Security
Last updated: February 17, 2026
Security principles
Our security model is based on least privilege, data minimization, and encryption-first controls. We design systems to store the smallest possible amount of account data required for dependable service access.
Minimal data retention
We retain only encrypted account email information needed to keep user accounts operational and to support authentication and account continuity workflows.
We do not keep chat transcripts, prompt logs, or model conversation histories as persistent account data. We do not intentionally collect sensitive personal data unrelated to core account operation.
Encryption and transport protection
- Encrypted storage controls for retained account identifiers.
- TLS-protected network communication for service traffic.
- Pro Pass key handling with local encryption safeguards where applicable.
Access controls and operations
Administrative access is restricted by role and operational need. Security events and infrastructure behavior are monitored to detect abuse, protect availability, and support incident response.
Application and infrastructure hardening
We continuously improve software and infrastructure through updates, defensive defaults, and risk reduction practices focused on confidentiality, integrity, and service resilience.
Responsible disclosure
If you discover a potential vulnerability, report it via the support contact listed on the plugin page. We review credible reports promptly and prioritize remediation based on impact.