Privacy Policy
Last updated 27 August 2026. Draft — pending legal review.
Plutarch (operated by Plutarch Labs) is a self-serve hiring feasibility intelligence service for the energy industry. This policy explains what we collect when you use it, how we handle it, and the choices you have. It is aligned with Singapore’s Personal Data Protection Act (PDPA) and, where EU/UK residents are involved, the General Data Protection Regulation (GDPR).
What we collect
Three kinds of data:
- Account data — the email address you sign in with. We authenticate with a one-time code emailed to you; we do not store a password.
- Content you submit — the job descriptions, URLs and queries you paste in to generate a brief, and the briefs produced from them.
- Messages you send us — if you write to us through the contact form, we store your name, email address, any company you give, and your message, and use them only to reply to you. We do not add you to a marketing list.
We do not ask for, and the service is not designed to hold, candidate CVs or candidate personal data. Please do not paste it.
Personal data is redacted before processing
Before any job description reaches an AI model or is written to storage, it passes through an automated redaction step that strips obvious personal data — email addresses, phone numbers, and names in contact and sign-off lines. This runs on our servers, ahead of every model call and every write. It is deliberately conservative: over-redacting a stray phrase is acceptable, leaking a person is not. Salary figures are preserved so your brief stays useful.
We never train AI on your data
Your job descriptions, queries and briefs are never used to train or fine-tune AI models — ours or third parties’. We send redacted content to the AI providers that power a brief solely to produce that brief for you, under their API terms, which prohibit training on submitted data. We do not sell your data.
How your data is stored and kept private
Content and briefs are stored in Google Firestore, encrypted in transit and at rest. Your job descriptions, your briefs and your account are private to you: no other customer can see the text you paste, the briefs you generate, or that they came from you.
Market research is shared; your content is not
Plutarch is a market-intelligence service, and it gets better the more it researches. When we research a role — what it pays, how scarce the people are, who else is hiring — that research describes the public labour market, not you. We keep it and reuse it across Plutarch, so a later question about a similar role in the same market is answered faster and from more evidence.
To be precise about the line: your job description, your briefs and your identity are never shown to another customer. The research we produce from them is. That research is redacted before it is stored, and it can name employers — including one named in a job description — because who is hiring for a role is a public market fact and is the substance of what we sell. We do not attach your name, your company or your account to it.
Third parties we rely on
We share data only with the infrastructure and AI providers needed to run the service:
- Google (Firebase Authentication and Firestore) — sign-in and storage.
- Vercel — application hosting.
- AI providers (including Google Gemini, Anthropic, OpenAI and xAI) — to reason over the redacted content of a brief. These providers do not train on data submitted through their APIs.
Retention and your rights
We keep your account and content for as long as your account is active. Under PDPA and GDPR you may request access to, correction of, or deletion of your personal data, and you may withdraw consent. Email us and we will action it. Deleting your account removes your briefs and submitted content, subject to short-lived backups.
Contact
Questions, or a data request? Email santosh@plutarchlabs.com.
This is a draft policy for an early-access product and is subject to legal review and change. It is not legal advice.