Word Add-in Privacy Policy
Last updated: February 2026
This policy covers the PlotLens Microsoft Word add-in specifically. For the general PlotLens service, see our main privacy policy.
Overview
PlotLens for Word is a narrative intelligence add-in that checks your writing against your Story Bible — the facts your story has established (what readers call canon). This policy explains what data we collect, how we process it, and your rights.
Data We Collect
Document Content
- What: Text from the active Word document, sent for a Manuscript Check against your project's established facts.
- When: Only when you click "Validate Now" or have auto-validation enabled.
- Retention: Document text is processed in-memory and not stored after the validation response is returned. No document content is persisted on our servers.
Authentication Data
- What: Email address and OAuth access token.
- When: During sign-in via the Office Dialog API.
- Retention: Tokens are stored locally in Office document settings. Email is stored in your PlotLens account.
Usage Analytics
- What: Anonymous usage metrics (feature usage counts, error rates, API latency).
- When: During normal add-in operation.
- Retention: Aggregated metrics are retained for 90 days.
Your Content Is Yours
We do not use your creative content to train AI models. Document text is processed transiently to produce validation results and then discarded.
How We Process Data
- Validation requests — Document text is sent to the PlotLens API over HTTPS, processed by our validation engine (which may use LLM services for entity extraction), and the results are returned to the add-in.
- Entity extraction — When you upload documents to your PlotLens project (via the web app), entities are extracted using LLM providers. This does not occur within the Word add-in itself.
- Search queries — Story Bible search queries are processed server-side against your project's indexed content.
Third-Party Services
- PlotLens API — Validation, entities, search. Receives document text (transient) and auth token.
- AWS Bedrock / OpenAI — Entity extraction and embeddings (web app only). Receives document content you upload to projects.
- Stripe — Billing (web app only). Receives payment information.
Data Storage & Security
- All data in transit is encrypted via TLS 1.2+.
- Authentication uses OAuth 2.0 with PKCE (no client secrets in the add-in).
- Server-side data is encrypted at rest.
- Infrastructure is hosted on secured cloud providers.
Your Rights
- Access: View your data at any time through the PlotLens web dashboard.
- Deletion: Delete your account and all associated data from Settings > Account.
- Export: Export your project data (entities, rules, documents) from the web dashboard.
- Opt-out: Uninstall the add-in at any time. No data is retained locally after uninstall.
Children's Privacy
PlotLens is not directed at children under 13. We do not knowingly collect data from children.
Changes to This Policy
We will notify users of material changes via email and in-app notification.
Contact
- Email: privacy@plotlens.ai
- Support: plotlens.ai/support/word-addin