Privacy
Your workspace is your business’s. This page says what we hold, where it is stored, who else touches it, and how to get it back. Last updated 17 September 2026.
What we hold
Two things. The first is your workspace: the apps, tables, automations, documents, messages, files and records you and your team put into Plyxl. The second is your account: your name, your email address, the workspace you belong to, your plan, and the ordinary logs a service keeps to stay up and to bill correctly, such as timestamps, IP addresses and error traces.
We do not buy data about you, and we do not sell or rent what you give us.
Where it is stored
Everything in your workspace lives in a managed Postgres database and object store run by Supabase, hosted on Amazon Web Services in us-east-1, Northern Virginia, United States. It is encrypted in transit with TLS and encrypted at rest on disk. Each row is scoped to a workspace, so one workspace cannot read another’s.
If you need your data held in a particular country or region, that is a Business plan conversation. Write to us and we will tell you plainly whether we can do it.
The tools you connect
When you connect Gmail, a calendar, a CRM or anything else, you grant Plyxl a set of permissions through that provider’s own consent screen. We store the resulting access token, encrypted at rest, and use it only to do the work you or your agent asks for inside those permissions. We do not read beyond the scopes you granted, and we do not copy an entire account across unless you ask us to sync it.
Disconnect a tool at any time and we delete its tokens. You can also revoke Plyxl from the provider’s side, which cuts our access immediately.
The agent and AI models
When you ask the agent to do something, your instruction and the workspace content needed to answer it are sent to OpenAI’s API to produce the response. OpenAI does not use data submitted through its API to train its models, and neither do we. We do not train any model on your workspace, and we do not use your content to improve the product for anyone else.
Who else processes it
These are the companies that handle data on our behalf. Each is bound by a data processing agreement and each is used for the one job listed.
- SupabaseDatabase, file storage and sign-inAWS us-east-1, United States
- OpenAIThe models behind the agentUnited States
- ComposioThe connections to your other toolsUnited States
- Apple (APNs)Push notifications to the mobile appUnited States
- CloudflareServing plyxl.comGlobal edge network
- PostHogVisits to plyxl.com, not workspace dataUnited States
How long we keep it
Workspace data is kept while your account is open. Delete something and it goes from the live database; encrypted backups roll off within 30 days. Close your account, or write to us asking for deletion, and we remove the workspace within 30 days, except where we must keep an invoice or a record to satisfy tax or accounting law.
Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. If you are in the UK, the EU or the EEA, you have those rights under the GDPR; if you are in California, you have them under the CCPA. Either way the route is the same: email hello@plyxl.com and we will answer within 30 days.
Cookies
The app sets the cookies needed to keep you signed in. This marketing site uses PostHog to count visits and see which headline works better; it never sees anything inside a workspace.
Security
TLS everywhere, encryption at rest, access to production limited to the people who need it, and workspace isolation enforced in the database rather than only in the application. If you believe you have found a vulnerability, write to hello@plyxl.com and we will treat it as the first thing we do that day.
Changes
If this policy changes in a way that matters, we will update the date at the top of this page and tell account owners by email before it takes effect.
Contact
Plyxl, hello@plyxl.com. Our team reads that inbox.