Privacy Policy
Effective Date: August 23, 2026
Last Updated: August 23, 2026
Ploy, Inc. (“Ploy,” “we,” “our,” or “us”) provides a hosted deployment and cloud platform for building, deploying, and running applications, including AI agents and serverless workloads. This Privacy Policy explains how we collect, use, share, retain, and protect personal information when you use our websites, dashboard, APIs, command-line tools, software development kits, deployment infrastructure, and related services (collectively, the “Service”).
This Policy is incorporated into our Terms of Use. Capitalized terms not defined here have the meaning given in the Terms.
1. Our Role: Controller and Processor
Our role depends on the information involved:
- Controller. We decide why and how to process account, billing, website, marketing, product-analytics, security, and business contact information. For this data, Ploy acts as the data controller.
- Processor or service provider. You decide why and how to process the code, content, application data, end-user data, and other information submitted to or processed through your projects (“Customer Data”). For this data, Ploy acts as your processor under the GDPR and service provider under applicable U.S. privacy laws.
You are responsible for acting as the controller or business for Customer Data, having a lawful basis for processing it, and giving us lawful instructions. A signed data processing addendum or other written agreement controls over this Policy where it applies to Customer Data. Ploy does not use Customer Data to train AI models.
2. Information We Collect
a. Account and Organization Information
We collect information such as your name, email address, profile details, authentication identifiers, organization name, team membership, role, preferences, and account settings. If you sign in or connect an account through GitHub, we receive information that GitHub makes available based on your authorization.
b. Customer Data
The Customer Data we process depends on the features you use and may include:
- Source code, repository metadata, branches, commits, build instructions, dependencies, and build output;
- Project configuration, deployment artifacts, static files, domains, environment variables, credentials, tokens, and secrets;
- Database contents, state, cache entries, files, queue messages, workflow inputs and results, and sandbox files or process output;
- Requests to and responses from deployed applications, including IP addresses, headers, URLs, request bodies, and other end-user data your application processes;
- Build, deployment, runtime, request, security, and diagnostic logs; and
- AI prompts, inputs, context, model selections, generated outputs, token usage, latency, and cost information when you use AI features.
c. Usage and Technical Information
We automatically collect information about how the Service is accessed and used, such as IP address, browser and device type, operating system, referring page, pages viewed, clicks, timestamps, session identifiers, API activity, feature usage, resource consumption, errors, performance, and security events.
d. Billing Information
For paid plans, we and Stripe may collect billing contact details, company name, billing address, tax information, subscription status, invoices, and transaction history. Stripe processes payment-card details; we do not store complete card numbers.
e. Communications and Support
We collect information you send us through email, support requests, feedback, surveys, community channels, or other communications, including contact details and the contents of your message. Do not send secrets or unnecessary Customer Data in support messages.
f. Cookies and Similar Technologies
We use cookies and similar technologies to authenticate users, preserve settings, secure the Service, understand product usage, and improve our websites. You can control cookies through your browser and, where available, our consent controls. Disabling necessary cookies may prevent parts of the Service from working.
3. Legal Bases for Processing in the EEA and UK
Where the GDPR or UK GDPR applies, we rely on:
- Contract: to create and administer accounts, provide the Service, process payments, and respond to support requests;
- Legitimate interests: to secure, maintain, analyze, and improve the Service, prevent abuse, communicate with business users, and establish or defend legal claims, balanced against your rights;
- Legal obligation: to keep required billing and tax records and respond to valid legal requests; and
- Consent: for optional marketing and non-essential cookies where required. You may withdraw consent at any time.
When we process Customer Data as a processor, your lawful instructions and agreement with us govern that processing.
4. How We Use Information
We use information to:
- Provide, operate, maintain, support, and secure the Service;
- Authenticate users and manage accounts, organizations, roles, projects, integrations, domains, deployments, and billing;
- Build, deploy, host, route traffic to, and observe your applications;
- Provide databases, storage, queues, workflows, sandboxes, AI features, and other cloud resources you configure;
- Measure usage, calculate charges, enforce limits, and process payments;
- Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms;
- Analyze and improve the Service using account data, usage information, feedback, and aggregated or de-identified information; and
- Send transactional messages, security alerts, product updates, support responses, and permitted marketing communications.
We do not sell personal information. We do not use Customer Data for advertising or to train AI models.
5. How We Share Information
We share information only as reasonably necessary with:
- Sub-processors and service providers. Vendors that help us provide hosting-related functions, source integrations, payments, communications, analytics, and AI features. Our authoritative list is the Sub-processor List.
- Integrations you enable. When you connect or direct us to use a third-party service, we share the information necessary to complete your request. The third party's privacy terms govern its independent processing.
- Your organization. Organization owners and administrators may access member, project, usage, and billing information and Customer Data according to their permissions.
- Legal authorities and safety. We may disclose information when we reasonably believe it is required by law, legal process, or to protect the rights, safety, and security of Ploy, our users, or the public.
- Business transactions. Information may be transferred in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and privacy protections.
6. AI Features and LLM Gateway
Ploy uses LLM Gateway as a sub-processor to provide AI connectivity for features such as application AI requests and assisted database queries. When you use these features, Ploy sends the prompt, input, relevant context, selected model, and necessary request metadata to LLM Gateway. LLM Gateway routes the request to an AI model provider and returns the output to Ploy or your application.
LLM Gateway and the model providers it uses process information under their agreements and data-handling practices. Retention, processing location, and other practices may vary by model provider. You should not include personal, confidential, regulated, or sensitive information in AI requests unless you have determined that the feature and provider are appropriate for your use case and have a lawful basis to do so.
7. Your Applications and End Users
Ploy does not determine why your application collects or uses end-user personal data. You are responsible for your application's privacy practices, including providing notices, obtaining consent where required, responding to end-user requests, and configuring appropriate security, retention, and access controls.
If an end user asks us about Customer Data controlled by you, we may direct the request to you. We will assist with valid requests as required by applicable law and our agreement with you.
8. Data Retention and Deletion
We keep personal information only as long as reasonably necessary for the purposes described in this Policy, including providing the Service, meeting contractual commitments, resolving disputes, enforcing agreements, and complying with law. Retention depends on the data and context:
- Account and organization data is generally kept while the account or organization is active and for a limited period afterward;
- Customer Data is kept while needed to provide the resources you configure and is deleted or made inaccessible following resource or account deletion, subject to backup cycles and legal holds;
- Logs, analytics, and detailed usage records may be retained for periods that vary by plan, product function, security need, and technical configuration; and
- Billing, tax, fraud-prevention, and legal records may be retained for the period required by applicable law or legitimate business needs.
Deletion from active systems may not immediately remove encrypted backup copies. Backups are isolated, access-restricted, and overwritten or deleted according to our backup cycle unless preservation is legally required. Aggregated or de-identified information may be kept where it can no longer reasonably identify an individual.
9. Security
We use reasonable technical and organizational measures designed to protect personal information, including encryption in transit, access controls, authentication, service isolation, logging, monitoring, and security review. No system is completely secure, and we cannot guarantee absolute security.
You are responsible for protecting your credentials and secrets, assigning appropriate permissions, securing your application code and dependencies, and maintaining backups suitable for your risk. If we become aware of a personal-data breach affecting you, we will notify you and regulators as required by applicable law.
10. Your Privacy Rights
Depending on where you live and subject to legal exceptions, you may have the right to access, correct, delete, or receive a copy of your personal information; object to or restrict processing; withdraw consent; or appeal a decision about a privacy request.
To exercise a right, email contact@meetploy.com. We may need to verify your identity and authority. We will not discriminate against you for exercising a privacy right. If Ploy processes your data on behalf of one of our customers, contact that customer first.
EEA, Switzerland, and UK
You may also lodge a complaint with your local data protection authority. We encourage you to contact us first so we can address your concern.
United States
Residents of certain U.S. states may have rights to know, access, delete, or correct personal information and to opt out of certain sales, sharing, targeted advertising, or profiling. Ploy does not sell personal information or share it for cross-context behavioral advertising. You may use an authorized agent where permitted by law.
11. International Data Transfers
Ploy and our sub-processors may process information in the United States, the European Economic Area, and other countries where we or they operate. Those countries may have different data-protection laws. Where required, we use appropriate transfer safeguards, such as adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism.
AI processing locations may depend on LLM Gateway and the model provider used for a request. Review the Sub-processor List and avoid submitting data to AI features where the available safeguards do not meet your requirements.
12. Children's Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect personal information directly from children. If you believe a child has provided account information to us, contact us so we can take appropriate action. Customers are responsible for determining whether their own applications may be used by children and for complying with applicable children's privacy laws.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The current version will be posted on this page with a revised “Last Updated” date. We will provide reasonable notice of material changes, such as by email or an in-product notice, before they take effect where required.
14. Contact Us
For questions, privacy requests, or concerns about this Policy, contact:
Ploy, Inc.
Email: contact@meetploy.com
Website: meetploy.com