Privacy Policy

Last updated: May 12, 2026

This Privacy Policy describes how PluginMaker (pluginmaker.ai) collects, uses, and protects your personal information.

1. Information We Collect

Account Information

When you create an account, we collect your email address, name, and profile picture (if you sign in with Google).

Plugin Data

We store the plugins you create, including DSP code, UI blueprints, presets, and generated screenshots. This data is associated with your account.

Payment Information

Payment processing is handled by Stripe. We do not store credit card numbers or bank account details. When you use the marketplace, Stripe processes and stores payment data according to their Privacy Policy.

Marketplace Data

If you sell plugins, we store your seller profile (display name, bio) and transaction history (sales, earnings). If you buy plugins, we store your purchase history.

Usage Data

We collect usage data including page views, feature usage, and error reports to improve the platform. When you are logged in, this data is linked to your account. We use PostHog for analytics.

Native Plugin Telemetry (Opt-In, Default Off)

The PluginMaker installer and every plugin you install through it can optionally send anonymous diagnostic data from your machine to help us identify crashes, freezes, and performance issues. This is off by default. The first time you open the PluginMaker installer, you are shown a consent dialog with two buttons (“Share crash + diagnostic data” or “No thanks”). No data is transmitted until you click one. Your choice applies to the installer itself and to every PluginMaker plugin running on your machine — one decision, one record, no per-plugin re-prompting. This consent is separate from any other consent on the pluginmaker.ai website.

When enabled, we collect:

  • Symbolicated crash and hang stack traces
  • Plugin ID, plugin version, host application name and version, operating system and build, sample rate, buffer size, channel layout
  • Audio-thread performance counters: load percentage histograms, xrun count, NaN/Inf detection count, denormal flush rate, instance count
  • Environmental fingerprint: WebView runtime version, audio driver name and version, GPU vendor and driver version, CPU model and instruction-set flags, display DPI scaling, monitor count, coarse locale (country code only), and the names of antivirus or endpoint-protection products injected into the host (matched against a fixed published allowlist — we do not enumerate every loaded library on your machine)
  • Last 30 seconds of audio-thread events leading up to a crash or hang: parameter change identifiers and numeric values, edge-triggered NaN/silence detections, processing-stage timing

We never collect, from the plugin:

  • Audio buffers, MIDI streams, or any sample content
  • Project file paths, project names, or session content
  • Preset names you have typed
  • Your operating system username, hostname, IP address, MAC address, disk serial, or machine UUID
  • License keys, account information, or payment data

Lawful basis: your explicit consent under GDPR Article 6(1)(a) and the ePrivacy Directive Article 5(3). You can revoke this consent at any time from the PluginMaker installer’s Settings panel (toggle “Share crash + diagnostic data”), or by deleting the file telemetry_consent.json from the PluginMaker user-data folder (%APPDATA%\PluginMaker\ on Windows, ~/Library/Application Support/PluginMaker/ on macOS). Revocation takes effect immediately in the installer; plugins already running pick it up on next launch.

Native plugin telemetry is stored on servers operated by Sentry GmbH in Frankfurt, Germany (EU region) for 90 days, after which raw events are deleted automatically. Aggregated statistics derived from this data may be retained longer for product improvement but are no longer attributable to any specific install or user.

2. How We Use Your Information

  • To provide and maintain the platform
  • To process marketplace transactions
  • To send important account notifications
  • To improve the platform based on usage patterns
  • To prevent fraud and abuse

3. Data Sharing

We share your data with the following third-party services. Some of these services are based in the US, which means your data may be transferred outside the EU/EEA.

  • Google (US) — authentication via Google Sign-In. Receives your email, name, and profile picture when you log in with Google
  • Stripe (US) — payment processing and seller payouts. Receives your name, email, and payment information
  • Anthropic / OpenAI (US) — your plugin descriptions and prompts are sent to AI providers for generation
  • Cloudflare R2 (US) — stores plugin files and assets linked to your account
  • PostHog (EU) — analytics. Collects usage data linked to your account when you are logged in. Only active if you accept analytics cookies
  • Langfuse (EU) — observability. Logs AI generation requests and responses to monitor and improve the platform
  • Sentry GmbH (EU — Frankfurt, Germany) — native plugin crash and performance telemetry. Only active if you opt in via the in-plugin consent banner. Receives the anonymous diagnostic data described under “Native Plugin Telemetry” above; never receives audio, MIDI, project content, file paths, or personal identifiers
  • Vercel (US) — hosts the frontend application
  • Hetzner / OVH (Germany/EU) — server infrastructure hosting the backend, database, and monitoring services
  • Neon (US) — managed database hosting for account and plugin data

We do not sell your personal data to third parties. Marketplace seller display names are publicly visible on plugin listings.

4. Data Retention

We retain your account data and plugins as long as your account is active. You can request deletion of your account and associated data at any time by contacting us.

5. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to processing of your data
  • Withdraw consent at any time

To exercise these rights, contact us at dominik@pluginmaker.ai.

6. Cookies

We use essential cookies for authentication and session management. We use PostHog for analytics which may set tracking cookies. Stripe may set cookies during the checkout process.

7. Security

We use industry-standard security measures including HTTPS, encrypted database connections, and secure authentication. However, no system is 100% secure.

8. Children

PluginMaker is not intended for children under 18. We do not knowingly collect data from minors.

9. Changes

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the platform.

10. Contact

Email: dominik@pluginmaker.ai / maks@pluginmaker.ai