PlutusDoc Privacy Policy

Last updated: August 27, 2026

1. Scope and operator

NJ Media LLC, doing business as PlutusDoc, provides the PlutusDoc document creation, delivery, electronic-signature, scheduling, billing, and collaboration service. This policy explains how PlutusDoc handles personal information when people use the service, receive or sign a document, book a meeting, or contact us.

Organizations and account holders decide what content to upload, whom to invite, and which integrations to connect. They are responsible for having a lawful basis to provide recipient, signer, contact, and document information to PlutusDoc.

2. Information we collect

We collect information needed to operate the service and complete actions requested by users and recipients.

  • Account and Team data: name, email address, password credentials in protected form, profile details, Team membership, roles, settings, and support communications.
  • Document and contact data: documents, uploaded files, form fields, variables, contacts, recipient names and email addresses, delivery history, comments, approvals, reminders, and audit events.
  • Signing and booking data: signatures, initials, signing timestamps, signing certificates, recipient actions, booking details, attendee details, availability settings, and meeting links.
  • Billing data: plan, subscription, invoice, payment status, and Stripe identifiers. Payment-card details are collected and processed by Stripe rather than stored by PlutusDoc.
  • Integration data: Google account identifiers, OAuth tokens, Gmail delivery metadata, calendar settings, calendar event details, and contact data when a user connects and uses those features.
  • AI data: prompts, conversation context, selected document or workspace content, tool results, generated output, usage, and error status when a user invokes Plutus.
  • Operational and document analytics: request logs, security events, device and browser information, coarse network and country information, document opens, section engagement, link clicks, downloads, and session identifiers. PlutusDoc truncates stored IP addresses and reduces stored browser-version detail for document analytics.

3. How we use information

We use personal information to provide and secure accounts; create, store, send, sign, and audit documents; deliver email and reminders; run Team review and automation; process subscriptions; connect requested integrations; provide booking and calendar features; answer support requests; troubleshoot failures; and improve service reliability.

When a user asks Plutus to draft, summarize, analyze, or act on content, the relevant prompt and context are sent to the AI provider configured for the service. Users should review generated content before relying on or sending it.

We do not sell personal information or use document, recipient, or signing data for third-party advertising.

4. Processors and integrations

We disclose information only as needed to provide the service, comply with law, protect users and the service, or complete a transaction involving the business. Service providers process data under their own contractual and security obligations.

  • Hosting, database, and file-storage providers store application records and uploaded document assets.
  • Stripe processes checkout, subscriptions, payment methods, invoices, and billing events.
  • Resend delivers service and document email. Gmail may deliver document email when a user connects a Google email account.
  • Google processes connected Calendar, Contacts, Gmail, OAuth, and Google Meet requests chosen by the user.
  • The configured AI provider may be Vercel AI Gateway, DeepSeek, Anthropic, or OpenAI and receives the prompt and context needed for the requested AI operation. Google user data is handled as described in the Google user data section below.
  • Authorized Team members, document collaborators, recipients, signers, booking participants, and integration clients receive information according to the access and sharing choices made in the service.

5. Google user data

When a user connects a Google account, PlutusDoc requests only the Google data needed for the features that user chooses to use: basic account information (name, email address, and account identifier) to identify the connected account; Gmail send permission to deliver documents from the user’s own email address when the user selects Gmail delivery; Calendar free/busy and event permissions to show availability, avoid double-booking, and create calendar events and Google Meet links for confirmed bookings; and Contacts read permission so the user can pick recipients from their own address book.

PlutusDoc’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

PlutusDoc uses Google user data only to provide or improve the user-facing features described above. PlutusDoc does not use Google user data for advertising; does not sell Google user data; does not transfer Google user data to data brokers, advertising platforms, or credit or lending services; and does not use or transfer Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models. If a user explicitly asks the Plutus assistant to act on their calendar, only the information needed to complete that request is processed, solely on that user’s behalf. Humans do not read Google user data unless the user gives explicit permission, it is necessary for security or abuse investigation, it is required to comply with applicable law, or the data has been aggregated and de-identified.

A user can disconnect a Google integration at any time from PlutusDoc settings, which deletes the stored OAuth tokens, and can also revoke PlutusDoc’s access from their Google Account security settings at myaccount.google.com/permissions. Remaining Google-derived records are handled as described in the Retention and deletion section.

6. Retention and deletion

We retain account, Team, document, recipient, signature, booking, integration, analytics, and audit data while it is needed to provide the service and maintain the record requested by the account holder. OAuth credentials are retained until the connection is removed, expires, or is revoked.

Users may delete content through available product controls or request account or personal-data deletion at dev@plutusdoc.com. We will delete or de-identify information we are not required to retain, subject to identity verification, the rights of other parties to a signed record, fraud and security needs, legal obligations, billing and tax records, and limited backup retention. Recipients may also contact the sender, who controls the document and recipient record.

Account cancellation does not by itself require immediate deletion of signed documents, audit trails, billing records, or other records that must be preserved for users, recipients, dispute resolution, or law. Before closing an account, users should export records they need.

7. Security and international processing

We use administrative, technical, and organizational safeguards intended to protect information, including access controls, encrypted transport, protected credentials and integration tokens, and audit records. No online service can guarantee absolute security.

PlutusDoc and its providers may process information in countries other than the country where it was collected. Where required, we use appropriate contractual or legal mechanisms for international transfers.

8. Your choices and rights

Depending on location, a person may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where consent is the basis for processing. Contact dev@plutusdoc.com to make a request. We may need to verify identity and may direct a recipient request to the organization that sent the document.

Users can disconnect Google integrations, change notification settings, manage Team access, and control browser storage as described in the Cookies Policy. Transactional and security messages may continue while an account or active document workflow requires them.

9. Children, changes, and contact

PlutusDoc is a professional service and is not directed to children. We do not knowingly create accounts for children under 18.

We may update this policy when the service or legal requirements change. We will update the date above and provide additional notice when a material change requires it.

Questions, complaints, and privacy requests may be sent to NJ Media LLC at dev@plutusdoc.com.