Privacy Policy

Last updated: July 21, 2026

This Privacy Policy describes how PluginMaker (pluginmaker.ai) collects, uses, and protects your personal information.

1. Information We Collect

Account Information

When you create an account, we collect your email address, name, and profile picture (if you sign in with Google).

Plugin Data

We store the plugins you create, including DSP code, UI blueprints, presets, and generated screenshots. This data is associated with your account.

Payment Information

Payment processing is handled by Stripe. We do not store credit card numbers or bank account details. When you use the marketplace, Stripe processes and stores payment data according to their Privacy Policy.

Marketplace Data

If you sell plugins, we store your seller profile (display name, bio) and transaction history (sales, earnings). If you buy plugins, we store your purchase history.

Usage Data

We collect usage data including page views, feature usage, and error reports to improve the platform. When you are logged in, this data is linked to your account. We use PostHog for analytics.

Installer and Native Plugin Diagnostics (Opt-In, Default Off)

A PluginMaker-branded installer, or a white-label installer powered byPluginMaker, and every plugin you install through it can optionally send diagnostic data from your machine to help us identify crashes and installer failures. PluginMaker determines the purposes and fields, receives the data, and is the data controller for this diagnostic service. The customer brand does not receive this diagnostic data. This data is not described as anonymous because a native crash report can contain technical details that may be personal data. This is off by default. The first time you open the installer, you are shown a consent dialog with two buttons (“Share crash + diagnostic data” or “No thanks”). No data is transmitted until you click one. Your choice applies to that branded installer and the plugins installed through it — one decision, one record, no per-plugin re-prompting. This consent is separate from any other consent on the pluginmaker.ai website and from a decision made in another branded installer.

When enabled, we may collect:

  • Installer event name, success or failure, duration, installer version, operating system, CPU architecture, and a plugin identifier where needed to diagnose an installation
  • For a failed Windows install or uninstall: failure category, random diagnostic ID, Windows error codes, retry count, lock-owner count, and the executable and application names (basenames only) of processes holding the affected plugin file
  • For native plugin crashes: event time, plugin ID/type/version and brand, host-process or DAW name, OS/build, CPU architecture and device model, exception information, register values, thread names, stack frames, module basenames, and debug identifiers used for symbolication
  • On Windows, the raw native minidump required for symbolication. A minidump can contain process/module details and module file paths; those paths may contain an operating-system account-folder name.

We do not intentionally collect through this diagnostic feature:

  • Audio buffers, MIDI streams, or any sample content
  • Project content or preset names you have typed
  • License keys, payment data, authentication tokens, command lines, MAC addresses, disk serials, or machine UUIDs
  • Account IDs, operating-system usernames/hostnames, full file paths, or process IDs in installer diagnostic events. The client removes these fields and redacts paths, email addresses, IP literals, and token-like values before sending those events.

Our infrastructure and diagnostic providers necessarily process the network IP address used to deliver and protect a request. We do not add it to the installer diagnostic payload or use it as an installer identifier. As explained above, native Windows crash data can still contain module paths with an account-folder name.

Lawful basis: your explicit consent under GDPR Article 6(1)(a) and the ePrivacy Directive Article 5(3). You can revoke this consent at any time from the installer’s Settings panel (toggle “Share crash + diagnostic data”), or by deleting its telemetry_consent.json file. The flagship installer stores that file in the PluginMaker user-data folder (%APPDATA%\PluginMaker\ on Windows, ~/Library/Application Support/PluginMaker/ on macOS). A white-label installer uses the same locations under its own displayed product name. Revocation takes effect immediately in the installer; plugins already running pick it up on next launch.

Structured installer diagnostic logs are retained for 30 days. Native crash events are stored by Sentry GmbH in its EU region for the retention period configured for our project, no longer than 90 days. Aggregated operational counters may be retained longer when they no longer contain event-level diagnostic details.

2. How We Use Your Information

  • To provide and maintain the platform
  • To process marketplace transactions
  • To send important account notifications
  • To improve the platform based on usage patterns
  • To prevent fraud and abuse

3. Data Sharing

We share your data with the following third-party services. Some of these services are based in the US, which means your data may be transferred outside the EU/EEA.

  • Google (US) — authentication via Google Sign-In. Receives your email, name, and profile picture when you log in with Google
  • Stripe (US) — payment processing and seller payouts. Receives your name, email, and payment information
  • Anthropic / OpenAI (US) — your plugin descriptions and prompts are sent to AI providers for generation
  • Cloudflare R2 (US) — stores plugin files and assets linked to your account
  • PostHog (EU) — analytics. Collects usage data linked to your account when you are logged in. Only active if you accept analytics cookies
  • Langfuse (EU) — observability. Logs AI generation requests and responses to monitor and improve the platform
  • Sentry GmbH (EU — Frankfurt, Germany) — installer and native plugin crash diagnostics. Only active if you opt in through the installer. Receives the crash data described under “Installer and Native Plugin Diagnostics” above. Native Windows minidumps can include module paths and process details; installer events are redacted and bounded before transmission
  • Vercel (US) — hosts the frontend application
  • Hetzner / OVH (Germany/EU) — server infrastructure hosting the backend, database, monitoring services, and structured installer diagnostic logs
  • Neon (US) — managed database hosting for account and plugin data

We do not sell your personal data to third parties. Marketplace seller display names are publicly visible on plugin listings.

4. Data Retention

We retain your account data and plugins as long as your account is active. You can request deletion of your account and associated data at any time by contacting us.

5. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to processing of your data
  • Withdraw consent at any time

To exercise these rights, contact us at dominik@pluginmaker.ai.

6. Cookies

We use essential cookies for authentication and session management. We use PostHog for analytics which may set tracking cookies. Stripe may set cookies during the checkout process.

7. Security

We use industry-standard security measures including HTTPS, encrypted database connections, and secure authentication. However, no system is 100% secure.

8. Children

PluginMaker is not intended for children under 18. We do not knowingly collect data from minors.

9. Changes

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the platform.

10. Contact

Email: dominik@pluginmaker.ai / maks@pluginmaker.ai