• @eamade24aec55withp-image
  • @elad-elyakimmade5524a20withp-image
  • @yamb0xmade53b0324withvideo-morph
  • @omri-steigmanmade850f0cewithp-image
  • @codymadef25e542withstyler/mixer
  • @nimrod-kleinmadeebb2cebwithvectorize
  • @ross-mogermadead49091withp-image
  • @wixmade5266044withp-image
  • @yehor-ivanovmade839a68dwithideogram-v4
  • @hendrik-baumlemade7035d38withflux-3-edit
  • @nicol-sergeevmade1485c13withp-image
  • @elad-malcamade10200dbwithmultiview-2.0

Trust Center

How Plnty protects your work: the controls in place today, every processor that touches your data, and where to report a problem. The binding text is the Privacy Policy; this page is the operational summary.

Files you make or upload live in Cloudflare R2 object storage. Account data and the asset catalog live in a Supabase Postgres database on AWS ap-south-1. Live board sync runs on Fly.io in Frankfurt. When you run a generation, the inputs of that run go to the model provider that executes it, and the result comes back to your board.

Last reviewed 11 August 2026 · security@plnty.app

Platform security

Encryption in transit

Every connection runs over TLS. plnty.app sits on the browser HSTS preload list, which makes plain-HTTP connections impossible rather than merely redirected.

Encryption at rest

Objects in R2 and the Postgres database are encrypted at rest by the storage layer with AES-256.

Content Security Policy

A strict CSP is enforced on the application and the marketing site.

Security headers

Every response carries HSTS. Page responses add frame-ancestors, X-Content-Type-Options, Referrer-Policy and a scoped Permissions-Policy.

Status monitoring

status.plnty.app probes the app, sync server, database, storage and AI gateways every two minutes and opens incidents automatically. It runs on infrastructure separate from production hosting, so an outage cannot take the status page down with it.

Secrets handling

API keys for AI providers and storage are held in server-side workers. The browser bundle contains no provider credentials.

Tenant isolation

Row-level security policies in Postgres scope every query to the requesting account's workspaces. Isolation is enforced at the database layer in addition to application checks.

Signed asset access

Media in R2 is served through short-lived signed URLs, minted per request by a dedicated signer service after a project-access check.

Billing authority

Credit balances change only through server-side code writing to an append-only ledger. The client cannot grant, spend or restore credit. Card numbers never touch a Plnty server; payments run through Polar as merchant of record.

Access control

Sign-in is Google or email through auth.plnty.app. The beta is invite-only: creating an account requires a personally issued code.

Subprocessors

Twenty-one third-party processors operate parts of the Service, each bound by a GDPR Article 28 data processing agreement. AI providers receive only the inputs of the runs you start. This register is the named list; the Privacy Policy describes each category of recipient and what it receives.

  • Cloudflare

    Global edge

    Edge compute and object storage (R2)

    Entity
    Cloudflare, Inc.
    Data processed
    User content, request metadata, IP addresses
    Address
    101 Townsend St, San Francisco, CA 94107, United States
    Contact
    dpo@cloudflare.com
  • Vercel

    United States

    Application hosting and marketing analytics

    Entity
    Vercel Inc.
    Data processed
    Request metadata, IP addresses, aggregate page views
    Address
    440 N Barranca Avenue #4133, Covina, CA 91723, United States
    Contact
    privacy@vercel.com
  • Supabase

    India (AWS ap-south-1)

    Database, authentication and realtime

    Entity
    Supabase Pte. Ltd.
    Data processed
    Account information, project data, asset metadata
    Address
    65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513
    Contact
    privacy@supabase.com
  • Fly.io

    Germany (Frankfurt)

    Realtime collaboration sync

    Entity
    Fly.io, Inc.
    Data processed
    Live board and document state
    Address
    2261 Market Street #4990, San Francisco, CA 94114, United States
    Contact
    support@fly.io
  • Polar

    Multi-region

    Payments, as merchant of record

    Entity
    Polar Software Inc.
    Data processed
    Name, email, billing address, payment status
    Address
    3500 South DuPont Highway, Dover, DE 19901, United States
    Contact
    privacy@polar.sh
  • Resend

    United States

    Transactional email

    Entity
    Plus Five Five, Inc.
    Data processed
    Recipient address, message body
    Address
    2261 Market Street #5039, San Francisco, CA 94114, United States
    Contact
    privacy@resend.com
  • fal.ai

    United States

    AI inference, multi-model aggregator

    Entity
    fal - Features & Labels, Inc.
    Data processed
    Prompts, uploaded images, mesh files
    Address
    2261 Market St. Suite 10467, San Francisco, CA 94114, United States
    Contact
    support@fal.ai
  • Replicate

    United States

    AI inference, multi-model aggregator

    Entity
    Replicate, LLC
    Data processed
    Prompts, images, mesh files, model parameters
    Address
    101 Townsend Street, San Francisco, CA 94107, United States
    Contact
    privacy@replicate.com
  • Tripo3D

    United States and Asia

    AI inference, text and image to 3D

    Entity
    Holymolly Ltd
    Data processed
    Prompts, images
    Contact
    support@tripo3d.ai
  • Meshy

    United States

    AI inference, 3D generation and retexturing

    Entity
    Meshy LLC
    Data processed
    Prompts, images, mesh files
    Address
    Murphy Square, 111 West Evelyn Avenue, Suite 304, Sunnyvale, CA 94086, United States
    Contact
    support@meshy.ai
  • OpenRouter

    United States, routes globally

    Language-model routing, text and vision

    Entity
    OpenRouter, Inc.
    Data processed
    Prompts, conversation context
    Address
    169 Madison Avenue, New York, NY 10016, United States
    Contact
    privacy@openrouter.ai
  • OpenAI

    United States

    Image editing, prompt enhancement, captioning

    Entity
    OpenAI OpCo, LLC
    Data processed
    Prompts, uploaded images
    Address
    1455 Third Street, San Francisco, CA 94158, United States
    Contact
    privacy@openai.com
  • Krea

    United States

    Image and video generation, upscaling

    Entity
    Krea.ai, Inc.
    Data processed
    Prompts, images, video
    Address
    2637 Buchanan Street, San Francisco, CA 94115, United States
    Contact
    support@krea.ai
  • Luma

    United States

    Image and video generation

    Entity
    Luma AI, Inc.
    Data processed
    Prompts, images, video
    Address
    380 Hamilton Ave, P.O. Box 102, Palo Alto, CA 94301, United States
    Contact
    hello@lumalabs.ai
  • BytePlus

    Singapore (AP-Southeast)

    AI inference, video generation

    Entity
    Byteplus Pte. Ltd.
    Data processed
    Prompts, reference images, video and audio
    Address
    1 Raffles Quay, #26-10, Singapore 048583
    Contact
    privacy@byteplus.com
  • RunPod

    European Union (Romania)

    GPU compute for real-time image inference

    Entity
    Runpod Inc.
    Data processed
    Canvas frames and prompts from the render window
    Address
    1181 Nixon Dr. #1158, Moorestown, NJ 08057, United States
    Contact
    privacy@runpod.io
  • Google

    Global

    Sign-in identity provider (OAuth)

    Entity
    Google LLC
    Data processed
    Email address, name, profile picture
    Address
    1600 Amphitheatre Parkway, Mountain View, CA 94043, United States
    Contact
    support.google.com/policies
  • GitHub

    United States

    Sign-in identity provider (OAuth)

    Entity
    GitHub, Inc.
    Data processed
    Username, email address
    Address
    88 Colin P. Kelly Jr. St., San Francisco, CA 94107, United States
    Contact
    dpo@github.com
  • Are.na

    United States

    Reference image search proxy

    Entity
    When It Changed Inc.
    Data processed
    Search queries, without user identifiers
    Address
    794 Route 217, Hudson, NY 12534, United States
    Contact
    info@are.na
  • Google Search and Lens, via SerpApi

    United States

    Reference and reverse-image search

    Entity
    SerpApi, LLC
    Data processed
    Search queries, reference image URLs
    Address
    5540 N Lamar Blvd #12, Austin, TX 78751, United States
    Contact
    support@serpapi.com
  • Apify

    European Union and United States

    Public Instagram post and profile metrics for the Residency

    Entity
    Apify Technologies s.r.o.
    Data processed
    Public Instagram post URLs and account handles
    Address
    Vodičkova 704/36, Nové Město, 110 00 Praha 1, Czech Republic
    Contact
    privacy@apify.com

Data and privacy

Model training

Plnty does not use your content to train, fine-tune or improve any AI model operated by Plnty or on its behalf. The commitment is Terms of Use section 4.4. Third-party model providers are bound by their own terms: an endpoint Plnty designates as a Protected Endpoint carries a written no-training commitment from its provider (Terms section 6.3), and any other endpoint operates under its provider's own terms (Terms section 6.5).

Processor agreements

Each subprocessor operates under a GDPR Article 28 data processing agreement and processes personal data only on Plnty's instructions.

International transfers

EU transfers rest on the European Commission adequacy decision for Israel, with Standard Contractual Clauses or the EU-US Data Privacy Framework where a processor sits outside the EEA.

Retention

Retention runs per data class: deleted account content is purged immediately, generated assets 30 days after project deletion, audit logs after 12 months, database backups after 7 days. The Privacy Policy states the criteria each period follows.

Deletion and export

Account deletion is self-service and takes effect immediately. A copy of your personal data is available on request.

Breach notification

In the event of a personal-data breach, affected users and the competent supervisory authorities are notified within the GDPR timeframe, typically 72 hours.

Telemetry

The application contains no third-party analytics and sends client errors to no third party: they are recorded first-party, in our own database. The marketing site uses cookieless aggregate analytics. During a new account's first session Plnty records a five-minute interaction tape, first-party and retained for 90 days: cursor positions, clicks and the names of the controls clicked, with no screen recording, no canvas content, no keystrokes and no prompt text.

Organizational security

Least privilege

Production access is limited to named operators with a business need. Support access to user content follows the same principle and is limited to what the task requires.

Audit logging

Administrative actions are logged, and the logs are retained for 12 months.

Backups and recovery

Board state is snapshotted server-side on a rolling schedule, and recovery procedures have been exercised against real production incidents. Daily database backups are retained for 7 days.

Subprocessor review

The security posture of each processor is assessed before it is added. Material subprocessor changes are announced in advance.

Vulnerability disclosure

Reports go to security@plnty.app. A security.txt file at the RFC 9116 location carries the same contact for automated scanners.