Privacy
Privacy Policy
Last updated 31 August 2026
Pliny exists to rewrite prompts. It collects what that requires and nothing else. The short version: we never store the text you enhance.
What we store
- Your account Name, email address and avatar from the Google or GitHub account you sign in with, plus the identifier that provider gives us so we can recognise you next time.
- Your plan and usage counts Which plan you are on, how many enhancements you have used in the current period, and when that period resets.
- A usage record per request Timestamp, tone, which model ran, token counts, computed cost, how long it took, and whether it succeeded. No prompt text and no output text; there is no column for either.
- Security events Sign-ins, token refreshes, and suspected credential reuse, with the IP address and browser user-agent that produced them.
- Billing records Handled entirely by Stripe. We store the Stripe identifiers and subscription status. We never see or hold your card details.
What we never store
The prompt you send and the rewrite we return are held in memory for the seconds it takes to answer, then discarded. They are not written to a database, not written to a log, not truncated into an error report, and not hashed “just in case”. Request bodies are stripped before any exception is recorded.
We do not use your prompts to train models. Your prompt is sent to Anthropic's API to produce the rewrite and is handled under Anthropic's commercial terms, which exclude training on API inputs.
Who else sees it
Four processors, each for one job: Anthropic produces the rewrite, Stripe handles payment, Google or GitHub verifies who you are when you sign in, and Google Analytics tells us how the website is used: which pages people open, where they click, and how far down they scroll. Analytics runs only on usepliny.com, never inside the extension, and never sees prompt text or anything you type. We sell nothing to anyone, and we run no advertising trackers.
How long we keep it
Usage records are kept for 24 months so we can answer billing questions and investigate abuse. Security events are kept for 12 months. Delete your account and everything above is removed within 30 days, except records we are required to retain for tax purposes.
Your rights
You can export or delete your account data at any time from your dashboard, or by writing to privacy@usepliny.com. We respond within 30 days.
The extension
The Pliny Chrome extension reads the contents of a text field only when you explicitly ask it to, by pressing its button or its shortcut. It does not read pages in the background, and it refuses to touch fields that look like passwords, one-time codes, card numbers, API keys or recovery phrases. Your sign-in tokens are stored in the browser's own extension storage and are sent only to usepliny.com.
Questions: privacy@usepliny.com