Privacy

Your data, mapped to the work.

This policy explains what PlugLayer receives, why it is needed, where agent and plugin data flows, and the controls available to you.

Scope and data roles

This Privacy Policy applies to PlugLayer websites, the customer portal, APIs, plugins, skills, MCP servers, command-line installers, deployment and infrastructure services, billing, and support. It applies when PlugLayer determines why and how account, platform-use, billing, security, or support data is processed.

When you deploy content or process information for your own users, you control that content and instruct PlugLayer to process it to provide the service. You are responsible for having the rights, notices, and lawful basis required for that content.

OpenAI, Codex, GitHub, identity providers, registries, DNS providers, and other services you connect have their own privacy practices. Their handling of data outside PlugLayer is governed by their policies.

Data we process

We receive information from you, workspace members, your browser or device, your PlugLayer-managed infrastructure, and connected services. The categories depend on the features you use.

Account and identity

Name, email, username, account identifiers, roles, workspace memberships, authentication records, sessions, and API or plugin-token metadata.

Projects and customer content

Projects, apps, databases, domains, environment configuration, compose files, registries, deployment instructions, and other content you submit to operate the service.

Compute and operations

Node details, capacity, network addresses, workload placement, runtime metrics, task state, logs, and infrastructure events needed to deploy and troubleshoot apps.

Plugin and agent activity

Tool names, parameters, responses, timestamps, correlation identifiers, errors, and the minimum project or app context needed to complete an MCP or agent request.

Billing

Stripe customer, checkout, subscription, invoice, and payment-status identifiers. PlugLayer does not store complete payment-card numbers.

Usage, device, and support

IP address, user agent, request metadata, security events, feedback, page context, attachments, support messages, and product preferences.

Sensitive values

Do not place secrets or unnecessary personal data in prompts, source files, environment variables, logs, tool arguments, feedback, or attachments. PlugLayer may need to process credentials that you deliberately configure for deployment, but product responses are designed not to return stored secret values.

Plugins, skills, agents, and MCP

The PlugLayer Codex plugin packages local skills and launches a local stdio MCP client. Skills can guide Codex to inspect repository files or run local commands when you ask it to do so. Installing the plugin does not, by itself, upload your repository to PlugLayer.

When you invoke a PlugLayer tool, the MCP client sends the authenticated request and the data needed for that operation to PlugLayer APIs. This can include project or app identifiers, deployment configuration, selected source content, task status, logs, domain details, feedback, and other values you intentionally provide to the tool.

The installer can save your PlugLayer API token locally in ~/.pluglayer/credentials.env with owner-only file permissions. The token is sent to PlugLayer as an authorization credential when a tool calls the API. PlugLayer stores issued plugin tokens in protected form and does not intentionally include token values in tool responses or logs.

Your AI host may process prompts, repository context, tool calls, and tool results under its own terms. PlugLayer receives only the content sent through PlugLayer requests or otherwise submitted directly to the service.

How we use data

  • Provide accounts, projects, apps, compute, data, domains, deployments, plugins, billing, and support.
  • Authenticate users and tokens, enforce ownership and permissions, and keep audit records.
  • Process requested tool and agent workflows, including read and write operations you approve.
  • Secure the platform, prevent abuse and fraud, diagnose failures, and measure reliability and capacity.
  • Meet legal obligations, enforce our terms, handle disputes, and protect rights and safety.

Depending on the context and applicable law, we rely on performance of a contract, legitimate interests, legal obligations, or consent. Where consent is required, you may withdraw it without affecting processing that was lawful before withdrawal.

Service providers, integrations, and transfers

We disclose data only as needed to infrastructure, identity, payment, registry, DNS, monitoring, backup, communications, support, security, and professional-service providers; to workspace members according to their role; or to authorities when legally required.

Deployment instructions may send content to the compute, registry, domain, repository, or integration you select. Stripe processes payment-card entry under its own terms, while PlugLayer receives billing identifiers and status.

Providers may process data outside your country. Where required, we use an adequacy decision, approved contractual safeguards, or another lawful transfer mechanism. We do not sell personal information or share it for cross-context behavioral advertising.

How long we keep data

Account and service data is generally kept while your account or relevant resource is active. Operational records, logs, archived resources, and backup copies may remain for a limited period afterward for recovery, security, troubleshooting, billing, disputes, and legal obligations.

Authentication sessions can last up to seven days. First-party appearance and interface preference cookies can last up to one year unless you reset them or clear browser storage. Retention can be extended when needed to preserve evidence, comply with law, or protect users and the service.

How we protect data

PlugLayer uses encrypted transport, authentication, ownership and role checks, scoped tokens, restricted administrative access, private authenticated downloads, infrastructure isolation, security headers, monitoring, and secret-handling controls appropriate to the service.

No service is completely secure. Keep credentials confidential, use least-privilege tokens, review agent-requested changes before approval, and rotate any credential that may have been exposed. If a breach creates a legally reportable risk, we will notify affected people and regulators as required.

Your choices and privacy rights

Depending on where you live, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent. You may also complain to your local data-protection authority. We do not discriminate against users for exercising applicable privacy rights.

Requests may require identity verification. We may retain information where necessary for billing, security, fraud prevention, legal obligations, disputes, or the rights of others. You can also revoke API or plugin tokens and remove resources through the available PlugLayer controls, subject to resource cleanup and retention requirements.

Children and policy changes

PlugLayer is intended for adults and business users, not children under 18. We do not knowingly collect personal data from children through the service.

We may update this policy when our product, plugins, providers, or legal requirements change. We will post the updated policy here and change the effective date. Material changes may also be communicated through the service or your account contact details.

Contact PlugLayer about privacy

Email privacy@pluglayer.com with the subject “Privacy request.” For product support or operational feedback, use the Feedback area in the PlugLayer portal or email hello@pluglayer.com.

These public terms work together with our Terms of Service.