Your manuscripts stay private.
Your draft is the most personal thing you own. We built PlotLens so that trusting us with it is a decision you can check, not one you have to take on faith.
Never used for AI training. Yours to export. Yours to delete.
Reviewing PlotLens for your organization?Skip to the controls reference. Last reviewed 9 August 2026.
The three things that matter most
Your work is never training data
We never use your manuscripts, characters or worlds to train or fine-tune AI models, and neither does the model provider we run on. Your book stays your book.
Encrypted, and walled off from everyone else
Encrypted with TLS on the way to us and AES-256 once it lands. Every query the application makes is locked to your account at the database level, so another customer cannot reach your pages even by accident.
Leaving is as easy as arriving
Export everything whenever you like. Delete a document, a project or your whole account from settings and it is gone from the product at once; the disaster-recovery copies behind it expire within 30 days.
For security reviewers
Controls reference
Everything below describes what is in place today, not what is planned. Where a control does not exist yet, it says so. Anything genuinely planned is in the roadmap at the foot of this page.
Tenant isolation and access management
| Control | How it works |
|---|---|
| Tenant data isolation | PostgreSQL row-level security. Every application query runs inside a database session bound to a single tenant, so a query cannot return another tenant’s rows even if application code asks for them. |
| Background processing | Background workers connect with a separate, scoped database role rather than the application role. That role is not reachable from a user-facing request path. |
| Authentication | Delegated to Clerk. PlotLens never stores account passwords. Sessions are short-lived signed tokens, verified at the API gateway on every request before any application code runs. |
| Authorization | Four team roles — owner, admin, editor and viewer — map to read, write, delete, invite and administrative permissions. Membership and role are evaluated server-side on every request, never trusted from the client. |
| Administrative access | Platform-administrator access is a persisted, individually granted role. It is never derived from a client-supplied email address or header. |
| Audit logging | Authentication, authorization, administrative, data-access and data-destruction events are written to an append-only audit log recording actor, action, resource, event category, source IP address and timestamp. |
Encryption
| Control | Detail |
|---|---|
| In transit | TLS on every public endpoint. TLS 1.2 is the enforced minimum; TLS 1.3 is negotiated where the client supports it. Service-to-service traffic stays on the cluster’s private network. |
| At rest | Azure platform-managed AES-256 encryption across the PostgreSQL storage, the manuscript object storage and the cluster disks. |
| Per-project envelope encryption | Manuscript bodies uploaded on or after 5 August 2026, 21:10 UTC are encrypted by PlotLens itself, in addition to the platform layer above, before the bytes reach storage. Each project gets its own key-encryption key in Azure Key Vault. The body is encrypted with AES-256-GCM under a data key belonging to that project, and the data key is stored only in wrapped form — unwrapping it is a call to the vault, and the key-encryption key’s private material never leaves the vault. |
| What that covers, and what it does not | Objects written before 5 August 2026, 21:10 UTC are covered by the Azure platform-managed encryption above and nothing further. The cutover is deliberately forward-only: no re-encryption pass runs over older manuscripts, so read this control as applying from that date onward rather than retroactively. |
| Key protection level | Software-protected RSA-2048 keys in a Standard-SKU Azure Key Vault. This is not a hardware-security-module-backed or FIPS 140-3 validated key store, and PlotLens does not claim it as one. Customer-managed keys — your vault, your key — are not offered today. |
| Secrets | Application secrets and provider credentials are held in Azure Key Vault and projected into workloads at runtime. They are not committed to the repository and not baked into container images. |
Two layers, stated separately on purpose. The Azure platform layer covers everything; the per-project envelope layer covers manuscript bodies written from the cutover date onward. Neither layer is independently attested — PlotLens holds no third-party certification or audit report, and nothing on this page should be read as external compliance attestation or FIPS coverage of these controls. If customer-managed keys are a requirement for your review, raise it before purchase.
Data residency
| Scope | Location |
|---|---|
| Application and primary data | Azure centralus (Iowa, United States). Application compute, the primary PostgreSQL database, the search index and manuscript object storage all live in this region. |
| Backups | Geo-redundant. PostgreSQL backups replicate to the Azure paired region, which is also within the United States. |
| AI inference | The Azure OpenAI resource is provisioned in centralus, but its model deployments use Azure’s Global Standard deployment type. Microsoft may therefore process an individual inference request in a data center outside the United States. Data the service stores at rest stays within the resource’s geography. |
| Marketing site | This website is hosted separately from the product, on AWS us-east-1. It holds no customer content. |
| Company | PlotLens is operated from the United States by Family Friendly, Inc. (Delaware, US). |
If US-only inference is a hard requirement for your review, raise it before purchase — the Global Standard routing above is the honest position today, not a US-pinned guarantee.
Retention and deletion
| Data | Retention | Mechanism |
|---|---|---|
| Documents and manuscripts | Until you delete them | Deleting a document removes it from the product immediately. The stored object is deleted, and every retained copy of it — the prior version kept by object versioning, then the soft-delete copy — expires automatically, the last of them within about 32 days. |
| Account, projects and story bible | Life of the account | Deleting your account removes your personal data and content within 30 days. |
| Project encryption keys (crypto-shredding) | 30-day grace period | Deleting your account also destroys the key-encryption key of every project you solely own. The key stops being usable immediately, and is permanently purged after a 30-day grace period. Reversal inside that window is not self-service — because deleting your account also deletes your sign-in identity, there is no longer an account you could sign in to. Email support from the address the account used, and once we have verified it is you, a PlotLens operator can cancel the destruction before the key is purged. That restores the keys only: you sign up again and we re-link ownership. Once the key is purged, manuscript bodies written on or after 5 August 2026, 21:10 UTC cannot be decrypted by anyone — including PlotLens, and including the copies inside disaster-recovery backups, which hold only the wrapped data key. Projects owned by a team are deliberately not shredded when one member leaves. |
| Database backups | 30 days | Point-in-time backups roll off automatically on a rolling 30-day window. Backups cannot be selectively edited, so a deleted record persists inside them until the window passes. |
| Object-storage soft delete | 30 days | A deleted manuscript blob stays recoverable for 30 days as protection against accidental deletion, then is purged. Prior versions left by an overwrite expire within about a day and then run out the same 30-day tail. |
| Audit logs | Beyond account deletion | Retained where required for security and legal obligations. Audit records identify the actor and the action, not manuscript content. |
| Analytics events | Per sub-processor policy | Consent-gated, and carry no manuscript content. |
Nothing you delete is recoverable through the product — deletion is immediate and permanent from your side. The 30-day windows above are disaster-recovery copies that expire automatically; they are whole-system snapshots, not a record-level restore anyone can reach into.
AI processing
| Question | Answer |
|---|---|
| Who processes the text? | Azure OpenAI Service, operated by Microsoft under PlotLens’s own Azure subscription. |
| Is my writing used for training? | No. Your manuscripts are never used to train or fine-tune any model. Azure OpenAI does not train on customer content and does not share it with OpenAI. |
| Does the provider retain anything? | Azure OpenAI may retain prompts and completions for up to 30 days as part of Microsoft’s abuse-monitoring process. Retained data is accessible only to authorized Microsoft reviewers and is not used for training. PlotLens has not applied for the Limited Access exemption that disables this retention. |
| What exactly is sent? | Only what the requested operation needs: the passage under extraction or Manuscript Check, plus the relevant Story Bible context. Your email address and billing details are not sent to the model provider. |
| What about embeddings? | Text is converted to vector embeddings for semantic search. The resulting vectors are stored in PlotLens’s own infrastructure in the primary region. |
| Do PlotLens staff read my work? | Manuscript content is not routinely accessed by staff. Production data access is limited to named platform administrators and is audit-logged. |
Sub-processors
Current as of 9 August 2026. These are the third parties that may process customer data on PlotLens’s behalf.
| Sub-processor | Purpose | Data received | Region |
|---|---|---|---|
| Microsoft Azure | Hosting: Kubernetes, PostgreSQL, blob storage, Key Vault | All customer content and account data | US (centralus) |
| Azure OpenAI (Microsoft) | Story element extraction and Manuscript Check | Manuscript text submitted for processing | US (centralus) |
| Clerk | Authentication and identity | Email, name, authentication metadata | US |
| Stripe | Payments | Billing contact, payment method (held by Stripe) | US |
| Microsoft commercial marketplace | Subscription billing for Marketplace purchases | Subscription and entitlement metadata | US |
| Loops | Lifecycle and transactional email | Email address, product usage events | US |
| GitHub (Microsoft) | Support request tracking | Support request text and contact email you submit | US |
| Slack | Support request notifications | Support request text you submit; no email address | US |
| PostHog | Product analytics (consent-gated) | Usage events, no manuscript content | US |
| Google Analytics / Tag Manager | Marketing-site analytics (consent-gated) | Marketing-site page views only | US |
| Microsoft Clarity | Marketing-site heatmaps and session replay (consent-gated) | Marketing-site interactions only | US |
| Amazon Web Services | Marketing-site static hosting | No customer content | US (us-east-1) |
The analytics sub-processors load only after you accept analytics cookies, and they never receive manuscript content. The last row covers this marketing site, which is hosted separately from the product and holds no customer data.
Application security and SDLC
| Control | How it works |
|---|---|
| Dependency and secret scanning | Trivy scans the repository for known vulnerabilities and for committed secrets on every change. Findings at HIGH or CRITICAL fail the build. |
| Container image scanning | Images are built, scanned with Trivy, and pushed to the registry only if the scan passes — a vulnerable image never reaches the registry in the first place. |
| Infrastructure-as-code scanning | Trivy’s configuration scanner checks the Terraform and Helm definitions for insecure defaults. |
| Static analysis | SonarQube analyses every pull request. Ruff enforces a lint rule set on the Python codebase that includes security-relevant checks. |
| Change control | Every change lands through a reviewed pull request against a protected branch, with automated review on each push. Nothing is deployed from a developer machine. |
| Environment separation | Development, staging and production run as separate environments with separate credentials, separate datastores and separate secret scopes. |
Availability and resilience
| Control | Detail |
|---|---|
| Uptime commitment | PlotLens does not offer a contractual uptime SLA on its self-serve plans. Uptime commitments are available only under a negotiated Enterprise agreement. |
| Database durability | Azure Database for PostgreSQL Flexible Server, automated backups retained 30 days, geo-redundant replication of those backups to the Azure paired region. |
| Object durability | Manuscript blobs are versioned, so an overwrite preserves the prior version for about a day before it expires, and deleted blobs stay recoverable for 30 days. |
| Monitoring | Azure Monitor alert rules cover API, worker, database and queue health. External synthetic probes run from multiple Microsoft agent locations against the application root and the API health endpoint. |
| Release safety | Deploy health is evaluated automatically after every release, and a build identifier is exposed on the health endpoint so the running version can be verified independently. |
| Status page | Not yet published. See the roadmap below. |
Incident response
| Control | Detail |
|---|---|
| Detection | Alert rules and external synthetic probes route to a notification channel monitored by the engineering team. |
| Breach notification | If PlotLens confirms a personal-data breach affecting your data, we will notify affected customers without undue delay. Enterprise agreements can specify a fixed notification window. |
| Post-incident | Recurring root causes are written up in internal runbooks so a repeat failure is diagnosed against a known cause rather than from scratch. |
| Reporting an incident | Email security@plotlens.ai. |
Compliance and legal
| Topic | Position |
|---|---|
| Our role | For your manuscripts and account data, you are the controller and PlotLens is the processor. For this marketing site’s own analytics, PlotLens is the controller. |
| GDPR | Access, correction, deletion, export and objection rights are supported from account settings or by writing to privacy@plotlens.ai. |
| CCPA / CPRA | PlotLens does not sell personal information and does not share it for cross-context behavioral advertising. |
| International transfers | Data is processed in the United States. Transfers from the EEA, UK and Switzerland rely on the EU Standard Contractual Clauses, supplied with the data processing agreement. |
| Data processing agreement | Available on request from privacy@plotlens.ai. |
| Third-party attestations | PlotLens does not currently hold an independent third-party security certification, and has not commissioned an external security audit. This page exists so you can assess the controls that are actually in place, rather than infer them from a badge. |
| Age | PlotLens is not intended for users under 16 years of age. |
Vulnerability disclosure
| Topic | Detail |
|---|---|
| Where to report | Email security@plotlens.ai. A machine-readable contact is published at /.well-known/security.txt. |
| Acknowledgement | We aim to acknowledge a report within three business days. |
| Safe harbour | We will not pursue legal action for good-faith research that respects user privacy, avoids degrading the service, and does not access or modify data belonging to others. |
| Bug bounty | PlotLens does not currently run a paid bug-bounty program. |
Enterprise
Requirements that fall outside the self-serve plans are handled as a private offer rather than a plan tier.
Dedicated and on-premises deployment
Where dedicated infrastructure, on-premises deployment or custom terms are required, PlotLens Enterprise is available as a private offer. Contact support@plotlens.ai.
Negotiated uptime commitments
Uptime commitments, service credits and support-response targets are agreed in an Enterprise contract. They are not offered on the self-serve plans.
Data processing agreement and SCCs
A data processing agreement incorporating the EU Standard Contractual Clauses is available on request from privacy@plotlens.ai.
Security questionnaires
Send your questionnaire to security@plotlens.ai. Most of it is answerable from the controls reference above; we will complete the rest and tell you plainly where the answer is “not yet”.
On the roadmap
Listed here precisely because it is not shipped. Nothing in this table is available today, and none of it is a contractual commitment.
| Item | Status | Target |
|---|---|---|
| SSO and SAML | Not implemented today. Planned for Enterprise agreements. | Q4 2026 |
| Public status page | Planned. Availability is currently communicated by email. | Not yet scheduled |
Security questions?
Ask us anything about how we handle your work. If we cannot substantiate an answer, we will say so.