Privacy Policy

Last Updated:

Last updated: 14 September 2026

Pluck is a daily texting game. You practise conversations with characters played by an AI, and a coach marks what you sent. This policy explains what we collect, why, who else sees it, and how to get rid of it.

Pluck is operated by Tony Chow (“we”, “us”). Contact: [email protected].

1. The short version

  • You sign in with Apple. We never receive or store your name or email address for your account — only Apple's per-app identifier.

  • We do store the conversations you practise, because the coach has to read them to mark them, and because you can look back at a past round.

  • Your messages are sent to Anthropic to generate the character's replies and the coaching. They are not used to train anyone's model.

  • We use no advertising, no third-party analytics and no trackers. There is no advertising identifier in the app.

  • Deleting your account really deletes it, including every stored conversation and the anonymous counters belonging to the device you delete from, in one action from inside the app (§7).

  • Pluck is 18+.

2. Who this covers

This policy covers the Pluck app and the Pluck website. If you only join the waitlist on the website, the only thing we hold is your email address (§3.6).

3. What we collect

3.1 Account

When you sign in with Apple we store an opaque identifier Apple gives us for you (the “per-app subject”), our own internal id, and the dates you signed up and last opened the app. We do not ask Apple for your name or email, and we do not store them. If you use Apple's Hide My Email, nothing changes for us, because we were not using an email address anyway.

3.2 Your practice conversations

When you play a round we store the transcript — the messages you wrote, the character's replies, and the marks the coach gave each message — together with the round's state: which character and objective, the turn count, the engagement curve, and any safety flags. We store this because the coach must read the round to grade it, because your rating is computed from it, and so you can revisit a past round.

We also store the reads you tap during a round — whether you judged the other person to be leaning in, holding steady or cooling — alongside the answer the grader had, and the optional one-line "why?" if you wrote one. We keep these to check the grader against real players and improve it. They are stored with the round and are deleted when the round or the account is deleted.

Write as if a human might read it. We can read stored conversations when we have to: to investigate a content report, to fix a bug you tell us about, or where the law requires it. We do not read them routinely.

3.3 Scenarios you write

If you create your own scenario, we store the setup and opening line you wrote. It is private to your account.

3.4 App usage

Two things, both keyed to a random identifier generated on your device and neither linked to your account:

A daily open count. One row per install per day that the app was opened. It tells us how many people come back on day 1, day 3 and day 7.

A practice funnel. A small, fixed set of events recording which step of a round you reached and where you stopped: that the home screen was seen, that a round started and how it ended, that a message was sent, that the coach's breakdown was opened, that a retry was started, that a round was abandoned. Eleven event names in total.

We are specific about what an event may carry, because it is enforced in code rather than promised in a policy. Each event may only carry properties from a written allowlist, and every value must be a true/false, a whole number, or one of a short list of fixed words — for example the round's outcome, or which screen you started from. There is no free-text property, and there is no way for a message you wrote to end up in this store. The closest thing to content is the length of a message in characters, which we keep because "the message that ended it was four characters long" is a useful finding and a length cannot be turned back into a sentence.

Anything the app sends that is not on that allowlist is discarded by our server before it is written, including the event name itself.

3.5 Content reports

If you report something a character said, we store the report, what was shown, and enough context to review it.

3.6 Waitlist (website)

If you enter your email address on the Pluck website we store that address, a tag saying which part of the page you used, and the date. Your IP address is used in memory to rate-limit signups and is not written to our database. We will send you one email when Pluck opens. To be removed before then, email [email protected] and we will delete the row.

4. What we do not collect

We do not collect your name, your email address (for the app), your contacts, your phone number, your location, your photos, your device advertising identifier, or your real conversations with real people. Pluck contains no advertising SDK, no third-party analytics, and no cross-app tracking. We do not sell personal information and we do not share it for advertising.

There is no feature in Pluck today that imports your real chat history.

5. Who else processes your data

Who

What they get

Why

Anthropic

The content of the round: your messages and the conversation so far

To generate the character's next reply and the coach's grading

Fly.io

Everything we store, as our hosting and database provider

To run the service

Apple

Your sign-in, handled by Apple

To authenticate you without us holding an email address

Anthropic processes this as our service provider to answer our request. Under our terms with them, your conversations are not used to train their models.

We have no other processors: no analytics vendor, no email marketing platform, no advertising network, no data broker.

6. Automated processing, and what the grades are

Pluck is an AI product, and we want to be exact about it:

  • The characters are AI, not real people, and the app says so on screen.

  • Every message you send is scored by an automated system, and the round produces a rating that changes over time.

  • Those grades are a product opinion generated by a model — they are not a measurement of you, not a psychological assessment, and not advice. A real person may react differently to the same message.

  • The grading has no legal or financial consequence for you.

  • We compare the reads you tap against what the grader thought, and use the difference to calibrate the grader — to find where it is wrong, not to build a profile of you. This is our own tuning, not AI model training: your conversations are not used to train anyone's model (§5).

7. How long we keep it

  • Conversations, rounds, scenarios and your account: until you delete them. We run no automatic expiry, so what you keep, we keep.

  • Deleting your account removes your user record, sessions, every stored round and transcript, the reads you tapped in those rounds, your scenarios, and any friend connections. This is a real delete in our database, not a flag. If you are not signed in, the same deletion is available for everything your device created.

  • The anonymous counters in §3.4 are deleted too, per device. The daily open counts and the funnel events are keyed to a random device identifier rather than to your account, so we cannot find them from the account alone — the app sends that device identifier along with the delete, and we remove both sets of counters for that device. This works the same whether or not you are signed in. Two honest limits: the delete covers the device you run it from, so if you practised on a second device, deleting from that device too is what clears its counters; and a copy of the app old enough not to send the identifier will delete your account and rounds but leave that device's counters behind, which updating the app and deleting your data again will clear. The counters contain no name, no email, no message text and no identity.

  • Content reports: kept while we review them and for a reasonable period afterwards, because they are a safety record.

  • Waitlist email: until Pluck opens and we send the one email, or until you ask us to remove it.

  • Backups may hold copies for a short period after deletion before they age out.

8. Your choices

In the app: Settings → Delete account and practice data. That is the fastest and most complete route, and it needs no email to us.

California residents (CCPA/CPRA). You have the right to know what we collect, to get a copy, to correct it, and to have it deleted. You may also opt out of the “sale” or “sharing” of personal information — we do neither, and there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes requiring an opt-out. We will not discriminate against you for exercising any of these rights. To make a request, email [email protected]; we may need to verify that you control the account.

Anywhere else: email [email protected] and we will do the same thing.

9. Age

Pluck is for adults. You confirm you are 18 or over when you first open the app, and there is no way past that screen. If we learn that someone under 18 has an account, we will delete it and its data. If you believe a minor is using Pluck, email [email protected].

10. Security

Sign-in tokens are opaque and stored server-side so that signing out or deleting your account can genuinely revoke them. Traffic is encrypted in transit. Access to the production database is limited to the operator. No service is perfectly secure, and we will not pretend otherwise — but we hold as little as the product allows, which is the part that matters most.

11. Where your data is

Our servers and our providers are in the United States. If you use Pluck from elsewhere, your information is processed in the United States.

12. Changes

If we change this policy we will update the date above, and for anything material we will say so in the app before it takes effect.

13. Contact

[email protected] — privacy questions, deletion requests, or anything in this document that is not clear.