Plyto

Privacy policy

Last updated July 16, 2026

What we collect

Account details you provide (name, email) via our sign-in provider (Auth0); business data you or your team put into Plyto (contacts, companies, deals, tasks, emails, websites, blog posts); billing details processed by Stripe (we never store card numbers); usage and diagnostic data (pages visited, actions taken, errors) used to keep the product working and improve it.

How we use it

To provide the service: storing your CRM data, sending email you compose or approve, running automations you activate, publishing websites and blog posts you create, and running ad campaigns you explicitly approve. We also use AI providers (such as Anthropic) to power the Plyto agent: the content of your requests and relevant business records are processed to fulfill them. We do not sell your data or your contacts' data to anyone.

Your contacts' data

You own the contact data you bring to Plyto and are responsible for having a lawful basis to contact those people. Plyto enforces unsubscribe handling and do-not-contact flags on email sends.

Where data lives

Data is stored with reputable cloud providers (Vercel, Neon Postgres, Cloudflare, Resend for email delivery), primarily in the United States, encrypted in transit and at rest. OAuth tokens for connected ad accounts are encrypted with keys we control.

Connected ad accounts (Google & Meta)

When you connect Google Ads, you grant Plyto two permissions and nothing else. Google Ads (adwords) lets us read your campaign performance and, only when you approve a change, create and edit campaigns, ad groups, keywords, negative keywords, ads, budgets and bidding settings on your behalf. Data Manager (datamanager) lets us send your own conversions back to your Google Ads account: when a lead Plyto captured through your form becomes a customer, we upload that outcome against the original ad click so Google can optimize toward the ads that produce real business. We do not upload your contact lists to Google or build Google audiences from your customer data.

On Meta, if and only if you explicitly ask us to, Plyto can build a custom audience or lookalike audience from one of your own contact lists, inside your own Meta ad account. Email addresses are hashed before upload, Meta discards entries it cannot match, and you can delete the audience in Meta at any time. We never build audiences on our own initiative, never share them across businesses, and never upload anyone to a platform you have not connected.

Plyto's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the features you connected it for, we never sell it, we never transfer it except as required to provide those features or by law, we never use it for advertising of our own, and no human reads it except with your explicit permission for support or where required by law. Disconnect at any time in Settings, Integrations; we delete the stored tokens immediately and the performance data we cached within 30 days.

Cookies

Essential cookies (session authentication, your active-business selection, and your cookie choice itself) are always on; the product can't work without them. Analytics and marketing cookies are used only if you choose “Accept all” in the cookie banner, and you can change your choice any time via “Cookie preferences” in the footer.

Retention & deletion

Your data is retained while your account is active. Delete your account (or email us) and we remove your business data within 30 days, excluding minimal records we must keep for tax or legal reasons.

Contact

Questions or deletion requests: hello@plyto.ai.

← Back to plyto.ai