Privacy Policy
Last updated: March 14, 2026
Introduction
Promoat Holdings LLC ("we," "us," or "our") operates The Plug HQ (theplughq.com and app.theplughq.com). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. Please read this policy carefully. By using The Plug HQ, you agree to the collection and use of information in accordance with this policy.
Information We Collect
We collect information you provide directly to us, including:
Account Information: When you create an account, we collect your name, email address, and password (stored in hashed form). If you join a workspace via invitation, we collect the same information.
Business Information: To personalize your experience, we collect your business description, brand name, website URL, target audience, brand voice, and related business profile information that you provide in Settings.
API Keys: If you choose to bring your own AI provider API key (Anthropic, OpenAI, or Google), we store it securely and use it solely to make AI requests on your behalf. We never share your API keys with third parties.
Content You Create: We store content generated through the platform, including articles, social posts, resources, and other materials, within your workspace.
Usage Data: We automatically collect information about how you interact with the platform, including pages visited, features used, and timestamps. We also track AI token usage for platform management purposes.
How We Use Your Information
We use the information we collect to:
Provide, maintain, and improve The Plug HQ and its features, including trend scanning, content generation, resource creation, and engagement recommendations.
Personalize your experience by tailoring trends, content, and recommendations to your business and niche.
Send you transactional emails (account verification, password resets, workspace invitations, daily briefings, and notification emails you have opted into).
Monitor and analyze usage patterns to improve our platform.
Protect against unauthorized access and ensure the security of our platform.
Third-Party Services
We use the following third-party services to operate The Plug HQ:
AI Providers (Anthropic, OpenAI, Google): We send your business context and prompts to these providers to generate content, analyze trends, and power AI features. These providers process data according to their own privacy policies and API terms.
Vercel: Our platform is hosted on Vercel. Vercel may collect standard server logs.
Neon: Our database is hosted on Neon (serverless Postgres). Your data is stored securely on their infrastructure.
Resend: We use Resend to send transactional emails. Your email address is shared with Resend for this purpose.
Google reCAPTCHA: We use Google reCAPTCHA v3 to protect against automated abuse during login and signup.
Upstash Redis: We use Upstash for caching to improve platform performance. Cached data does not include raw API keys or passwords.
Data Retention
We retain your account information and workspace data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where we are required to retain it for legal or compliance purposes. Generated content and resources within your workspace are retained until you delete them or your account is closed.
Data Security
We implement appropriate technical and organizational measures to protect your personal information. Passwords are hashed using bcrypt. Sessions are managed via secure, httpOnly JWT cookies. API keys are stored securely and masked in user-facing displays. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
The right to access, update, or delete your personal information.
The right to object to or restrict certain processing of your data.
The right to data portability.
To exercise any of these rights, please contact us at dapo@promoat.co.
Cookies
We use a session cookie (httpOnly) to keep you logged in. We also use localStorage to store your theme preference. We do not use advertising or tracking cookies. Google reCAPTCHA may set its own cookies as part of its fraud prevention functionality.
Children's Privacy
The Plug HQ is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of The Plug HQ after any changes constitutes your acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, please contact us at:
Promoat Holdings LLC
Email: dapo@promoat.co
Website: theplughq.com