Privacy Policy
Last Updated:
Last updated: 14 September 2026
Pluck is a daily texting game. You practise conversations with characters played by an AI, and a coach marks what you sent. This policy explains what we collect, why, who else sees it, and how to get rid of it.
Pluck is operated by Tony Chow (“we”, “us”). Contact: [email protected].
1. The short version
You sign in with Apple. We never receive or store your name or email address for your account — only Apple's per-app identifier.
We do store the conversations you practise, because the coach has to read them to mark them, and because you can look back at a past round.
Your messages are sent to Anthropic to generate the character's replies and the coaching. They are not used to train anyone's model.
We use no advertising, no third-party analytics and no trackers. There is no advertising identifier in the app.
Deleting your account really deletes it, including every stored conversation and the anonymous counters belonging to the device you delete from, in one action from inside the app (§7).
Pluck is 18+.
2. Who this covers
This policy covers the Pluck app and the Pluck website. If you only join the waitlist on the website, the only thing we hold is your email address (§3.6).
3. What we collect
3.1 Account
When you sign in with Apple we store an opaque identifier Apple gives us for you (the “per-app subject”), our own internal id, and the dates you signed up and last opened the app. We do not ask Apple for your name or email, and we do not store them. If you use Apple's Hide My Email, nothing changes for us, because we were not using an email address anyway.
3.2 Your practice conversations
When you play a round we store the transcript — the messages you wrote, the character's replies, and the marks the coach gave each message — together with the round's state: which character and objective, the turn count, the engagement curve, and any safety flags. We store this because the coach must read the round to grade it, because your rating is computed from it, and so you can revisit a past round.
We also store the reads you tap during a round — whether you judged the other person to be leaning in, holding steady or cooling — alongside the answer the grader had, and the optional one-line "why?" if you wrote one. We keep these to check the grader against real players and improve it. They are stored with the round and are deleted when the round or the account is deleted.
Write as if a human might read it. We can read stored conversations when we have to: to investigate a content report, to fix a bug you tell us about, or where the law requires it. We do not read them routinely.
3.3 Scenarios you write
If you create your own scenario, we store the setup and opening line you wrote. It is private to your account.
3.4 App usage
Two things, both keyed to a random identifier generated on your device and neither linked to your account:
A daily open count. One row per install per day that the app was opened. It tells us how many people come back on day 1, day 3 and day 7.
A practice funnel. A small, fixed set of events recording which step of a round you reached and where you stopped: that the home screen was seen, that a round started and how it ended, that a message was sent, that the coach's breakdown was opened, that a retry was started, that a round was abandoned. Eleven event names in total.
We are specific about what an event may carry, because it is enforced in code rather than promised in a policy. Each event may only carry properties from a written allowlist, and every value must be a true/false, a whole number, or one of a short list of fixed words — for example the round's outcome, or which screen you started from. There is no free-text property, and there is no way for a message you wrote to end up in this store. The closest thing to content is the length of a message in characters, which we keep because "the message that ended it was four characters long" is a useful finding and a length cannot be turned back into a sentence.
Anything the app sends that is not on that allowlist is discarded by our server before it is written, including the event name itself.
3.5 Content reports
If you report something a character said, we store the report, what was shown, and enough context to review it.
3.6 Waitlist (website)
If you enter your email address on the Pluck website we store that address, a tag saying which part of the page you used, and the date. Your IP address is used in memory to rate-limit signups and is not written to our database. We will send you one email when Pluck opens. To be removed before then, email [email protected] and we will delete the row.
4. What we do not collect
We do not collect your name, your email address (for the app), your contacts, your phone number, your location, your photos, your device advertising identifier, or your real conversations with real people. Pluck contains no advertising SDK, no third-party analytics, and no cross-app tracking. We do not sell personal information and we do not share it for advertising.
There is no feature in Pluck today that imports your real chat history.
5. Who else processes your data
Who | What they get | Why |
|---|---|---|
Anthropic | The content of the round: your messages and the conversation so far | To generate the character's next reply and the coach's grading |
Fly.io | Everything we store, as our hosting and database provider | To run the service |
Apple | Your sign-in, handled by Apple | To authenticate you without us holding an email address |
Anthropic processes this as our service provider to answer our request. Under our terms with them, your conversations are not used to train their models.
We have no other processors: no analytics vendor, no email marketing platform, no advertising network, no data broker.
6. Automated processing, and what the grades are
Pluck is an AI product, and we want to be exact about it:
The characters are AI, not real people, and the app says so on screen.
Every message you send is scored by an automated system, and the round produces a rating that changes over time.
Those grades are a product opinion generated by a model — they are not a measurement of you, not a psychological assessment, and not advice. A real person may react differently to the same message.
The grading has no legal or financial consequence for you.
We compare the reads you tap against what the grader thought, and use the difference to calibrate the grader — to find where it is wrong, not to build a profile of you. This is our own tuning, not AI model training: your conversations are not used to train anyone's model (§5).
7. How long we keep it
Conversations, rounds, scenarios and your account: until you delete them. We run no automatic expiry, so what you keep, we keep.
Deleting your account removes your user record, sessions, every stored round and transcript, the reads you tapped in those rounds, your scenarios, and any friend connections. This is a real delete in our database, not a flag. If you are not signed in, the same deletion is available for everything your device created.
The anonymous counters in §3.4 are deleted too, per device. The daily open counts and the funnel events are keyed to a random device identifier rather than to your account, so we cannot find them from the account alone — the app sends that device identifier along with the delete, and we remove both sets of counters for that device. This works the same whether or not you are signed in. Two honest limits: the delete covers the device you run it from, so if you practised on a second device, deleting from that device too is what clears its counters; and a copy of the app old enough not to send the identifier will delete your account and rounds but leave that device's counters behind, which updating the app and deleting your data again will clear. The counters contain no name, no email, no message text and no identity.
Content reports: kept while we review them and for a reasonable period afterwards, because they are a safety record.
Waitlist email: until Pluck opens and we send the one email, or until you ask us to remove it.
Backups may hold copies for a short period after deletion before they age out.
8. Your choices
In the app: Settings → Delete account and practice data. That is the fastest and most complete route, and it needs no email to us.
California residents (CCPA/CPRA). You have the right to know what we collect, to get a copy, to correct it, and to have it deleted. You may also opt out of the “sale” or “sharing” of personal information — we do neither, and there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes requiring an opt-out. We will not discriminate against you for exercising any of these rights. To make a request, email [email protected]; we may need to verify that you control the account.
Anywhere else: email [email protected] and we will do the same thing.
9. Age
Pluck is for adults. You confirm you are 18 or over when you first open the app, and there is no way past that screen. If we learn that someone under 18 has an account, we will delete it and its data. If you believe a minor is using Pluck, email [email protected].
10. Security
Sign-in tokens are opaque and stored server-side so that signing out or deleting your account can genuinely revoke them. Traffic is encrypted in transit. Access to the production database is limited to the operator. No service is perfectly secure, and we will not pretend otherwise — but we hold as little as the product allows, which is the part that matters most.
11. Where your data is
Our servers and our providers are in the United States. If you use Pluck from elsewhere, your information is processed in the United States.
12. Changes
If we change this policy we will update the date above, and for anything material we will say so in the app before it takes effect.
13. Contact
[email protected] — privacy questions, deletion requests, or anything in this document that is not clear.