legal

privacy policy

last updated: september 2026

This policy describes what personal data pluto collects, the purposes and legal bases for processing it, how long it is kept, with whom it is shared, and the rights available to you. The data controller is the operator trading as “pluto”; full controller particulars required by applicable law are provided at checkout and on your receipt. References to “we” mean the controller. All privacy contact runs exclusively through tickets in the pluto Discord at https://discord.pluto.lgbt; there is no email, postal, or telephone privacy contact.

1. data we collect

What we do not collect: no advertising trackers, no analytics SDKs, no sale of personal data. The marketing site sets no cookies, runs no fingerprinting, and stores nothing on your device beyond what your browser ordinarily caches.

2. purposes and lawful bases (GDPR Art. 6)

Where your jurisdiction does not use GDPR terminology, equivalent concepts apply: we process your data to perform our contract with you, to protect the service against fraud and abuse, with your consent where required, and to comply with the law.

3. hardware identity, specifically

The launcher reads stable machine identifiers (per OS: OS install id, board serial, CPU id, system UUID, and never browsing history, files, keystrokes, or content) and they are hashed server-side with a secret salt before storage. Matching a second machine requires at least 3 of 4 components to agree, so a disk or RAM swap does not lock you out. Binding occurs on first login; self-service resets open weekly. This processing is necessary to enforce the one-machine license and is retained under contract and legitimate interests as described above.

4. retention

On account deletion we erase or anonymize data without undue delay except where retention is required or permitted under this section (for example tax records, or hashes strictly necessary to defend against fraud or establish legal claims).

5. sharing and disclosure

Processors under contract only: dedicated hosting infrastructure in Germany (EU/EEA), payment processing, and community tooling (Discord) where you contact us. Processors act solely on our documented instructions and are bound to confidentiality, purpose limitation, and appropriate security. We do not sell personal data, share it with advertising partners, or supply it to data brokers. We disclose data to third parties only: (a) to processors as described; (b) where required by valid, binding legal process or applicable law, after assessing validity and scope and notifying you unless prohibited; (c) to establish, exercise, or defend legal claims, including against fraud, chargeback abuse, redistribution, or infringement; or (d) in connection with a merger, acquisition, or asset sale, subject to continued protection under this policy and applicable law.

6. your rights

Under the GDPR/UK GDPR, and to the extent applicable equivalent rights under laws including the CCPA/CPRA (California), PIPEDA (Canada), the Privacy Act 1988 (Australia), and comparable regimes, you may request access to, correction of, portability of, restriction of, and erasure of your personal data, and may object to processing based on legitimate interests or withdraw consent at any time with prospective effect. To exercise any right, open a ticket in the Discord from the account or contact point associated with the data; we verify identity proportionate to the sensitivity of the request and respond within one month (extendable by two months for complex requests, with notice). Erasure of data necessary to an active license ends the license; hashes strictly necessary to defend against fraud or to establish legal claims may be retained where the law permits. Automated decisions with legal or similarly significant effect are not applied to accounts; enforcement actions involve human review on request. You may lodge a complaint with your supervisory authority (your national data protection authority, the IMY in Sweden or the ICO in the UK); we ask that you contact us first so we can resolve the matter.

7. international transfers

Infrastructure currently operates in Germany, with a planned relocation to Sweden; both are inside the EEA, so routine operation involves no third-country transfer. Where personal data leaves the EEA, UK, or a jurisdiction requiring equivalent protection, transfers occur only with an appropriate safeguard, whether an adequacy decision, standard contractual clauses, or another lawful mechanism, documented and available on request via a Discord ticket, subject to redaction of security-sensitive detail.

8. security and breach notification

TLS 1.3 in transit; salted slow hashes at rest (passwords and hardware identifiers are never stored raw); short-lived access tokens with rotating refresh; per-release encrypted artifacts; OS-keychain session storage on your device; least-privilege access among staff. No system is perfect. If we discover a personal-data breach likely to result in risk to your rights, we notify the competent supervisory authority within 72 hours of awareness where required, and notify affected users without undue delay where the risk is high, via the Discord and your account contact point. Suspected issues may be reported through a Discord ticket at any time.

9. children

pluto is not directed at children and purchase requires 18+. Account holders under 16 must have a parent or guardian hold the account and consent on their behalf. We delete accounts we learn are held by under-13s (or below the applicable minimum age in your jurisdiction), together with associated personal data except where retention is legally required.

10. data on your device; cookies

The launcher stores a session token in your OS keychain (or a locked-file fallback), cached manifests, and the verified build while installed. Clearing the application data removes them; the server-side copies expire or can be revoked as described above. The marketing site uses no cookies, no local storage beyond normal browser caching, and no cross-site tracking.

12. captcha

Account creation, login under attack, and password resets are guarded by pluto captcha: a memory-hard proof of work solved in your browser plus counts of ordinary interaction (pointer samples, key presses, their duration). It collects no content, no coordinates, no keys, and nothing biometric. Challenges expire within minutes, interaction records are evaluated in memory and never stored, and solved challenges are single-use. The legal bases are contract and our legitimate interest in preventing automated abuse, as described in section 2.

13. changes

Material changes are announced in the Discord at least 7 days before taking effect; continued use after the effective date constitutes acceptance. Where the law requires fresh consent for a new purpose, we obtain it before processing for that purpose.