Privacy

What Plexiform reads, what stays on your computer, and what little ever leaves it.

Beta notice. This page summarises the beta's privacy notice, which is a draft and hasn't had its legal review yet. Where they differ, the notice inside the app wins.

In short

  • Never: telemetry, analytics or advertising trackers. We don't sell or share your data.
  • Off by default: calendar, calendar subscription links, voice questions, answering permission prompts from the widget, and remote devices.
  • On by default: checking GitHub for pull requests and builds through your own gh login, if you have one signed in, and reading your Focus status on this computer.
  • Only if you join a team board: your cards, handovers and run progress go to your team's hub. Today that hub is run by Plexiform at app.plexiform.dev. When you sign in (with Google or GitHub, as accounts roll out), your name and email are shared with that hub.
  • Update checks and downloads, in the release that adds in-app updates: the app asks download.plexiform.dev whether a newer version exists and downloads it from there. Like any download, this reveals your IP address and your app version.
  • The website waitlist: if you join it, we store the email you give us.
  • Cloudflare passes all of this traffic through (the hub, this website and downloads) as our processor.
  • Not built yet: crash reports. They will be off until you opt in.

What stays on your computer

  • Your Claude Code conversation logs are read on your machine to work out tokens and cost. Only counts and costs are kept, not the text.
  • Your prompts and the replies are never stored by Plexiform.
  • Session state: the folder, the state, the current tool, the model name and task counts.
  • Your settings, rules and any face photos you add as cameos.
  • Voice is turned into text on your device. Audio is never written to disk.

What leaves, and when

  • GitHub, through your own login, about every 90 seconds, only if gh is installed and signed in.
  • Your AI tools send your prompts to their providers under those providers' terms. Plexiform neither sees nor changes that.
  • Plexiform's servers: update checks and downloads (download.plexiform.dev), in the release that adds in-app updates. They reveal your IP address and app version, like any download.
  • A calendar subscription link, only if you paste one, fetched over HTTPS.
  • Plexiform's servers: your team's hub (app.plexiform.dev), only if you join a team board: card text, handovers, run progress, member names, the identity of repos you link, and your account name and email when you sign in. Text passes a filter for credential-like strings and home-folder paths first. Sharing what you're working on is a separate opt-in.

This website

This site has no analytics and sets no cookies. If you join the waitlist, we store your email, the agent you said you use, and the time, and use them only to send you a beta invite. Email [email protected] to have it removed.