Pluribus

Privacy

Privacy, in plain language.

The short version: workflow and optional identity analysis run on your machine, media and face embeddings are not uploaded, and the hosted service processes the project and invite data you choose to sync alongside ordinary account, authentication, contact, and operational data. You can ask us to delete what we hold.

Updated July 18, 2026

The scan stays local

The Pluribus plugin reads graph structure — nodes, models, and reference inputs — on your ComfyUI server. If you explicitly enable local identity analysis, YuNet detects faces and SFace compares those appearances within the media being reviewed so the plugin can propose recurring groups. Face embeddings remain in memory for that analysis; private crops, evidence sheets, job state, and cache files stay in the plugin data directory. Pluribus does not upload that media or identify a stranger from a face.

What we collect

We store information you actively give us:

  • Onboarding and contact forms — name, role, organization, work email, and whatever you write in the notes field.
  • Accounts and sign-in — your email for magic links, or your name and email from Google if you sign in with Google. We never see your Google password.
  • Invites and the accept flow — the recipient email you enter, the detection context attached to the invite, and the terms and scope a person accepts or declines.
  • Talent accounts — signup details and the consent grants connected to a likeness.
  • Workspace materials — campaign documents a workspace uploads for review (briefs, decks, spreadsheets, email threads) and the people details entered alongside them, such as names and representative contacts.
  • Plugin sync — when you connect the plugin to a workspace, we store workflow structure: project names, workflow kind, opaque source references, person links, and rights-manifest versions. Not your images, renders, prompts, or models.
  • Operational records — standard logs that keep the service running and let us investigate problems, plus aggregate, non-identifying usage analytics on the public site.

How we use it

To run the product and nothing else: deliver invites, keep accept records connected to the right likeness, sync rosters, and reply when you write to us. We do not sell personal information, we do not run ads, and we do not use your data to train models.

Where it lives

Pluribus runs on infrastructure providers acting as processors on our behalf: Supabase (database, authentication, and private file storage), Resend (email delivery), Vercel (hosting and aggregate analytics), Google (only if you choose Google sign-in), and OpenAI (document review, below). Data is encrypted in transit, and access is limited to what operating the service requires.

Document review uses OpenAI

When a workspace uploads campaign materials and runs a review, the content of those documents is processed through the OpenAI API to extract campaign facts and suggest people and terms. Per OpenAI’s API terms, that data is not used to train their models. Nothing is sent to OpenAI unless a workspace uploads material and runs a review; the plugin’s local scan never touches it.

Your choices

Email privacy@trypluribus.com to access, correct, or delete the information we hold about you. If you accepted a consent grant and want to revoke it, contact us and we will mark the grant revoked in the records that reference it.

About this policy

Pluribus is an early-access product and this policy will evolve as features ship. Material changes will be reflected on this page with a new date. Questions about anything here: privacy@trypluribus.com.