PlumllyPlumlly
Back to Plumlly
Security

Security at Plumlly

We take the security of your data and your meetings seriously. Here is how we protect you.

Last updated: July 2026

Your data is encrypted everywhere

All data transmitted to and from Plumlly is encrypted using TLS 1.3 — the same standard used by banks and healthcare providers. Your meeting notes, calendar data, and personal information are encrypted both in transit and at rest using AES-256 encryption.

  • TLS 1.3 for all data in transit
  • AES-256 encryption for data at rest
  • Encrypted database backups
  • Secure key management

Secure authentication

Plumlly uses industry-standard authentication practices to protect your account.

  • OAuth 2.0 for Google and Microsoft sign-in
  • Secure session tokens with automatic expiry
  • No passwords stored — we use secure third-party authentication providers
  • Session invalidation on sign-out
  • Suspicious login detection

Your data belongs to you

We collect only what we need to provide the Plumlly service. We never sell your data to third parties. Ever.

  • Meeting data used only to provide your summaries and notes
  • AI processing done on your data only — never used to train shared models without explicit consent
  • Calendar data read only — we never modify your calendar without your action
  • You can export or delete all your data at any time from Settings

Enterprise-grade infrastructure

Plumlly is built on trusted, secure infrastructure providers with SOC 2 compliance and 99.9% uptime guarantees.

  • Hosted on Vercel and Render — enterprise-grade cloud infrastructure
  • Database hosted on Supabase (PostgreSQL) with automatic backups every 24 hours
  • Redis cache via Upstash with in-transit encryption
  • Automatic failover and redundancy
  • Infrastructure monitored 24/7

How we use AI on your data

Plumlly uses OpenAI to power AI features including meeting summaries, prep briefs, and follow-up drafts. Here is exactly how your data is handled:

  • Meeting transcripts are sent to OpenAI only to generate your specific summary
  • OpenAI does not use your data to train their models (we use the API, not the consumer product)
  • AI-generated content is stored only in your Plumlly account
  • You can disable AI features at any time in Settings

Calendar data security

When you connect Google Calendar or Microsoft Outlook to Plumlly, here is exactly what we access and why:

PermissionWhat we accessWhy
Read calendar eventsYour existing eventsTo show your availability and prevent double-bookings
Write calendar eventsOnly meetings you book through PlumllyTo create calendar invites
Read contactsNames and emailsTo auto-fill attendee information

We do NOT:

  • Delete any of your existing calendar events
  • Share your calendar data with third parties
  • Store your full calendar — only the availability slots needed for scheduling

Found a security issue?

We take security reports seriously and respond to all verified vulnerabilities promptly. If you have found a security issue in Plumlly, please contact us responsibly before disclosing publicly.

security@plumlly.com

Response commitment:

  • Initial acknowledgment within 24 hours
  • Status update within 72 hours
  • Fix timeline communicated within 7 days

We do not currently offer a bug bounty program, but we deeply appreciate responsible disclosure and will credit researchers who report valid vulnerabilities.

Compliance and standards

  • GDPR compliant — we honor data subject rights for EU users
  • CCPA compliant — California residents can request data deletion
  • Data Processing Agreements available for enterprise customers
  • SOC 2 assessment in progress

Have a security question that is not answered here?

security@plumlly.com

Contact security team →