Purpl

Purpl

Privacy Policy

Learn what information Purpl processes and what choices you have.

Effective August 14, 2026

Plum (“we,” “us,” or “our”) operates the Purpl web service, server API, and related features in accordance with applicable privacy laws.

This policy applies to Purpl account users and purchase-customer information from applications connected to Purpl. Application developers determine the purposes and legal bases for processing customer information they send to Purpl. We process that information only as needed to provide the service on their instructions.

1. Information we process and why

CategoryInformationPurpose
Account and sign-inGoogle account identifier, verified email address, display name, preferred language, and identity information provided by Google and verified by PurplRegistration, sign-in, account identification, and security
Organizations and applicationsOrganization membership, application and store identifiers, and product, entitlement, catalog, paywall, and localization configurationPurchase configuration management and service delivery
Customers and transactionsDeveloper-assigned customer identifiers, store account identifiers, product and transaction identifiers, purchase tokens, purchase, expiration, cancellation and refund dates and status, store environment, entitlements, store notifications, and verification resultsPurchase verification, transaction synchronization, entitlement calculation, and restoration
Notifications and connectionsWebhook addresses and encrypted credentials, Telegram user and chat identifiers and connection details, delivery results, and errorsEvent notifications and developer-system integrations
Automatic translationCatalog and paywall titles, descriptions, and notices submitted for translationGenerating translation drafts
Usage and securityAuthentication token hashes and expiration dates, User-Agent, request, error, and security recordsSession management, incident response, and abuse prevention

Purpl does not directly collect or store store payment method details such as card numbers.

2. How we collect information

  • Through Google sign-in and information entered directly in the dashboard
  • Through the Purpl SDK or server API on a developer’s instructions
  • From Apple and Google Play server notifications and verification APIs
  • From connected Telegram and webhook requests and delivery results
  • From authentication, access, and error records generated while the service is used

3. Retention and deletion

InformationRetention criteria
Account and organization informationUntil an account or organization termination request is completed and any legally required retention period ends
Authentication sessionsUntil the session expires, the user signs out, or the session is revoked
Application configuration and purchase-customer informationUntil the connected application is terminated or a deletion request is completed, plus any period needed to provide the service or comply with law
Delivery and security recordsFor as long as needed to confirm delivery, respond to incidents, prevent abuse, and resolve disputes

When information is no longer needed, we delete or de-identify it using methods designed to prevent recovery. Information remaining in backups is deleted through the regular backup replacement cycle and is not used for other purposes in the meantime.

4. Sharing and developer-directed delivery

We do not sell personal information. We do not disclose personal information to third parties unless the user consents or applicable law permits or requires it.

When a developer configures a webhook or Telegram notification, Purpl sends the selected purchase events and entitlement information to that destination on the developer’s instructions. The developer is responsible for the destination’s lawful use, access controls, and security settings.

5. Service providers and external services

ProviderPurpose and processing
GoogleGoogle sign-in, Google Play transaction verification and notifications, Cloud Run API hosting, encryption key management, message delivery, and user-requested Gemini translation
AppleApp Store transaction verification, transaction-history synchronization, and server notifications
SupabasePostgreSQL database operation and backups
TelegramNotifications and account linking through chats connected by the user
Developer-selected webhook providersDelivery of events and entitlement information selected by the developer

Each external service processes information only when the related feature is used or connected. Depending on a provider’s infrastructure, information may be processed outside the user’s country. In that case, it is transmitted over encrypted connections and retained only as needed to provide the feature or meet legal obligations.

6. Cookies and automatic collection

Purpl uses essential authentication cookies to maintain sign-in and protect the service. We do not use advertising cookies or advertising identifiers to track users. Blocking essential cookies prevents sign-in and dashboard features from working.

7. Security measures

  • Encryption in transit and restricted access controls
  • Storage of session tokens as hashes rather than plaintext
  • Separate encryption keys for webhook secrets and App Store API private keys
  • Operational records for detecting errors and unusual access

8. Your rights

You may request access to, correction or deletion of, restriction of processing of, or withdrawal of consent for your personal information. Requests concerning your Purpl account may be submitted through the contact information below.

Application purchase customers should first contact the developer of the relevant application. We support the developer’s lawful request to access, correct, or delete related information.

9. Privacy contact

10. Changes to this policy

We will announce changes to this policy on the Purpl website before they take effect. If a change materially affects user rights, we will provide separate notice within a reasonable period.