This policy explains how ConceptPlug (“we”, “us”) handles information when you use the website, API, WordPress plugin, and its tools (the “Service”). It must be reviewed with the final legal-entity, jurisdiction, and privacy-contact details before public sales are enabled.
1. Local features
Product management, local Product Health/SEO checks, templates, and local image utilities run on your WordPress server. These actions do not send product content to a ConceptPlug AI provider and do not require activation. Your WordPress host and any other plugins you use may process that data under their own policies.
2. Information we process
Account, activation, and security
- Email address, site URL, installation identifier, hashed activation credential, and verification state
- IP address and request/security signals used for rate limiting, fraud prevention, and incident investigation
- Credit balance, credit lots, operation records, consent choices, and marketing preference
Billing
When you buy credits, we process the selected pack, business name, consent record, payment status, amount, currency, Stripe identifiers, refunds, and disputes. Stripe collects and processes your card details; ConceptPlug does not receive your full card number.
Cloud AI data
Only after you explicitly confirm an AI action, we process the product brief, selected product fields, images, brand settings, language, and instructions needed for that action. Publishing a product or opening a local report does not start an AI request.
Optional pseudonymous telemetry
If you opt in to usage statistics, events are associated with pseudonymous account and installation identifiers. They are not anonymous. Telemetry may include feature names, counts, timings, success/error codes, numeric health scores, and software versions. It excludes product names, descriptions, images, prompts, payment-card data, and activation credentials. You may opt out at any time.
3. Why we process information
- Provide activation, AI jobs, result recovery, credits, and billing
- Prevent abuse, duplicate charging, fraud, and security incidents
- Reconcile payments, refunds, disputes, and the credit ledger
- Improve reliability using opt-in pseudonymous telemetry
- Send marketing only when you have opted in
4. Service providers
Depending on the action and configured route, the following providers process limited data on our behalf:
- OpenRouter routes supported AI requests. We use ConceptPlug’s own website as the HTTP referrer rather than your store URL.
- Google Gemini may directly process supported image-generation or image-edit requests.
- Stripe processes payments, refunds, and disputes.
- Resend processes email addresses and activation/service email content.
5. Retention
- AI image input is deleted after the job finishes; AI text payloads and retrievable results are retained for up to 7 days.
- Idempotency metadata and activation-attempt/security records are retained for up to 30 days.
- Opt-in telemetry is retained for up to 90 days before deletion or aggregation.
- Account data is retained while the account is active or while needed to provide requested export/deletion processing.
- Payment, refund, dispute, tax, and append-only credit-ledger records are retained for the period required by applicable legal and accounting obligations. The exact jurisdictional period must be approved before public sales.
6. Your choices and requests
- Use local features without creating a ConceptPlug cloud account
- Do not confirm an AI action if you do not want product data sent to AI providers
- Disable optional telemetry and marketing independently
- Request an account-data export or deletion; required financial records may be retained separately
A tested privacy contact address must be added here before public sales. Until then, production payments must remain disabled.
7. Security and international processing
We use HTTPS, hashed credentials, access controls, audit records, and retention jobs to protect information. Providers may process data in countries different from yours. No transmission or storage method is completely secure.
8. Children
The Service is intended for businesses and is not directed to children under 13.
9. Changes
Material changes will be posted here with a revised date. Where required, we will request renewed consent.