Skip to content
Plinta.

Privacy Policy

Last updated August 5, 2026

Plinta holds bid documents and approval records that end up in contract disputes, so this page is specific: what we hold, exactly which vendors it reaches and why, how long it lives, and what never happens to it.

What we hold, and about whom

Customer teams: your name, work email, and role; the documents your organization uploads and the text extracted from them; the register, revisions, comments, and attachments your team creates; and an append-only audit trail of who changed what, when.

External reviewers: if a customer sends you a transmittal, we hold your name, email address, and — for each action you take on a review link — timestamp, IP address, and browser user agent. Construction disputes turn on who approved what and when; this record is the evidence, we say so openly, and it is retained with the audit trail.

Usage and billing metadata: pages processed, job costs, plan state. Card details go to Stripe directly and never touch our systems.

What we do with it — and what we never do

We use this data to run the product, bill for it, secure it, and support you. That is the list.

We do not sell data, share it for advertising, or run third-party analytics or tracking scripts — the application sets exactly two kinds of cookie, both essential: your sign-in session and which organization you have open. We do not train AI models on your content, and we restrict production AI providers to ones whose terms exclude training on it, enforced by a startup check in the processing worker rather than by policy. The security page describes this in the same words a vendor questionnaire would ask for.

Every vendor that touches data

The complete list, current as of the date above. Every entry below runs in production today; a vendor we have built against but not turned on would appear here labelled “Not enabled” rather than omitted.

Supabase (on AWS, US region)
Database, authentication, file storage. All customer data, encrypted at rest and in transit.
Vercel
Serves the web application. Request traffic; documents live in storage, not on the web host.
Railway
Runs the document-processing worker. Document text while a processing job runs.
Anthropic
AI extraction, compliance analysis, addendum diffing. Specification and product-data text (not files). Commercial terms exclude training on customer content, and the worker refuses to start in production against any provider whose terms do not..
Stripe
Billing. Billing contact and payment details — card data never touches our systems.
Resend
Transactional email. Recipient addresses; transmittal subjects and messages.
Cloudflare Turnstile
Bot protection on sign-in, sign-up, and external review submissions. A browser check on those pages only.
Sentry
Error monitoring. Error reports with identifiers, never document contents — content fields are scrubbed in code before anything is sent.

How long data lives

While your account is active: as long as you keep it. When you delete a document, project, or organization: gone from every path immediately, hard-purged after a 14-day undo window, and out of backups within 30 days as they age out.

What survives deletion, disclosed rather than discovered: append-only audit records — including the name labels of deleted accounts, so the history of organizations you worked with stays readable — and the business records billing law requires.

Where it lives

A single US region, with provider-managed encryption keys. Data-region choice and customer-managed keys are enterprise work we have not built; the security page tracks both honestly.

Your choices

You can read, correct, and export your data from the app — each project’s register exports to Excel — and organization owners control invitations, roles, and deletion for their workspace. For anything the app cannot yet do itself (a full account-data export, correction of audit metadata, deletion questions), contact us and we will do it manually during the retention windows above.

Where Plinta processes documents on behalf of a customer organization, that organization controls the data and we act on its instructions — requests about a workspace’s contents go to its owner, and we route misdirected ones there.

Changes to this policy

Material changes are emailed to account owners before they take effect. The vendor table above changes only with notice: adding a processor that would see customer data is exactly the kind of change notice exists for.

Reaching us

Privacy questions and requests: support@getplinta.app.