Plexxa AI

Privacy

How Plexxa collects, uses and protects information across the platform.

Information we process

Plexxa may process account details, workspace configuration, uploaded documents, web links, prompts, AI responses, logs and support correspondence so the service can operate.

How information is used

Information is used to provide the platform, authenticate users, answer workspace queries, improve reliability, provide support, prevent abuse and meet legal obligations.

Customer content

Customer content belongs to the customer. Customers choose what they upload and are responsible for ensuring they have the rights and permissions needed to store and process that content.

Google user data

If you connect a Gmail mailbox, Plexxa reads messages from that mailbox so your team can triage enquiries in one place and so the assistant can answer questions from your own mail. If you additionally grant permission to send, Plexxa can create draft replies in your Gmail Drafts folder and send a reply once a person has approved it.

Access is opt-in for each individual mailbox. No Gmail data is accessed until someone explicitly connects one. Read access and send access are granted separately: connecting a mailbox grants read-only access, and permission to draft or send is requested later, only when a user first tries to send.

Sharing and disclosure of Google user data

We do not sell Google user data and we do not use it for advertising. We share it only with the service providers below, and only so that a feature you have asked for can work.

Apart from these providers, we disclose Google user data only where we are legally required to do so.

We do not use Google user data, whether raw, aggregated, anonymised or derived, to create, train or improve any generalised or foundational artificial intelligence or machine learning model, and no provider listed below is permitted to do so with data we send them.

  • Microsoft Azure OpenAI Service — generates AI-drafted replies and powers semantic search. Receives subjects and message bodies from the mailbox you connect.
  • Qdrant Cloud — managed vector database. Receives numeric embeddings derived from your content.
  • Supabase (PostgreSQL) — our primary application database. Stores message metadata and bodies of fetched mail, and encrypted OAuth tokens.
  • Fly.io — application hosting. Processes data in transit and in memory.

Protecting sensitive data

All traffic between you, Plexxa and the providers listed above is encrypted in transit using TLS.

Gmail access and refresh tokens are encrypted before they are written to our database, so the plaintext token is never stored.

Every table holding customer data is subject to PostgreSQL row-level security, enforced by the database itself rather than only by application code. Each request runs under its own workspace identity, so one workspace cannot read or write another workspace's data.

Disconnecting a mailbox revokes our OAuth grant with Google and deletes the stored tokens, cached messages, AI-generated drafts and mailbox settings for that mailbox.

Limited Use

Plexxa's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google Workspace data, raw or derived, to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models.

Contact

For privacy questions, contact info@travelogica.ai.

Plexxa account and data deletion

Plexxa users can request deletion of their account and associated app data, or request deletion of specific personal data without deleting their account. Requests are normally processed within 30 days, subject to any legal, security, fraud prevention, billing or dispute-resolution retention requirements.

Request Plexxa account or data deletion