BACK TO PLURA LEGAL · PRIVACY

Privacy Policy

Last updated: July 18, 2026

Plura is a bring-your-own-key (BYOK) AI client. It does not require a Plura account or a mandatory developer backend. Your keys, conversations, and settings are stored on your device. When you choose an external feature, Plura sends only the disclosed data from your device to the destination and operator identified in the consent notice, and only after you grant provider-specific permission in the app. If a destination is operated by the developer or Hucent Studio, the notice explicitly identifies that operator; otherwise the developer does not receive the transmitted data.

01Data the developer collects

Plura contains no analytics, advertising, telemetry, or third-party crash-reporting SDK. The developer does not automatically receive app traffic, API keys, conversations, or images. The only exception is when the consent notice names the developer or Hucent Studio as the operator of the configured destination. In that case, the destination receives the categories disclosed in Section 3 only to authenticate and perform the AI or search service you requested and to protect the service against security threats or abuse; the data is not sold, used for advertising, or used to track you. Apple may separately provide the developer with aggregated or diagnostic information when a user has chosen to share diagnostics with app developers in iOS; that sharing is controlled by the user's Apple settings. Our marketing website (plura.hucentstudio.app) sets no tracking or advertising cookies and uses local storage only to remember theme and language; like any website, its hosting provider may keep standard server logs such as IP addresses for security and operation.

02Data stored on your device

Everything Plura creates is stored locally on your device unless you choose an external feature and authorize the disclosed transmission described in Section 3:

Deleting the app removes its database and image container. iOS Keychain items may remain after an uninstall, but Plura cannot restore or use them after its local provider records are removed. To avoid inaccessible credential remnants, delete each AI provider and use “Delete Key” for web search in Settings before uninstalling.

03Data you may choose to send

Plura handles content when you type or paste it, select a photo, dictate text, configure instructions, or enable a feature that derives information locally from your conversations. Depending on the feature, a request to an external AI or search provider may contain:

Cloud AI and search requests are sent directly from your device to the configured destination shown in the consent notice, using that destination's API transport. The notice identifies the actual receiving operator, including when a destination is operated by the developer or Hucent Studio. Plura uses the data only to perform the feature you requested: authenticate the request, generate or analyze content, return an AI response, search the web, create a title or summary, extract an enabled memory, or create an embedding. The on-device Apple model does not send chat content to a third-party AI provider.

Automatic titles, memory extraction, summarization, and embeddings may use a compatible provider that differs from the model selected for the current chat. Plura will not make such an external call unless that receiving provider is authorized. Cross-chat search/RAG and memory are off by default and can be turned off in Settings.

04Permission before sharing

Before Plura sends data to a third-party AI or search provider for the first time, it shows “Share Data with Third-Party AI?” Each recipient has a separate card identifying the receiving operator or service, destination base URL, identity or control relationship, available privacy-policy link, the purpose and data involved in the current request, and the additional categories and supported uses that may apply only when a later user action triggers those features. The notice offers “Don’t Send” and “Allow & Send.” No AI or search API request containing the disclosed data or a credential is transmitted unless you affirmatively choose “Allow & Send.” Permission covers only the scope displayed for that recipient and is stored separately per provider. Selecting a new provider, changing its destination, operator, policy, control relationship, or materially changing the disclosure requires a new decision.

You can review or revoke one provider's permission—or revoke all permissions—at any time in Settings → Privacy → AI Data Sharing Permissions. Revocation blocks future transmissions to that provider, including utility calls triggered by related user actions. You can also remove its API key. Revocation does not retrieve data already delivered to a provider; use that provider's account or privacy controls for previously received data.

05Recipients and equivalent protection

The recipient is the service you configure and authorize. Supported recipients include OpenAI, Anthropic (Claude), Google (Gemini), DeepSeek, an OpenAI-compatible endpoint or local Ollama service you specify, and optional search services Tavily, Brave Search, or Serper. Plura recognizes the exact official API hosts for the named built-in providers and displays the operator and privacy-policy link. Localhost and private-network destinations are identified as services controlled by you. We do not sell this data or disclose it to advertisers or data brokers.

Any third-party provider that receives personal data through Plura must handle it under privacy and security protections that are the same as or equivalent to this policy, including purpose limitation, reasonable security, and retention/deletion controls. A public custom endpoint is blocked unless it uses HTTPS and you provide the actual receiving operator. You must identify whether it is managed by you or your organization or is a third-party relay. For a third-party relay, you must also provide its public HTTPS privacy-policy URL and expressly confirm that you reviewed the operator and policy and that the service provides the same or equivalent protection. Plura displays this supplied identity, relationship, destination, and policy before permission is requested. Changing any of them invalidates the prior permission. If we learn that a supported recipient no longer provides equivalent protection, we will stop enabling transmission to it until the issue is addressed.

06Third-party retention and deletion

Plura's local copy of your API keys, conversations, memories, images, provider settings, and consent decisions remains on your device until you delete it. Deleting a message or conversation removes image files in Plura that are no longer referenced elsewhere; incognito-chat images and unsent images are removed when discarded. If the process is force-quit before that cleanup runs, unreferenced image files are removed on the next launch. A copy you explicitly save to the Photos library is managed by iOS Photos and is not removed when you delete the image from Plura. You can delete a provider and its AI key, delete the saved key for each search service, or revoke either permission. Deleting the app removes its database and image container, while Keychain credentials may persist as explained above. A receiving provider—including Hucent Studio when it is named as the destination operator—may retain data it already received according to the destination's privacy policy, account configuration, and security requirements. A Hucent Studio-operated destination uses received content and credentials only to fulfill the requested API service and for security or abuse prevention, not for advertising, tracking, or sale. Plura cannot delete data from a provider's systems; use that provider's deletion controls or contact support@hucentstudio.app for a Hucent Studio-operated destination. Removing local data or revoking permission affects future transmissions but does not automatically erase a recipient's existing copy.

07Voice

If you use dictation, Plura configures Apple's Speech framework to require on-device recognition. If on-device recognition is unavailable for the current device or language, dictation fails locally instead of falling back to server recognition. The resulting transcript is treated like text you typed and is not sent to a third-party AI provider without the permission described above. Read-aloud uses Apple's speech synthesis. Plura does not retain audio recordings.

08Photos

If you attach an image, you choose it through the system photo picker. Plura sends that image only when you request a feature that needs it and authorize the displayed provider. If you save a generated image, Plura writes it to your photo library with the system's permission. Plura does not scan your photo library.

09Fees

Plura 1.0 is a free app and contains no in-app purchases. AI and search usage costs are billed directly to you by the providers you choose under your own accounts and keys; those charges are not processed by us.

10Children

Plura is not directed to children and does not knowingly collect information from children. Because Plura can connect to third-party AI services, users must also meet each chosen provider's age requirements.

11Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected here with an updated date. If a change materially affects what data is shared or who receives it, Plura will request permission again before the new sharing occurs.

12Contact

Questions about this policy, a provider, or a privacy request? Contact: support@hucentstudio.app.

Plura is developed by Chengkang Liang (hucentstudio). Bundle ID: app.hucentstudio.plura.