Privacy
Updated · September 19, 2026
Privacy, in plain language.
The short version: Pluribus collects what it needs to run your workspace and nothing else. We don’t sell personal information, run ads, or train models on your data. Google data is used only for the feature you connected it for. You can export or delete what we hold at any time.
01Who this covers.
This policy covers trypluribus.com, the Pluribus workspace, the Pluribus ComfyUI plugin, and our documentation site. It applies to account holders, people invited to a workspace or asked to accept terms, people whose details or likeness a workspace records, and visitors.
For the content a workspace puts into Pluribus (its media, documents, and the people details it records), the organization that owns the workspace decides what is collected and why, and Pluribus processes it on that organization’s behalf. For account, contact, and site data, Pluribus is the responsible party. A data processing agreement is available to any workspace on request.
02What we collect.
We collect information you give us, information a workspace records about you, and a small amount of technical data generated when the service is used. We do not buy personal information from data brokers.
Account and sign-in
Your email address for one-time sign-in links, or your name, email address, and profile picture from Google if you choose Google sign-in. We never see or store your Google password.
Onboarding and contact
Name, role, organization, work email, and anything you write in a notes field or send us by email.
Invites and acceptances
The recipient email you enter, the context attached to the invite, and the terms and scope a person accepts or declines, with the time, IP address, and browser recorded as evidence of that decision.
People and consent records
Names, representative contacts, and the consent grants connected to a person’s likeness, entered by a workspace or by the person themselves.
Workspace materials
Documents a workspace uploads for review, such as briefs, decks, spreadsheets, and email threads.
Talent Tracker media
The ads, reference photos, and headshots a workspace uploads or imports from Google Drive so the people who appear can be found and reviewed.
Plugin sync
When you pair the ComfyUI plugin to a workspace: project names, workflow kind, source references that carry no filenames or paths, person links, record versions, and the portrait crops a producer confirms.
Google connection
If you connect Google Drive and Sheets: the account email, the permissions you granted, encrypted access credentials, and references to the files you picked and the Sheets you exported.
Technical records
IP address, browser type, timestamps, and the requests your browser or plugin makes, kept in service and security logs. Workspace actions are also written to an append-only audit log.
03Google user data.
Google is optional in Pluribus. You can use Google to sign in, and separately you can connect Google Drive and Sheets to import reference files and export a Talent Sheet. Each asks for your permission on Google’s own consent screen, and each requests only the access listed here.
openid, email, profile
Your name, email address, and profile picture. Used to sign you in and to show which Google account is connected.
drive.file
Only the files you select in Google’s file picker, and files Pluribus creates for you. We cannot list, search, or open anything else in your Drive.
spreadsheets
Used only to create the Talent Sheet you ask us to export into your own Google account, and to write its rows. We do not open, read, or change any spreadsheet Pluribus did not create.
How we use it. Files you pick from Drive are copied into your workspace’s private storage and processed exactly like a file you upload directly, as described in Media and face analysis. We never modify, move, or delete the originals in your Drive. The Talent Sheet is created in your own Google account, private to you, and sharing it is your decision.
How we store it. The credential that keeps your connection alive is encrypted with AES-256-GCM, kept on our servers, and never written to logs. Google’s file picker runs in your browser, so it receives a short-lived access token while it is open; that token is never stored. We keep references to the files you picked and the Sheets you exported so the workspace can show what came from where.
Who we share it with. Google user data goes only to the processors needed to deliver the feature you asked for, listed in Who processes it. We do not sell it, use it for advertising, or transfer it to data brokers. No one at Pluribus reads your Google data unless you ask us to for support and agree to it, or it is necessary for security or to comply with the law.
Pluribus’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalized AI or machine learning models.
Disconnecting and deleting. Disconnect Google from your workspace settings at any time. Disconnecting deletes the tokens we hold and revokes our access with Google immediately. You can also remove Pluribus from your Google Account permissions. Files you imported stay in the workspace until you delete them there; Sheets you exported stay in your Drive under your control. To have everything removed, email privacy@trypluribus.com.
04The plugin review runs on your machine.
The plugin reads graph structure (nodes, models, reference inputs) on your ComfyUI server. That reading stays local. Your images, renders, prompts, and models are not uploaded by the plugin.
Portrait analysis is optional and off until you turn it on. If you enable it, the plugin downloads two small open-source models (YuNet and SFace) after you explicitly choose to install them. They detect faces and group similar appearances within your project’s media so a producer can confirm whether a group is the same person. Face data from that analysis stays in memory, and crops, evidence sheets, and job state live in the plugin’s private data directory on your machine. Unconfirmed analysis is never uploaded.
One deliberate exception: when a project is paired to a workspace and a producer confirms an appearance, that confirmed portrait crop syncs to the workspace so the person’s record has a face.
05Media and face analysis in the workspace.
Talent Tracker finds the people who appear in an ad so a producer can account for each of them. A workspace uploads the ad and any reference photos, or imports them from Google Drive. A private processing service samples frames, detects faces, and groups appearances that look alike. A producer then reviews every group and decides who is who. Pluribus suggests; a person confirms.
To group appearances, the service computes numerical measurements of each detected face. Those measurements are used only inside the project they came from, only to compare against that project’s own media, and are deleted when processing finishes. They are never compared across workspaces, never added to a shared database, and never used to identify a stranger. The portrait crops a producer reviews remain part of the project until the workspace deletes them.
The workspace is responsible for having the right to submit the media it uploads, including any notice or consent the law requires for the people who appear in it. If you appear in a Pluribus workspace and have a question or request, write to privacy@trypluribus.com and we will route it to the workspace and help see it through.
06AI processing uses OpenAI.
Some workspace features send content to the OpenAI API. When a workspace uploads campaign materials and runs a review, those documents are processed to pull out campaign facts, suggest people and terms, and draft summaries. When Talent Tracker processes an ad, a small number of selected frames are classified to separate featured talent from background context. Nothing goes to OpenAI unless a workspace starts one of those actions. The plugin’s optional policy check uses your own OpenAI key and travels straight from your machine to OpenAI; it never passes through Pluribus and carries no media.
Under OpenAI’s API terms, this content is not used to train their models. OpenAI may retain it for up to 30 days to monitor for abuse and then deletes it. We send the minimum needed for the task, and no account details travel with it. Suggestions are reviewed by a person before they become part of a record; Pluribus makes no automated decisions with legal effect.
07How we use it.
To run the product, and for nothing else. We don’t sell or share personal information for advertising, we don’t run ads, and we don’t use your content to train models.
Provide the service
Sign you in, run the workspace, process the media and documents you submit, deliver invites, keep acceptance records connected to the right person, and export the records you ask for. Our basis is the contract with you or your organization.
Keep it secure
Rate limiting, abuse prevention, audit logging, and investigating incidents. Our basis is our legitimate interest in a safe service.
Support you
Reply when you write to us and send service messages about your account. We send no marketing email unless you ask for it, and every such email has an unsubscribe link.
Improve the product
Aggregate, non-identifying usage and performance measurements. We do not build advertising profiles.
Meet legal obligations
Respond to lawful requests and keep the records the law requires.
08Who processes it.
Pluribus runs on a short list of infrastructure providers acting as processors on our behalf, each bound by a written agreement to protect the data and use it only to provide their service to us. We update this list before a new provider starts processing personal information.
Supabase
Database, authentication, and private file storage. Holds account, workspace, and consent records, uploaded files, and encrypted Google credentials. United States.
Vercel
Application hosting, request logs, and aggregate, cookieless analytics. United States, with global edge delivery.
Google Cloud
Private, isolated media storage and processing for Talent Tracker: sampling frames, detecting faces, and grouping appearances. United States.
Sign-in, the Drive file picker, and Sheets export, only if you choose to use them.
OpenAI
Document review, drafting assistance, and the classification of selected video frames, through the OpenAI API. Not used to train OpenAI’s models. United States.
Resend
Delivery of sign-in links, invites, and service email. Holds recipient addresses and message content. United States.
Beyond these, we disclose personal information only when you direct us to (for example, a share link you issue), when the law requires it, or as part of a merger or acquisition, in which case we will tell you beforehand and this policy continues to apply to your data.
09How long we keep it.
We keep personal information only as long as the purpose it was collected for requires, then delete it or strip the identifiers from it.
Account
For as long as your account is open. Deleted within 30 days of closing it.
Workspace content
Documents, people details, and records stay until you delete them or the workspace is closed. Deleted items leave live systems within 30 days.
Talent Tracker media
Uploaded and imported source media is kept for 30 days after processing so the review can be finished, then deleted. The portrait crops a producer confirms stay with the project.
Face analysis data
The numerical face measurements used to group appearances exist only while a run is processing and are deleted when it finishes, never later than 24 hours after it starts.
Google credentials
Until you disconnect Google, close your account, or the connection goes unused for 180 days. Deleted immediately at that point.
Consent and acceptance records
For the life of the workspace that holds them, because they are the evidence the record exists to keep. A revoked grant is marked revoked everywhere it is referenced.
Audit log
For the life of the workspace. When a person’s data is deleted, their identifiers in the log are replaced with a placeholder so the chain stays verifiable.
Service and security logs
30 days, then deleted or aggregated.
Contact and waitlist details
24 months after our last exchange, or sooner if you ask.
Backups
Encrypted backups roll off within 30 days. Deleted data may persist in a backup until then, and is never restored into live use.
10How we protect it.
The full architecture is described on the security page. In short:
Encryption
TLS 1.2 or higher on every connection and AES-256 at rest. Google credentials and other secrets are additionally encrypted at the application layer with keys held outside the database.
Isolation
Postgres row-level security separates workspaces on every table. Uploaded files sit in private storage and are served only through short-lived signed links to authorized members.
Least privilege
Production access is limited to the people who need it, protected by multi-factor authentication, and logged. Processing services run without long-lived keys.
Tamper-evident audit log
Workspace actions land in an append-only, hash-chained log that is re-verified daily.
Incident response
If a breach affects your personal information, we notify affected workspaces and people without undue delay, and within 72 hours of confirming it.
11Your data, your call.
Wherever you live, you can:
- Access the personal information we hold about you and receive a copy in a portable format.
- Correct anything that is inaccurate or incomplete.
- Delete your account and the personal information connected to it.
- Object to or restrict processing, and withdraw any consent you gave, at any time.
- Revoke a likeness consent grant. We mark it revoked everywhere it is referenced.
- Disconnect Google at any time, which deletes the credentials we hold and revokes our access.
Export and account deletion are available in your account settings. For anything else, email privacy@trypluribus.com. We verify the request, respond within 30 days, and never charge for it or treat you differently for asking. If the information sits in a workspace owned by another organization, we pass your request to them and help them fulfil it.
If you are in the EEA, the UK, or Switzerland, these are your rights under the GDPR, and you may also complain to your local data protection authority. If you are a California resident, these are your rights under the CCPA: to know, delete, correct, and limit the use of sensitive personal information. Pluribus does not sell or share personal information as those terms are defined, and honors Global Privacy Control signals. If we decline a request, you can appeal by replying to our decision.
13Where it is processed.
Pluribus and its processors operate in the United States. If you use Pluribus from elsewhere, your information is transferred to and processed in the United States. For transfers from the EEA, the UK, and Switzerland, we rely on the Standard Contractual Clauses with our processors and offer them to workspaces in our data processing agreement.
14Children.
Pluribus is a tool for professional productions. Accounts are for people aged 18 and over, and we do not knowingly collect personal information from children. When a production involves a minor, the workspace is responsible for the consent of a parent or guardian. If you believe a child has given us personal information, write to us and we will delete it.
15Changes and contact.
This policy changes as the product does. Material changes show up on this page with a new date, and we email workspace owners at least 14 days before they take effect. If we ever want to use Google user data in a new way, we will update this policy and ask for your consent first.
Questions, requests, and complaints go to privacy@trypluribus.com. Security reports go to security@trypluribus.com.
