Legal · version 2026-09

Plum Developer Terms

Draft for legal review. This page states the rules the store enforces; the binding text will replace it before public launch.

1. Your key, your signature

Every bundle you publish is signed with a key only you hold. You are responsible for that key and for what it signs. The store verifies your signature and adds its own countersignature only after automatic checks (beta) or a human review (public). Register a recovery key; the store cannot recover a lost key for you except through the waiting-period rotation described in the console.

2. What may be published

Apps must declare every permission they use and must not read, send or store user data beyond those permissions. No malware, no covert data collection, no circumvention of the box's sandbox, no impersonation of Plum or of other publishers. App ids must stay within your namespace.

3. Review and removal

Public versions are reviewed by a person and may be rejected with reasons. Plum may remove a published version or suspend a publisher for violations, and may revoke the store countersignature; boxes that trust only the store will then refuse the version. Beta versions reach only the boxes you list as testers.

4. Updates and continuity

Updates must be signed by the same key as the version they replace, or carry a rotation record. Users' boxes enforce this; the store enforces it at upload.

5. Pricing and payment

Paid apps and in-app entitlements are sold through Plum Store at the price you set; Plum keeps a commission stated in the console at listing time. Nothing in the Plum apps may steer users to payment outside Plum Store for box-side features.

6. Data and privacy

Data your app stores lives on the user's box and belongs to the user. Any data leaving the box must be disclosed in the listing.

7. Changes

When these terms change materially, the console asks you to accept the new version before your next upload. The version you accepted is recorded with your account.