Skip to content

Privacy

Updated · August 11, 2026

Privacy, in plain language.

The short version: the workflow review runs on your machine, and the hosted service stores only what you choose to sync: project and invite information, the portrait crops a producer confirms, and ordinary account and operational data. You can ask us to delete what we hold.

01The review runs on your machine.

The plugin reads graph structure (nodes, models, reference inputs) on your ComfyUI server. That reading stays local.

Portrait analysis is optional and off until you turn it on. If you enable it, the plugin downloads two small open-source models (YuNet and SFace) after you explicitly choose to install them. They detect faces and group similar appearances within your project’s media so a producer can confirm whether a group is the same person. Face data from that analysis stays in memory, and crops, evidence sheets, and job state live in the plugin’s private data directory on your machine. Unconfirmed analysis is never uploaded.

One deliberate exception: when a project is paired to a workspace and a producer confirms an appearance, that confirmed portrait crop syncs to the workspace so the person’s record has a face. Everything else stays local, and Pluribus cannot identify a stranger from a face.

02What we store.

Information you actively give us:

  • Onboarding and signup: name, role, organization, work email, and anything you write in a notes field.
  • Accounts and sign-in: the email you use for one-time sign-in links, or your name and email from Google if you choose Google sign-in. We never see your Google password.
  • Invites and the accept flow: the recipient email you enter, the context attached to the invite, and the terms and scope a person accepts or declines.
  • Talent accounts: signup details and the consent grants connected to a likeness.
  • Workspace materials: documents a workspace uploads for review (briefs, decks, spreadsheets, email threads) and the people details entered alongside them, like names and representative contacts.
  • Plugin sync: when you pair the plugin to a workspace, we store workflow structure. Project names, workflow kind, source references that carry no filenames or paths, person links, record versions, and the portrait crops a producer confirms. Your wider media stays local: images, renders, prompts, and models are not uploaded.
  • Operational records: standard logs that keep the service running and help us investigate problems, plus aggregate, non-identifying analytics on the public site.

03How we use it.

To run the product, and for nothing else: deliver invites, keep accept records connected to the right person, sync rosters, and reply when you write to us. We don’t sell personal information, we don’t run ads, and we don’t use your data to train models.

04Where it lives.

Pluribus runs on infrastructure providers acting as processors on our behalf: Supabase (database, authentication, and private file storage), Resend (email delivery), Vercel (hosting and aggregate analytics), Google (only if you choose Google sign-in), and OpenAI (document review, below). Data is encrypted in transit, and access is limited to what operating the service requires.

05Document review uses OpenAI.

When a workspace uploads campaign materials and runs a review, those documents are processed through the OpenAI API to pull out campaign facts and suggest people and terms. Under OpenAI’s API terms, that data is not used to train their models. Nothing goes to OpenAI unless a workspace uploads material and runs a review. The plugin’s local review never touches it.

06Your data, your call.

Email privacy@trypluribus.com to see, correct, or delete the information we hold about you. If you accepted a consent grant and want to take it back, write to us and we’ll mark the grant revoked everywhere it’s referenced.

07About this policy.

This policy changes as the product does. Material changes show up on this page with a new date.