Purpl
Privacy Policy
Learn what information Purpl processes and what choices you have.
Effective August 14, 2026
Plum (“we,” “us,” or “our”) operates the Purpl web service, server API, and related features in accordance with applicable privacy laws.
This policy applies to Purpl account users and purchase-customer information from applications connected to Purpl. Application developers determine the purposes and legal bases for processing customer information they send to Purpl. We process that information only as needed to provide the service on their instructions.
1. Information we process and why
| Category | Information | Purpose |
|---|---|---|
| Account and sign-in | Google account identifier, verified email address, display name, preferred language, and identity information provided by Google and verified by Purpl | Registration, sign-in, account identification, and security |
| Organizations and applications | Organization membership, application and store identifiers, and product, entitlement, catalog, paywall, and localization configuration | Purchase configuration management and service delivery |
| Customers and transactions | Developer-assigned customer identifiers, store account identifiers, product and transaction identifiers, purchase tokens, purchase, expiration, cancellation and refund dates and status, store environment, entitlements, store notifications, and verification results | Purchase verification, transaction synchronization, entitlement calculation, and restoration |
| Notifications and connections | Webhook addresses and encrypted credentials, Telegram user and chat identifiers and connection details, delivery results, and errors | Event notifications and developer-system integrations |
| Automatic translation | Catalog and paywall titles, descriptions, and notices submitted for translation | Generating translation drafts |
| Usage and security | Authentication token hashes and expiration dates, User-Agent, request, error, and security records | Session management, incident response, and abuse prevention |
Purpl does not directly collect or store store payment method details such as card numbers.
2. How we collect information
- Through Google sign-in and information entered directly in the dashboard
- Through the Purpl SDK or server API on a developer’s instructions
- From Apple and Google Play server notifications and verification APIs
- From connected Telegram and webhook requests and delivery results
- From authentication, access, and error records generated while the service is used
3. Retention and deletion
| Information | Retention criteria |
|---|---|
| Account and organization information | Until an account or organization termination request is completed and any legally required retention period ends |
| Authentication sessions | Until the session expires, the user signs out, or the session is revoked |
| Application configuration and purchase-customer information | Until the connected application is terminated or a deletion request is completed, plus any period needed to provide the service or comply with law |
| Delivery and security records | For as long as needed to confirm delivery, respond to incidents, prevent abuse, and resolve disputes |
When information is no longer needed, we delete or de-identify it using methods designed to prevent recovery. Information remaining in backups is deleted through the regular backup replacement cycle and is not used for other purposes in the meantime.
4. Sharing and developer-directed delivery
We do not sell personal information. We do not disclose personal information to third parties unless the user consents or applicable law permits or requires it.
When a developer configures a webhook or Telegram notification, Purpl sends the selected purchase events and entitlement information to that destination on the developer’s instructions. The developer is responsible for the destination’s lawful use, access controls, and security settings.
5. Service providers and external services
| Provider | Purpose and processing |
|---|---|
| Google sign-in, Google Play transaction verification and notifications, Cloud Run API hosting, encryption key management, message delivery, and user-requested Gemini translation | |
| Apple | App Store transaction verification, transaction-history synchronization, and server notifications |
| Supabase | PostgreSQL database operation and backups |
| Telegram | Notifications and account linking through chats connected by the user |
| Developer-selected webhook providers | Delivery of events and entitlement information selected by the developer |
Each external service processes information only when the related feature is used or connected. Depending on a provider’s infrastructure, information may be processed outside the user’s country. In that case, it is transmitted over encrypted connections and retained only as needed to provide the feature or meet legal obligations.
6. Cookies and automatic collection
Purpl uses essential authentication cookies to maintain sign-in and protect the service. We do not use advertising cookies or advertising identifiers to track users. Blocking essential cookies prevents sign-in and dashboard features from working.
7. Security measures
- Encryption in transit and restricted access controls
- Storage of session tokens as hashes rather than plaintext
- Separate encryption keys for webhook secrets and App Store API private keys
- Operational records for detecting errors and unusual access
8. Your rights
You may request access to, correction or deletion of, restriction of processing of, or withdrawal of consent for your personal information. Requests concerning your Purpl account may be submitted through the contact information below.
Application purchase customers should first contact the developer of the relevant application. We support the developer’s lawful request to access, correct, or delete related information.
9. Privacy contact
- Operator: Plum
- Service: Purpl
- Email: contact@madeuse.com
10. Changes to this policy
We will announce changes to this policy on the Purpl website before they take effect. If a change materially affects user rights, we will provide separate notice within a reasonable period.