What we store
Account email and organisation membership, to authenticate you and resolve which organisation you may act on.
Execution metadata: token counts, measured cost, latency, the model selected, the candidates refused, and the policy and pool versions in force.
What we do not store by default
Prompt and response content. Retention defaults are conservative during beta and content is not retained for model improvement. Nothing you send is used to train any model — ours or a provider's — beyond the terms of your own agreement with that provider.
Your provider credentials. Under BYOK these are supplied as configuration and resolved at the execution boundary; they are not written to the database.
Sub-processors
Supabase (EU) for the database and authentication. Render (EU) for application hosting. Model providers you configure, which receive the content of your requests under your own agreement with them.
Your rights
Export or deletion requests go to hello@planverity.ai. Deleting an account removes its membership rows; execution records tied to an organisation are retained as required for billing accuracy and are not attributable to an individual user.