Privacy
Last updated: July 18, 2026
This policy explains how Plutus (“Plutus,” “we,” “us”) collects, uses, and protects information across this marketing site (plutus-cloud.com) and the Plutus product itself (console.plutus-cloud.com, the “Console”). If you’re a member of an organization using Plutus, your organization’s administrator controls your account, and this policy explains what we — not they — do with the data that passes through our systems. Plutus is operated by Chris Henderson, trading as Plutus, based in Scotland, United Kingdom. If you need a postal address, ask us at the email in “Contact us” below.
Account and identity information. When you sign up, we collect your name and email address. If you sign in with Google or GitHub, we receive your name, email, and a provider account identifier from that provider instead of storing a password. If you enable two-factor authentication, we store the security data needed to verify future sign-ins.
Billing information. Paid plans are billed through Stripe. We never see or store your card number — Stripe handles payment collection directly, and we store only your subscription status, plan, and billing dates.
Provider credentials you connect. To pull in your spend, you may connect third-party providers (for example, an AWS role, an Anthropic API key, or a Salesforce, GitHub, Slack, or Teams connection). These credentials are encrypted at rest (AES-256-GCM) and used only to sync the corresponding cost or event data — we don’t use them for anything else.
Cost, usage, and event data. This is the core of the product: spend data synced from your connected providers, data you push to us directly via our usage-ingestion API, and event data (like releases or client onboardings) from sources like GitHub and Salesforce. If you send us usage data about your own end customers, we process that data on your behalf as a service provider — it remains yours, and we don’t use it for any purpose beyond providing the service to you.
Support and communications. If you email us or contact support, we keep that correspondence. If a staff member accesses your account to help troubleshoot an issue, that access is logged.
Log and device data. Like most web services, our infrastructure logs standard technical data — IP address, browser/device information, timestamps, and request paths — for security, debugging, and abuse prevention.
Product usage analytics. Inside the Console, we use PostHog to understand how the product is used — this includes automatically captured interactions (clicks, page views, form submissions) and session recordings that replay what you did on screen, tied to your account so we can see usage patterns and debug issues. We use this to improve the product, not for advertising, and we don’t sell it. See “Cookies” below for how to opt out.
This marketing site specifically. We use Google Analytics on plutus-cloud.com to understand how visitors find and use the site — see “Cookies” below for details. We don’t run advertising trackers or sell this data. Page fonts are loaded from Google Fonts’ servers, which means your browser sends your IP address to Google when the page loads. The Console (console.plutus-cloud.com) sets a functional session cookie to keep you signed in, plus the PostHog analytics cookies described above — see “Cookies” below.
We do not sell your personal information. We do not use your account data or your cost/event data to train AI models. If you connect a third-party AI assistant (like Claude or ChatGPT) to our MCP server, that assistant queries your data directly, using a scoped key you create and control — we don’t send your data to any AI provider ourselves, and you can revoke that key at any time.
We share data with the service providers below to the extent needed to run Plutus. We don’t sell it, and we don’t share it for third-party advertising.
| Provider | What it handles |
|---|---|
| Neon | Managed Postgres — accounts, users, connections, billing records. |
| Hetzner | Application hosting and our self-hosted cost/usage data store. |
| Cloudflare | DNS, edge network, and DDoS/WAF protection in front of the Console. |
| Stripe | Payment processing and subscription billing. |
| Resend | Delivery of transactional and alert emails. |
| Google / GitHub | Sign-in, if you choose “Continue with Google/GitHub.” |
| Grafana Cloud | Infrastructure metrics and logs for our own servers. |
| Google Analytics | Traffic and usage analytics for the marketing site (plutus-cloud.com) only. |
| PostHog | Product usage analytics and session recordings inside the Console (console.plutus-cloud.com) only. |
If you configure your own alert destinations — a Slack workspace, a Microsoft Teams channel, a webhook URL, or extra email recipients — we send alert payloads to those destinations because you asked us to. We may also disclose information if required by law, or in connection with a merger, acquisition, or sale of assets, in which case we’ll make reasonable efforts to notify you first.
The Console uses a single essential session cookie to keep you signed in. It’shttpOnly (not readable by page scripts) and cannot be used to track you across other sites.
The Console also uses PostHog for product analytics, which sets cookies (prefixedph_) to tie your activity to your account. This includes automatically captured clicks, page views, and form submissions, and session recordings that replay what happened on your screen so we can debug issues and understand usage patterns. This data isn’t used for advertising, isn’t sold, and isn’t shared outside Plutus and PostHog. If you’d like your PostHog activity opted out or deleted, contact us using the details in “Contact us” below.
On the marketing site (plutus-cloud.com), we use Google Analytics to see which pages get visited and how people find the site. Google Analytics sets cookies (for example,_ga) in your browser to distinguish visitors and sessions. We don’t use this data for advertising, and we don’t combine it with account data from the Console. You can opt out using a browser extension like Google’sAnalytics opt-out add-on, or by blocking cookies from google-analytics.com andgoogletagmanager.com in your browser settings.
Separately from Google Analytics, this site records how you arrived — any campaign parameters in the link you followed (for exampleutm_source) and the domain that referred you — in your browser’s sessionStorage underplutus_attribution. That entry is cleared when you close the tab. If you then click through to the Console, those same parameters are appended to the link so we can tell which channels bring people to Plutus. It holds no identifier for you, no Google Analytics data, and nothing is sent to a third party; blocking site data in your browser settings switches it off.
Cost and event history is retained according to your plan — from 30 days on the Hobby tier up to three years on Enterprise. Account and profile information is retained for as long as your account is active, plus a reasonable period afterward for legal, tax, and fraud-prevention purposes. You can request deletion of your account and associated data at any time — see “Your rights” below.
Third-party provider credentials and alert-destination configs are encrypted at rest (AES-256-GCM). Traffic to and from the Console is encrypted in transit (TLS). Multi-factor authentication is available on every plan. Access to your account is restricted by role, and any staff access to your account for support purposes is logged. No system is perfectly secure, and we can’t guarantee absolute security, but we design and operate Plutus to industry-standard practices.
You can access, correct, export, or delete your account data, disconnect any provider, and turn MFA on or off at any time from your account settings. Depending on where you live, you may have additional statutory rights — for example, under the GDPR (EEA/UK) or the CCPA (California) — including the right to access, delete, correct, or port your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details below.
Plutus operates from Scotland, UK, and our application infrastructure is hosted in the EU (Germany). Some of the service providers listed above may process data in other countries, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers. [Confirm specific transfer mechanism per subprocessor with counsel before relying on this section.]
Plutus is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16.
We’ll update the “last updated” date above when we make changes, and we’ll make a reasonable effort to notify account administrators of material changes before they take effect.
Questions about this policy or your data? Email us atprivacy@plutus-cloud.com.