Privacy Policy

Last updated: September 17, 2026

Pluto: Photo Editor is provided by Justin Cahoon. This policy explains how Pluto handles information when you edit photos, use optional online features, or contact support.

Editing and projects on your device

Ordinary photo adjustments, signatures, manual masks, and supported automatic subject/background selection are processed on your device. Projects store photos, editing instructions, and related files locally so you can continue editing on that device.

Local projects are not automatically synchronized between devices. Device or browser storage settings and backups can affect how long local data remains available.

Optional cloud AI

Magic Eraser, Target Replace, and Generative Expand require an internet connection. When you request one of these operations, Pluto sends the image needed for the operation, a selection mask where applicable, and any text prompt to its cloud service to generate and return a result.

Pluto uses Amazon Web Services, including Amazon Bedrock image models, for this processing. Service and security information can include request/network information, operation and model names, timing, image sizes, usage counters, and errors. These records support operation, troubleshooting, and abuse prevention.

Processing and retention are subject to the service configuration and applicable provider safeguards, including security and abuse handling. We do not promise immediate deletion of every input or service record. You can use local editing without requesting cloud AI.

Photo transfer with Teleport

When you start a Teleport transfer, Pluto uploads the selected photo to private AWS storage so the receiving device can download it. Transfer/session information and temporary access credentials are used to complete the transfer. Teleport transfers a photo; it does not synchronize an editable project.

Teleport sends the selected original photo, which may include embedded metadata such as capture location. It does not automatically remove that metadata before transfer.

Transfer sessions expire. Pluto attempts to delete the uploaded file when a transfer is completed, canceled, or expired. A storage rule also schedules Teleport files for expiration after one day. Storage deletion can occur later than the session timeout or scheduled expiration. Do not share a transfer link or pairing code with someone you do not want to receive the photo.

Analytics and diagnostics

Pluto uses Google Analytics/Firebase for usage, feature outcomes, reliability, and acquisition reporting, and Sentry for error and performance diagnostics. Information can include interactions, operation outcomes, app version, platform, device or installation identifiers, device/software characteristics, and technical error information.

Analytics can also derive approximate location from network information. See how Google uses information from apps and sites that use its services.

Pluto's product analytics events are designed to report editing activity and outcomes without sending photo pixels or selection-mask content as analytics events. Optional cloud AI and Teleport send image content separately as described above. Analytics and diagnostic services maintain their own records under their applicable settings and service terms.

Store purchases and attribution

Apple and Google handle store payments. RevenueCat supports purchase records, subscription status, and restoration, using app-user identifiers and store transaction information. Pluto does not receive your payment-card details from the stores. On iOS, RevenueCat can also receive Apple AdServices attribution information.

Older versions may display subscription controls. Free access does not itself delete historical purchase or transaction records. Store records are also governed by the relevant Apple or Google account and policies.

Permissions and your choices

Photo-library access allows importing photos and saving results. Camera access allows taking photos. Available permissions depend on your platform; you can review or revoke them in device settings. A permission to access a photo does not mean every photo in your library is uploaded.

You choose whether to request cloud AI or begin a Teleport transfer. Exported photos and device/cloud backups may remain outside Pluto after you remove a local project or uninstall the app. See data deletion for the differences between local files, transfers, and service records.

Intended audience

Pluto is a general-purpose photo editor intended for teenagers and adults. It is not designed for children under 13. If you believe a child under 13 has provided personal information through Pluto, contact us using the address below.

Support and privacy requests

If you contact us, we receive the email address and information you choose to send. We use this information to respond to your request. Please do not send passwords, payment-card details, or private photos unless they are needed for an agreed support investigation.

Contact Justin Cahoon about support, access, correction, or deletion requests at aiphotoeditor123@gmail.com. We may need enough information to identify relevant records. Some information may need to be retained for security, dispute resolution, or legal obligations.