Plum Developer Terms
Draft for legal review. This page states the rules the store enforces; the binding text will replace it before public launch.
1. Your key, your signature
Every bundle you publish is signed with a key only you hold. You are responsible for that key and for what it signs. The store verifies your signature and adds its own countersignature only after automatic checks (beta) or a human review (public). Register a recovery key; the store cannot recover a lost key for you except through the waiting-period rotation described in the console.
2. What may be published
Apps must declare every permission they use and must not read, send or store user data beyond those permissions. No malware, no covert data collection, no circumvention of the box's sandbox, no impersonation of Plum or of other publishers. App ids must stay within your namespace.
3. Review and removal
Public versions are reviewed by a person and may be rejected with reasons. Plum may remove a published version or suspend a publisher for violations, and may revoke the store countersignature; boxes that trust only the store will then refuse the version. Beta versions reach only the boxes you list as testers.
4. Updates and continuity
Updates must be signed by the same key as the version they replace, or carry a rotation record. Users' boxes enforce this; the store enforces it at upload.
5. Pricing and payment
Paid apps and in-app entitlements are sold through Plum Store at the price you set; Plum keeps a commission stated in the console at listing time. Nothing in the Plum apps may steer users to payment outside Plum Store for box-side features.
6. Data and privacy
Data your app stores lives on the user's box and belongs to the user. Any data leaving the box must be disclosed in the listing.
7. Changes
When these terms change materially, the console asks you to accept the new version before your next upload. The version you accepted is recorded with your account.