Plyto

Privacy policy

Last updated July 16, 2026

What we collect

Account details you provide (name, email) via our sign-in provider (Auth0); business data you or your team put into Plyto (contacts, companies, deals, tasks, emails, websites, blog posts); billing details processed by Stripe (we never store card numbers); usage and diagnostic data (pages visited, actions taken, errors) used to keep the product working and improve it.

How we use it

To provide the service: storing your CRM data, sending email you compose or approve, running automations you activate, publishing websites and blog posts you create, and running ad campaigns you explicitly approve. We also use AI providers (such as Anthropic) to power the Plyto agent: the content of your requests and relevant business records are processed to fulfil them. We do not sell your data or your contacts' data to anyone.

Your contacts' data

You own the contact data you bring to Plyto and are responsible for having a lawful basis to contact those people. Plyto enforces unsubscribe handling and do-not-contact flags on email sends.

Where data lives

Data is stored with reputable cloud providers (Vercel, Neon Postgres, Cloudflare, Resend for email delivery), primarily in the United States, encrypted in transit and at rest. OAuth tokens for connected ad accounts are encrypted with keys we control.

Cookies

Essential cookies (session authentication, your active-business selection, and your cookie choice itself) are always on; the product can't work without them. Analytics and marketing cookies are used only if you choose “Accept all” in the cookie banner, and you can change your choice any time via “Cookie preferences” in the footer.

Retention & deletion

Your data is retained while your account is active. Delete your account (or email us) and we remove your business data within 30 days, excluding minimal records we must keep for tax or legal reasons.

Contact

Questions or deletion requests: hello@plyto.ai.

← Back to plyto.ai