometric review

If you start individual verification, Pluria asks for explicit consent before collecting a short front-camera clip, preview frame, challenge / timing telemetry, moderator decision data, and the consent version attached to the session.

We also keep a stable install identifier and related review signals so one verification session can be tied to one app install and one integrity review. Verification material is used for trust, fraud prevention, dispute handling, and moderator review. It is not used for advertising and is not published on your profile.

This feature is optional. If local law requires a higher threshold, we rely on explicit consent to start collection and then retain only what is needed for review, integrity, disputes, and legal obligations.

Permissions and optional features

  • Camera: Used only when you choose profile photos, poll media, or verification features.
  • Microphone: Used only when you record audio or video for poll or verification features.
  • Photos / media library: Used only when you upload media or choose to save exported result images.
  • Location: Used only when you choose location-based features such as regional results or nearby content.
  • Push notifications: Used only if you grant permission.

These permissions are optional at the device level. If you deny them, core account access can still work, but features that depend on those permissions may be unavailable.

Retention and deletion

Account deletion requests enter a 30-day recovery window before permanent deletion. During that window, your account is scheduled for deletion and public access is limited. Personal public content associated with the account is queued for permanent removal when deletion completes.

Some vote history, integrity records, and anti-abuse logs may remain in anonymized or aggregate form where needed to preserve poll integrity, prevent fraud, or maintain non-personal statistical history. Verification media, decision history, and install-binding records may also be retained while needed for moderation, fraud prevention, dispute handling, or legal obligations.

Billing support records, subscription-validation records, and limited financial or fraud evidence may also remain where necessary for refunds, disputes, compliance, or accounting obligations. Deleting your Pluria account does not by itself cancel an App Store or Google Play subscription.

If you need a verification-data deletion or consent-withdrawal review before deleting the full account, contact account@pluria.org.

For the full deletion flow, see Delete Account.

Service providers and third parties

Pluria relies on service providers for authentication, cloud hosting, data storage, crash reporting, billing validation, app-store subscription processing, messaging, customer support, moderation tooling, and advertising or measurement where ads are enabled.

Those providers process only the data needed for their role under their own terms, security controls, and where applicable our instructions. App Store and Google Play also process payment information directly when you buy or manage a subscription.

Your choices

  • Use in-app privacy controls to decide what appears publicly on your profile.
  • Request export, deletion, or other account help from the app or by email.
  • Link or unlink sign-in methods and optional contact details from account settings.
  • Withdraw from optional permissions at the device level.
  • Manage or cancel store subscriptions through Apple or Google.
  • Use the footer's Ad choices control on pluria.org public pages to revisit web ad consent.
  • Read the GDPR page for regional rights details and Billing and subscriptions for purchase help.

Contact

For privacy or account requests, contact account@pluria.org. For general support, use support@pluria.org.

Privacy Policy | Pluria