Trust

Security

Plainpaper holds your marketing work, so it is fair to ask how that work is protected. This page says how, in the same plain terms as our privacy policy, and tells you how to reach us if you find something wrong.

Last updated: 28 August 2026.

Where your data lives

Your account, your content and your uploaded files are stored in the EU. Traffic to and from the service is encrypted in transit. The full list of processors behind the service, what each one does and where it operates, is published in the privacy policy.

Workspace isolation

Workspaces are isolated from one another in the database as well as in the application code: every read and write is filtered by workspace membership before it reaches your data. A bug in our application code cannot hand one customer another customer's boards, because the database refuses the query first.

Accounts and credentials

Passwords are stored only as cryptographic hashes, never in readable form. Signing in with Google is limited to the email and profile scopes, described in full in the privacy policy. Card details are handled by Stripe and never touch our systems.

Agent access

An AI assistant reaches Plainpaper either by signing in from the assistant itself or with an agent token you issue from the app. Both are scoped to a workspace, both can be revoked from the Agents page at any time, and a token's secret half is never written to a log or returned by a tool. The connector receives only the tool calls an assistant makes, never your conversation; that boundary is spelled out in the privacy policy.

Plainpaper holds no credentials for the platforms you market on and has no tool that sends, publishes or deletes on an outside platform. When work ships, it ships through that platform's own integration, initiated by your agent after your approval. A compromised board could embarrass you; it could not empty your ad account.

Uploaded files

Uploaded assets are private by default and served only through short-lived signed links. There is no permanent public URL for your files.

Backups and deletion

We keep backups so a fault does not cost you your work. When you delete your account, your content is removed from the live service immediately and from backups within 90 days, on the schedule in the privacy policy.

Reporting a vulnerability

If you believe you have found a security problem in Plainpaper, tell us before telling anyone else: [email protected] with "Security" in the subject line. Describe what you found, the steps to reproduce it, and what you think an attacker could do with it. We will acknowledge your report within three business days and keep you informed while we fix it.

We ask for coordinated disclosure: give us reasonable time to fix the problem before publishing it. In return, we will not take legal action over research conducted in good faith that respects other customers' data, avoids service disruption, and stays within the account you tested with.

Machine-readable details live at /.well-known/security.txt, per RFC 9116.

What to report elsewhere

Vulnerabilities in the platforms we build on, listed as processors in the privacy policy, belong with those vendors' own security programmes. Volumetric denial-of-service findings, spam, and social engineering of our team are outside the scope of what we can reward with anything but gratitude, and testing them causes the disruption this page asks you to avoid.

  • Privacy policy: what is collected, why, where it lives, and the rights you have over it.
  • Terms of service: the agreement behind your account, your content, and billing.
  • Approvals & control: what a connected agent may do alone and what needs a human click.
  • FAQ & troubleshooting: connection issues, approval blockers, and how data isolation works day to day.