Security
How Planloom protects your work.
Plain-English answers about what is encrypted, who can see what, and what AI receives. We would rather be precise than impressive: personal space and shared Co-Spaces work differently.
Your personal space is end-to-end encrypted
Personal notes, journal entries and personal canvases are sealed in your browser before they leave your device, so our servers only store ciphertext.
- AES-256-GCM encryption, performed in your browser.
- Keys are generated on your device; per-record keys are derived with HKDF and bound to the owner and record so they cannot be swapped.
- You save a recovery key yourself. New devices must be approved by a device you already trust, using P-256 key exchange.
- Joining a Co-Space never gives teammates access to your personal space.
Shared Co-Spaces are role-based, not end-to-end encrypted
Collaboration needs the server to coordinate real-time sync, so shared Co-Space canvases are protected by access control rather than end-to-end encryption.
- Workspace membership and role (owner, editor, viewer) are checked on every request.
- Invite links are controlled by Co-Space owners.
- Real-time sync uses Yjs; edits made offline queue locally and merge on reconnect.
AI sends the minimum context
Planloom AI works on what you select, not your whole workspace.
- Only the selected text is sent for an AI action, never files or images.
- Results are previewed before they are inserted, and land on the board as a single undo step.
- If you connect your own assistant through the MCP server, it sees only what you can see, using a token you create and can revoke in Settings.
Your work stays portable
There is no lock-in: take your boards with you whenever you want.
- Export canvases as PNG, SVG, PDF or editable JSON.
- Mermaid flowcharts can be exported back to Mermaid for your docs.
For the legal detail, see GitHub permissions, read the Privacy Policy and Terms. Questions about security? Email support@planloom.app.