This Privacy Policy explains how PlugKit (“PlugKit”, “we”, “us”, or “our”) collects, uses, stores, shares, and deletes personal data when you use our website, API, SDKs, dashboard, and MCP server (together, the “Services”). It also explains how we handle data we access from connected platforms — including Meta (Facebook, Instagram, Messenger, Threads, and WhatsApp), X, LinkedIn, TikTok, YouTube, Pinterest, Reddit, and others — on behalf of our customers.
In short: PlugKit is infrastructure that lets developers and their AI agents connect social and messaging accounts through official OAuth flows and act on them through a single API. We process Platform Data only to provide those features, we never sell it, and you can disconnect an account or delete your data at any time. See Section 9 — Your Rights & Data Deletion.
PlugKit provides a unified API that allows developers — and the AI agents they build — to publish content, read and reply to messages, and receive events across multiple social and messaging platforms through a single integration.
For personal data relating to our own account holders (for example, the developer or organization that signs up for PlugKit), PlugKit acts as a data controller. For Platform Data and end-user content that our customers process through the Services, PlugKit acts as a data processor acting on the customer’s instructions (see Section 2).
This policy applies to two kinds of people:
Where PlugKit processes end-user Platform Data on behalf of a customer, the customer is the controller and is responsible for having a lawful basis and a privacy notice covering that processing. PlugKit processes such data only to provide the Services and according to our agreement with the customer.
When you connect an account, you direct PlugKit to access only the data covered by the permissions you grant. Depending on the platform and scopes, this may include:
Some integrations rely on platforms governed by their own developer terms — including the Meta Platform Terms and Developer Policies. Where we access data from Meta technologies (Facebook, Instagram, Messenger, Threads, WhatsApp) we additionally commit to the following:
If any term of this policy conflicts with a platform’s developer terms regarding that platform’s data, the stricter requirement that protects the individual applies to that data.
PlugKit’s YouTube integration uses YouTube API Services. By connecting a YouTube channel to PlugKit you are also agreeing to the YouTube Terms of Service, and Google’s handling of your information is described in the Google Privacy Policy.
youtube.readonly, to identify the channel you are connecting, read the status of its videos and read the comments they receive; youtube.upload, to upload videos to that channel on your instruction; and youtube.force-ssl, to post the replies you write to comments on your videos and to hide or remove comments when you ask PlugKit to. We do not request access to your Gmail, Drive, Contacts, or any other Google product.| Purpose | Example |
|---|---|
| Provide the Services | Authenticate accounts, store and refresh tokens, publish content, read/reply to messages, deliver webhooks. |
| Operate & secure the platform | Rate limiting, fraud and abuse prevention, debugging, maintaining uptime. |
| Support | Respond to your requests and troubleshoot integration issues. |
| Billing | Process subscriptions and usage-based charges. |
| Improve the product | Aggregated, de-identified usage analytics. We do not train models on your customers’ private messages or content without your explicit instruction. |
| Legal & compliance | Meet legal obligations and enforce our terms. |
Where the GDPR applies, we rely on the following legal bases:
For end-user Platform Data processed on a customer’s behalf, the customer is responsible for establishing the applicable legal basis.
We do not sell personal data. We share data only with:
Subject to applicable law (including the GDPR and the California Consumer Privacy Act), you may request to access, correct, export, restrict, or delete your personal data, and object to certain processing. You may also withdraw consent and lodge a complaint with a supervisory authority.
You can revoke PlugKit’s access at any time from your PlugKit dashboard (Settings → Connections → Disconnect), or from the platform’s own app settings (for Meta: Settings & Privacy → Settings → Business integrations / Apps and Websites). Disconnecting revokes the stored tokens and deletes the associated Platform Data.
To delete your account and all associated personal data, email contact@plugkit.co from your account address, or use Settings → Delete account in the dashboard. We will verify the request and complete deletion within 30 days, except for data we must retain by law.
If you have used PlugKit through a Meta (Facebook/Instagram) login and want the data we processed from that account deleted, you can:
Upon receiving a valid request we delete the corresponding tokens and Platform Data and confirm completion by email, typically within 30 days. We do not charge for these requests.
PlugKit is operated from the United States, and our sub-processors may process data in the United States and other countries. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and additional technical measures.
No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected users and authorities of incidents as required by law.
Our marketing site uses only essential cookies needed to load the page and, where you consent, privacy-respecting analytics to understand aggregate traffic. To improve the site, we also record browsing sessions on our marketing pages (pages viewed, clicks, scrolling) and combine them into heatmaps, using PostHog hosted in the European Union. Text typed into form fields is masked and never recorded. The PlugKit dashboard uses strictly necessary cookies to keep you signed in. Our live-chat widget stores an identifier in your browser so a conversation you start stays yours across page loads and visits; it is set only once the chat loads, and clearing your browser storage ends that session. You can control non-essential cookies through your browser or our consent banner where shown.
To measure which signup buttons lead to an account, we retain the selected button in browser local storage for up to 24 hours and send that source with the signup event to DataFast. This records whether signup followed the onboarding pop-up, pricing section, or another landing-page button; it does not record text entered into forms or reserve an onboarding call.
The Services are intended for businesses and developers and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy to reflect changes to the Services or the law. We will revise the “Last updated” date above and, for material changes, provide additional notice (for example, by email or an in-product notice). Your continued use of the Services after an update constitutes acceptance of the revised policy.
For privacy questions, data requests, or to reach our data protection contact: