Skip to content

Your manuscripts stay private.

Your draft is the most personal thing you own. We built PlotLens so that trusting us with it is a decision you can check, not one you have to take on faith.

Never used for AI training. Yours to export. Yours to delete.

Reviewing PlotLens for your organization?Skip to the controls reference. Last reviewed 9 August 2026.

The three things that matter most

Your work is never training data

We never use your manuscripts, characters or worlds to train or fine-tune AI models, and neither does the model provider we run on. Your book stays your book.

Encrypted, and walled off from everyone else

Encrypted with TLS on the way to us and AES-256 once it lands. Every query the application makes is locked to your account at the database level, so another customer cannot reach your pages even by accident.

Leaving is as easy as arriving

Export everything whenever you like. Delete a document, a project or your whole account from settings and it is gone from the product at once; the disaster-recovery copies behind it expire within 30 days.

For security reviewers

Controls reference

Everything below describes what is in place today, not what is planned. Where a control does not exist yet, it says so. Anything genuinely planned is in the roadmap at the foot of this page.

Tenant isolation and access management

ControlHow it works
Tenant data isolationPostgreSQL row-level security. Every application query runs inside a database session bound to a single tenant, so a query cannot return another tenant’s rows even if application code asks for them.
Background processingBackground workers connect with a separate, scoped database role rather than the application role. That role is not reachable from a user-facing request path.
AuthenticationDelegated to Clerk. PlotLens never stores account passwords. Sessions are short-lived signed tokens, verified at the API gateway on every request before any application code runs.
AuthorizationFour team roles — owner, admin, editor and viewer — map to read, write, delete, invite and administrative permissions. Membership and role are evaluated server-side on every request, never trusted from the client.
Administrative accessPlatform-administrator access is a persisted, individually granted role. It is never derived from a client-supplied email address or header.
Audit loggingAuthentication, authorization, administrative, data-access and data-destruction events are written to an append-only audit log recording actor, action, resource, event category, source IP address and timestamp.

Encryption

ControlDetail
In transitTLS on every public endpoint. TLS 1.2 is the enforced minimum; TLS 1.3 is negotiated where the client supports it. Service-to-service traffic stays on the cluster’s private network.
At restAzure platform-managed AES-256 encryption across the PostgreSQL storage, the manuscript object storage and the cluster disks.
Per-project envelope encryptionManuscript bodies uploaded on or after 5 August 2026, 21:10 UTC are encrypted by PlotLens itself, in addition to the platform layer above, before the bytes reach storage. Each project gets its own key-encryption key in Azure Key Vault. The body is encrypted with AES-256-GCM under a data key belonging to that project, and the data key is stored only in wrapped form — unwrapping it is a call to the vault, and the key-encryption key’s private material never leaves the vault.
What that covers, and what it does notObjects written before 5 August 2026, 21:10 UTC are covered by the Azure platform-managed encryption above and nothing further. The cutover is deliberately forward-only: no re-encryption pass runs over older manuscripts, so read this control as applying from that date onward rather than retroactively.
Key protection levelSoftware-protected RSA-2048 keys in a Standard-SKU Azure Key Vault. This is not a hardware-security-module-backed or FIPS 140-3 validated key store, and PlotLens does not claim it as one. Customer-managed keys — your vault, your key — are not offered today.
SecretsApplication secrets and provider credentials are held in Azure Key Vault and projected into workloads at runtime. They are not committed to the repository and not baked into container images.

Two layers, stated separately on purpose. The Azure platform layer covers everything; the per-project envelope layer covers manuscript bodies written from the cutover date onward. Neither layer is independently attested — PlotLens holds no third-party certification or audit report, and nothing on this page should be read as external compliance attestation or FIPS coverage of these controls. If customer-managed keys are a requirement for your review, raise it before purchase.

Data residency

ScopeLocation
Application and primary dataAzure centralus (Iowa, United States). Application compute, the primary PostgreSQL database, the search index and manuscript object storage all live in this region.
BackupsGeo-redundant. PostgreSQL backups replicate to the Azure paired region, which is also within the United States.
AI inferenceThe Azure OpenAI resource is provisioned in centralus, but its model deployments use Azure’s Global Standard deployment type. Microsoft may therefore process an individual inference request in a data center outside the United States. Data the service stores at rest stays within the resource’s geography.
Marketing siteThis website is hosted separately from the product, on AWS us-east-1. It holds no customer content.
CompanyPlotLens is operated from the United States by Family Friendly, Inc. (Delaware, US).

If US-only inference is a hard requirement for your review, raise it before purchase — the Global Standard routing above is the honest position today, not a US-pinned guarantee.

Retention and deletion

DataRetentionMechanism
Documents and manuscriptsUntil you delete themDeleting a document removes it from the product immediately. The stored object is deleted, and every retained copy of it — the prior version kept by object versioning, then the soft-delete copy — expires automatically, the last of them within about 32 days.
Account, projects and story bibleLife of the accountDeleting your account removes your personal data and content within 30 days.
Project encryption keys (crypto-shredding)30-day grace periodDeleting your account also destroys the key-encryption key of every project you solely own. The key stops being usable immediately, and is permanently purged after a 30-day grace period. Reversal inside that window is not self-service — because deleting your account also deletes your sign-in identity, there is no longer an account you could sign in to. Email support from the address the account used, and once we have verified it is you, a PlotLens operator can cancel the destruction before the key is purged. That restores the keys only: you sign up again and we re-link ownership. Once the key is purged, manuscript bodies written on or after 5 August 2026, 21:10 UTC cannot be decrypted by anyone — including PlotLens, and including the copies inside disaster-recovery backups, which hold only the wrapped data key. Projects owned by a team are deliberately not shredded when one member leaves.
Database backups30 daysPoint-in-time backups roll off automatically on a rolling 30-day window. Backups cannot be selectively edited, so a deleted record persists inside them until the window passes.
Object-storage soft delete30 daysA deleted manuscript blob stays recoverable for 30 days as protection against accidental deletion, then is purged. Prior versions left by an overwrite expire within about a day and then run out the same 30-day tail.
Audit logsBeyond account deletionRetained where required for security and legal obligations. Audit records identify the actor and the action, not manuscript content.
Analytics eventsPer sub-processor policyConsent-gated, and carry no manuscript content.

Nothing you delete is recoverable through the product — deletion is immediate and permanent from your side. The 30-day windows above are disaster-recovery copies that expire automatically; they are whole-system snapshots, not a record-level restore anyone can reach into.

AI processing

QuestionAnswer
Who processes the text?Azure OpenAI Service, operated by Microsoft under PlotLens’s own Azure subscription.
Is my writing used for training?No. Your manuscripts are never used to train or fine-tune any model. Azure OpenAI does not train on customer content and does not share it with OpenAI.
Does the provider retain anything?Azure OpenAI may retain prompts and completions for up to 30 days as part of Microsoft’s abuse-monitoring process. Retained data is accessible only to authorized Microsoft reviewers and is not used for training. PlotLens has not applied for the Limited Access exemption that disables this retention.
What exactly is sent?Only what the requested operation needs: the passage under extraction or Manuscript Check, plus the relevant Story Bible context. Your email address and billing details are not sent to the model provider.
What about embeddings?Text is converted to vector embeddings for semantic search. The resulting vectors are stored in PlotLens’s own infrastructure in the primary region.
Do PlotLens staff read my work?Manuscript content is not routinely accessed by staff. Production data access is limited to named platform administrators and is audit-logged.

Sub-processors

Current as of 9 August 2026. These are the third parties that may process customer data on PlotLens’s behalf.

Sub-processorPurposeData receivedRegion
Microsoft AzureHosting: Kubernetes, PostgreSQL, blob storage, Key VaultAll customer content and account dataUS (centralus)
Azure OpenAI (Microsoft)Story element extraction and Manuscript CheckManuscript text submitted for processingUS (centralus)
ClerkAuthentication and identityEmail, name, authentication metadataUS
StripePaymentsBilling contact, payment method (held by Stripe)US
Microsoft commercial marketplaceSubscription billing for Marketplace purchasesSubscription and entitlement metadataUS
LoopsLifecycle and transactional emailEmail address, product usage eventsUS
GitHub (Microsoft)Support request trackingSupport request text and contact email you submitUS
SlackSupport request notificationsSupport request text you submit; no email addressUS
PostHogProduct analytics (consent-gated)Usage events, no manuscript contentUS
Google Analytics / Tag ManagerMarketing-site analytics (consent-gated)Marketing-site page views onlyUS
Microsoft ClarityMarketing-site heatmaps and session replay (consent-gated)Marketing-site interactions onlyUS
Amazon Web ServicesMarketing-site static hostingNo customer contentUS (us-east-1)

The analytics sub-processors load only after you accept analytics cookies, and they never receive manuscript content. The last row covers this marketing site, which is hosted separately from the product and holds no customer data.

Application security and SDLC

ControlHow it works
Dependency and secret scanningTrivy scans the repository for known vulnerabilities and for committed secrets on every change. Findings at HIGH or CRITICAL fail the build.
Container image scanningImages are built, scanned with Trivy, and pushed to the registry only if the scan passes — a vulnerable image never reaches the registry in the first place.
Infrastructure-as-code scanningTrivy’s configuration scanner checks the Terraform and Helm definitions for insecure defaults.
Static analysisSonarQube analyses every pull request. Ruff enforces a lint rule set on the Python codebase that includes security-relevant checks.
Change controlEvery change lands through a reviewed pull request against a protected branch, with automated review on each push. Nothing is deployed from a developer machine.
Environment separationDevelopment, staging and production run as separate environments with separate credentials, separate datastores and separate secret scopes.

Availability and resilience

ControlDetail
Uptime commitmentPlotLens does not offer a contractual uptime SLA on its self-serve plans. Uptime commitments are available only under a negotiated Enterprise agreement.
Database durabilityAzure Database for PostgreSQL Flexible Server, automated backups retained 30 days, geo-redundant replication of those backups to the Azure paired region.
Object durabilityManuscript blobs are versioned, so an overwrite preserves the prior version for about a day before it expires, and deleted blobs stay recoverable for 30 days.
MonitoringAzure Monitor alert rules cover API, worker, database and queue health. External synthetic probes run from multiple Microsoft agent locations against the application root and the API health endpoint.
Release safetyDeploy health is evaluated automatically after every release, and a build identifier is exposed on the health endpoint so the running version can be verified independently.
Status pageNot yet published. See the roadmap below.

Incident response

ControlDetail
DetectionAlert rules and external synthetic probes route to a notification channel monitored by the engineering team.
Breach notificationIf PlotLens confirms a personal-data breach affecting your data, we will notify affected customers without undue delay. Enterprise agreements can specify a fixed notification window.
Post-incidentRecurring root causes are written up in internal runbooks so a repeat failure is diagnosed against a known cause rather than from scratch.
Reporting an incidentEmail security@plotlens.ai.

Compliance and legal

TopicPosition
Our roleFor your manuscripts and account data, you are the controller and PlotLens is the processor. For this marketing site’s own analytics, PlotLens is the controller.
GDPRAccess, correction, deletion, export and objection rights are supported from account settings or by writing to privacy@plotlens.ai.
CCPA / CPRAPlotLens does not sell personal information and does not share it for cross-context behavioral advertising.
International transfersData is processed in the United States. Transfers from the EEA, UK and Switzerland rely on the EU Standard Contractual Clauses, supplied with the data processing agreement.
Data processing agreementAvailable on request from privacy@plotlens.ai.
Third-party attestationsPlotLens does not currently hold an independent third-party security certification, and has not commissioned an external security audit. This page exists so you can assess the controls that are actually in place, rather than infer them from a badge.
AgePlotLens is not intended for users under 16 years of age.

Vulnerability disclosure

TopicDetail
Where to reportEmail security@plotlens.ai. A machine-readable contact is published at /.well-known/security.txt.
AcknowledgementWe aim to acknowledge a report within three business days.
Safe harbourWe will not pursue legal action for good-faith research that respects user privacy, avoids degrading the service, and does not access or modify data belonging to others.
Bug bountyPlotLens does not currently run a paid bug-bounty program.

Enterprise

Requirements that fall outside the self-serve plans are handled as a private offer rather than a plan tier.

Dedicated and on-premises deployment

Where dedicated infrastructure, on-premises deployment or custom terms are required, PlotLens Enterprise is available as a private offer. Contact support@plotlens.ai.

Negotiated uptime commitments

Uptime commitments, service credits and support-response targets are agreed in an Enterprise contract. They are not offered on the self-serve plans.

Data processing agreement and SCCs

A data processing agreement incorporating the EU Standard Contractual Clauses is available on request from privacy@plotlens.ai.

Security questionnaires

Send your questionnaire to security@plotlens.ai. Most of it is answerable from the controls reference above; we will complete the rest and tell you plainly where the answer is “not yet”.

On the roadmap

Listed here precisely because it is not shipped. Nothing in this table is available today, and none of it is a contractual commitment.

ItemStatusTarget
SSO and SAMLNot implemented today. Planned for Enterprise agreements.Q4 2026
Public status pagePlanned. Availability is currently communicated by email.Not yet scheduled

Security questions?

Ask us anything about how we handle your work. If we cannot substantiate an answer, we will say so.