Security at Plumlly
We take the security of your data and your meetings seriously. Here is how we protect you.
Last updated: July 2026
Your data is encrypted everywhere
All data transmitted to and from Plumlly is encrypted using TLS 1.3 — the same standard used by banks and healthcare providers. Your meeting notes, calendar data, and personal information are encrypted both in transit and at rest using AES-256 encryption.
- TLS 1.3 for all data in transit
- AES-256 encryption for data at rest
- Encrypted database backups
- Secure key management
Secure authentication
Plumlly uses industry-standard authentication practices to protect your account.
- OAuth 2.0 for Google and Microsoft sign-in
- Secure session tokens with automatic expiry
- No passwords stored — we use secure third-party authentication providers
- Session invalidation on sign-out
- Suspicious login detection
Your data belongs to you
We collect only what we need to provide the Plumlly service. We never sell your data to third parties. Ever.
- Meeting data used only to provide your summaries and notes
- AI processing done on your data only — never used to train shared models without explicit consent
- Calendar data read only — we never modify your calendar without your action
- You can export or delete all your data at any time from Settings
Enterprise-grade infrastructure
Plumlly is built on trusted, secure infrastructure providers with SOC 2 compliance and 99.9% uptime guarantees.
- Hosted on Vercel and Render — enterprise-grade cloud infrastructure
- Database hosted on Supabase (PostgreSQL) with automatic backups every 24 hours
- Redis cache via Upstash with in-transit encryption
- Automatic failover and redundancy
- Infrastructure monitored 24/7
How we use AI on your data
Plumlly uses OpenAI to power AI features including meeting summaries, prep briefs, and follow-up drafts. Here is exactly how your data is handled:
- Meeting transcripts are sent to OpenAI only to generate your specific summary
- OpenAI does not use your data to train their models (we use the API, not the consumer product)
- AI-generated content is stored only in your Plumlly account
- You can disable AI features at any time in Settings
Calendar data security
When you connect Google Calendar or Microsoft Outlook to Plumlly, here is exactly what we access and why:
| Permission | What we access | Why |
|---|---|---|
| Read calendar events | Your existing events | To show your availability and prevent double-bookings |
| Write calendar events | Only meetings you book through Plumlly | To create calendar invites |
| Read contacts | Names and emails | To auto-fill attendee information |
We do NOT:
- Delete any of your existing calendar events
- Share your calendar data with third parties
- Store your full calendar — only the availability slots needed for scheduling
Found a security issue?
We take security reports seriously and respond to all verified vulnerabilities promptly. If you have found a security issue in Plumlly, please contact us responsibly before disclosing publicly.
security@plumlly.com
Response commitment:
- Initial acknowledgment within 24 hours
- Status update within 72 hours
- Fix timeline communicated within 7 days
We do not currently offer a bug bounty program, but we deeply appreciate responsible disclosure and will credit researchers who report valid vulnerabilities.
Compliance and standards
- GDPR compliant — we honor data subject rights for EU users
- CCPA compliant — California residents can request data deletion
- Data Processing Agreements available for enterprise customers
- SOC 2 assessment in progress