Privacy Policy
Last updated: September 5, 2026
Plumely is a multi-tenant compliance platform for pharmaceutical and API manufacturing teams. Unlike a consumer app, the whole point of the Service is to store and track your organization's regulated records on your behalf — so this policy explains what we hold, why, how it's kept separate from every other organization on the platform, and how long we keep it.
1. Who this policy covers
This policy covers the personal data of individual users — the people who sign up for and use Plumely. Your organization is the controller of the compliance records (suppliers, CoAs, deviations, studies, and similar) it stores in the Service; Plumely processes that data on the organization's behalf, as described below.
2. Account data
Signing up creates an account through our authentication provider, Supabase: your email address and a securely hashed password (or your chosen sign-in method) are stored so we can identify you across sessions. Your profile can optionally include a full name, an avatar, and a phone number — the phone number is only ever used if your organization enables SMS alerts and you choose to provide it. We use an essential session cookie to keep you signed in; we set no advertising or cross-site tracking cookies, and Plumely shows no ads.
3. Organization data
Creating or joining an organization stores the organization's name, its membership list, the roles and per-tool permissions assigned to each member, and any outstanding invites (email address, invited role, status). Membership and role data is visible only to other members of the same organization — Postgres row-level security enforces this at the database layer, in addition to the application's own access checks.
4. Your organization's compliance records
The substantive data you enter into each tool — supplier and material qualification records, certificates of analysis and other uploaded documents, deviations and CAPAs, stability studies and pull results, protocol amendments, export/shipment documentation, and country dossier checklists — is stored in our database and, for uploaded files, in encrypted object storage, scoped strictly to your organization. No other organization on the platform can see it, and it is used only to provide the Service to your organization, never to train models, build advertising profiles, or share with other customers.
5. Clinical Trial Lite Manager — PHI
This tool is deliberately PHI-minimized by design: participants are recorded by a coded identifier only, and there is no name or date-of-birth field anywhere in its schema. Even so, if your organization uses this tool with real participant data, your organization is responsible for its own IRB, HIPAA, and other applicable obligations, including obtaining a signed Business Associate Agreement with the underlying infrastructure provider before entering real participant data — self-hosted deployments are excluded from this requirement. Plumely provides the tool; it does not by itself make your use of it compliant.
6. Audit trail
Material actions taken in the Service are written to an append-only, hash-chained audit log — who did what, when, and why — designed to support recordkeeping practices commonly expected under 21 CFR Part 11 and similar frameworks. This log cannot be edited or deleted through the app, and it is retained as part of your organization's compliance record even if the underlying record is later changed. Some tools also capture an electronic-signature event (password re-authentication plus a stated meaning) when a record is formally signed off; that signature record is stored immutably alongside the action it signs.
7. Cookies
We use only essential cookies — the session cookie that keeps you signed in. We load no third-party advertising or cross-site tracking scripts.
8. Who we share data with
We do not sell personal information and we do not share it for advertising purposes. Data is disclosed only to the infrastructure providers needed to run the Service, under contracts that require them to process it only on our instructions:
- Supabase — authentication, our Postgres database, and encrypted file storage for uploaded documents. Holds the data described in sections 2–6 above.
- Our application hosting provider — processes requests in transit to serve the app; holds no persistent copy of your data.
- If your organization enables email or SMS alerts, the notification is sent using the contact details configured in your profile or organization settings.
9. How long we keep data
Compliance records and the audit trail are retained for as long as your organization's account is active, and are not silently deleted — GxP recordkeeping expectations generally require retention, not deletion, and the audit trail's own integrity depends on not removing entries. If your organization closes its account, we retain data only as long as needed to meet legal, contractual, or accounting obligations, then delete or anonymize it. If you leave an organization or delete your personal account, your profile data (name, avatar, contact details) is removed, but audit-trail entries that reference actions you took are retained, attributed to your former account, to preserve the integrity of the compliance record.
10. Security
All traffic runs over HTTPS/TLS. Access to another organization's data is blocked both at the database layer (Postgres row-level security) and in the application's own authorization layer, since some backend queries connect with elevated database privileges that RLS alone does not restrict. Platform-wide administrative access exists for a small number of Plumely operators and is not self-service — it is granted only through an internal script run directly against the database, is logged to the affected organization's own audit trail when used to change tool access, and is never available through any in-app control.
11. Your rights
You can request access to, correction of, or deletion of your personal account information by emailing us. Requests to access, export, or delete an organization's compliance records should generally come from that organization's own administrators, since the records belong to the organization, not to any one member. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we do not sell or share personal information in the way those laws define it.
12. Children
Plumely is a business tool for pharmaceutical and manufacturing professionals and is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from them.
13. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with an updated date.
14. Contact
Questions about privacy, or a data request? Email hello@plumely.online.