Security

How Planloom protects your work.

Plain-English answers about what is encrypted, who can see what, and what AI receives. We would rather be precise than impressive: personal space and shared Co-Spaces work differently.

Your personal space is end-to-end encrypted

Personal notes, journal entries and personal canvases are sealed in your browser before they leave your device, so our servers only store ciphertext.

  • AES-256-GCM encryption, performed in your browser.
  • Keys are generated on your device; per-record keys are derived with HKDF and bound to the owner and record so they cannot be swapped.
  • You save a recovery key yourself. New devices must be approved by a device you already trust, using P-256 key exchange.
  • Joining a Co-Space never gives teammates access to your personal space.

Shared Co-Spaces are role-based, not end-to-end encrypted

Collaboration needs the server to coordinate real-time sync, so shared Co-Space canvases are protected by access control rather than end-to-end encryption.

  • Workspace membership and role (owner, editor, viewer) are checked on every request.
  • Invite links are controlled by Co-Space owners.
  • Real-time sync uses Yjs; edits made offline queue locally and merge on reconnect.

AI sends the minimum context

Planloom AI works on what you select, not your whole workspace.

  • Only the selected text is sent for an AI action, never files or images.
  • Results are previewed before they are inserted, and land on the board as a single undo step.
  • If you connect your own assistant through the MCP server, it sees only what you can see, using a token you create and can revoke in Settings.

Your work stays portable

There is no lock-in: take your boards with you whenever you want.

  • Export canvases as PNG, SVG, PDF or editable JSON.
  • Mermaid flowcharts can be exported back to Mermaid for your docs.

For the legal detail, see GitHub permissions, read the Privacy Policy and Terms. Questions about security? Email support@planloom.app.