Privacy & Security

Your data stays yours.

PLUMdata reads your Google Drive files in session, only to name and organise them, and keeps nothing once that session ends. We dont sell your data, we dont train AI on it, we dont serve ads, and no human at PLUMdata reads it. Our use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements — and is designed around GDPR and CCPA.

The short version

Session-only processing
File content lives in memory only and is discarded when your session ends
Limited Use, always
Google data is used only to power the naming and organising you can see — never ads, never resale
No AI training on your data
Your files are never used to train, fine-tune or evaluate any AI model
Nothing changes without you
Every suggestion is shown for review; every applied change reverses in one click

Our Limited Use commitment

This is the heart of how we treat your Google data, stated plainly and up front.

PLUMdatas use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What Limited Use means here

We use Google data only to provide the user-facing features you connect for: naming and organising your files
We do not use or transfer your data to serve advertising of any kind
We do not sell your data or transfer it to third parties, except as needed to run the service or comply with law
No human reads your data, except with your explicit consent, for security, to comply with law, or when anonymised
We never use your data to develop, train or improve generalised AI or machine-learning models

The data lifecycle inside PLUMdata

Here is the exact sequence from sign-in through to session end. No gaps, no vague language.

Step by step

You connect your Drive

You sign in through Googles own authorisation flow and choose what PLUMdata may scan. We never see your password — only a temporary access token, held in an encrypted session cookie and never written to a database on our side.
Temporary token only

Metadata analysis

PLUMdata reads your file names, folder names and structure — the descriptive metadata of your estate. Where a name alone isnt enough context, it reads the identifying signals inside a file — a documents headings, a spreadsheets columns, a photos subject — to classify what it is. All of this is handled in memory and never written to disk.
Processed in memory, never stored

Suggestions generated

The extracted signals are processed by our AI provider to generate naming suggestions, folder groupings, duplicate and stale-file flags, and sensitivity labels — all aligned to the convention you set. Your data is not used to train, fine-tune or evaluate any model. Once a suggestion is generated, the input is discarded.
Zero AI training on your data

You review every change

Every suggested rename and move is presented for your review. Approve, skip, edit or bulk apply — nothing in your Drive changes until you explicitly approve it, and every change is applied in place through Googles official API, preserving permissions and version history. PLUMdata cannot delete your files: the capability does not exist in the code.

Session data discarded

When your session ends, every piece of Drive content we processed — file names, extracted signals, folder structure — is permanently discarded from our systems. We retain only your email address and a record of your payment.
Deleted on session end

The Google access we request, and why

When you connect, Google shows you a consent screen. PLUMdata requests the Google Drive scope a restricted scope and here is exactly what it powers and what it does not.

Google Drive Restricted scope

The drive scope lets PLUMdata read file names, folder structure and — where needed — the identifying content of the files you choose to scan, and write back the renames, folder moves and private index you approve. We request it because our core, prominent feature is bringing the files you already have under a standard. Narrower scopes such as drive.file only expose files the app itself created, which cannot deliver that.

Your email & basic profile Requested

The openid, email and profile scopes identify your account and let us send payment receipts. Nothing more.

Email, calendar, contacts, other services Not requested

PLUMdata only touches your file storage. We never request access to Gmail, Calendar, Contacts or any other Google service.
You can revoke PLUMdatas access at any time from your Google account permissions, or with the button further down this page. Either immediately ends our ability to read or modify anything.

What we never do, and always do

Never

Store the content of your files once your session ends
Use your data to serve or target advertising
Train, fine-tune or evaluate AI on your data
Sell, broker or transfer your data to third parties
Let a human read your files, outside the narrow, policy-permitted cases
Access anything beyond your file storage — no email, calendar or contacts
Apply any change to your Drive without your approval

Always

Use Google data only to power the features you can see
Show every proposed change before it is applied
Provide one-click undo for any applied change
Encrypt your data in transit and at rest
Discard session data the moment your session ends
Let you export everything, or revoke access, self-service
Respond to data requests within 48 hours

What we actually store

A short list. Everything about your files lives in your own Drive, not on ours.

Your email address Stored

Used to identify your account and send payment receipts. Never shared or sold.

Payment records Via Stripe

Payment processing is handled by Stripe. We keep a record of transactions (amount, date, file count) for receipts. Card details are never held by PLUMdata.

A one-way free-tier marker Hashed

A salted, one-way hash of your email, kept only to record that your one-time free allowance has been used so it cant be reset by deleting and re-creating an account. It contains no readable personal data and is the one record that deliberately survives account deletion.

Anonymised error events ~90 days

To keep the service reliable we log technical errors to Sentry, keyed by an opaque session ID and containing no file content. They auto-expire after roughly 90 days.

Your convention, index, audit log & usage In your Drive

The naming convention you set, the private index of what your Drive contains, the audit log of changes and your usage record are stored as plain JSON in your own Google Drive — not on PLUMdata servers. You can open or delete them directly, with or without us.

File names, folder names, document content Not stored

Processed in memory during your session only. Gone when youre done.

How we keep it secure

Security is verified, not just asserted. PLUMdata is built to the controls required for Googles restricted-scope handling and is independently assessed under the App Defense Alliances Cloud Application Security Assessment (CASA) framework.

Encryption everywhere In transit & at rest

All traffic is served over TLS. The limited data we hold — your email, payment record — is encrypted at rest by our infrastructure providers.

Tokenised access, no password, no token warehouse By design

We authenticate through Googles OAuth flow and never see your password. Your access token lives in an encrypted session cookie and is never persisted to a database on our side.

Least-privilege, in-place operations By design

Changes are made through Googles official Drive API, in place, preserving each files location, permissions and version history. Deletion of your files is not implemented at all.

Independent security assessment CASA

PLUMdata undergoes the App Defense Alliance CASA assessment required for apps using restricted Google scopes, verifying secure handling of Google user data against a recognised application-security standard.

Vulnerability disclosure security@plumdata.io

Found something? Report it to security@plumdata.io. We investigate promptly and wont pursue good-faith researchers who follow coordinated disclosure.

Who we share data with

The complete list of service providers that process data on our behalf. Each is bound to use it only to provide their service to us never for their own purposes.

Google Drive API & sign-in

Your storage provider and identity provider. PLUMdata reads and writes files you approve through Googles API.

Anthropic AI processing

Generates naming suggestions from the extracted signals. Contractually barred from training on or retaining your data.

Stripe Payments

Processes payments. PCI-DSS compliant. Card details never reach PLUMdata.

Vercel Hosting

Runs the application. No Drive file content is stored on its infrastructure.

Sentry Error monitoring

Receives anonymised technical error events, keyed by opaque session ID, with no file content. Auto-expire after ~90 days.

Your data, your control

If youre signed in you can download everything PLUMdata holds or controls about you, or revoke our access and delete your record no email required.

Download your data

A single JSON bundle with your naming convention, usage record, audit log, and index summary all read live from your own Drive.

Delete my account

Revokes PLUMdatas access to your Drive and deletes any Stripe customer record we hold. We retain only a one-way hashed marker that your free allowance was used no readable personal data so the free tier cant be reset by re-registering. Your own Drive files are untouched.
All four items in the download convention, usage, audit log, and index also live as plain JSON files in your own Drive (appDataFolder and root). You can open them directly from Drive at any time, with or without PLUMdata. Under GDPR and CCPA you also have the right to access, correct, port and erase your data; email privacy@plumdata.io and well action any request within 48 hours. The only thing we retain after erasure is the one-way free-tier marker described above, kept for abuse prevention under our legitimate interest.

Questions we get asked

Only what it needs to name a file. If a name like “New Document (3)” gives no context, PLUMdata reads the identifying signals — a document’s headings, a spreadsheet’s column names, a photo’s subject — to work out what the file is. It never reads a file the way a person would, that content is handled in memory, and nothing it reads is stored, logged or retained.
Last updated July 2026 · PLUMdata. Questions: privacy@plumdata.io

Ready to secure and organise your data workspace?