Legal
Privacy Policy
Last updated: September 5, 2026
1. Introduction
Plexon AI ("we", "our", "us") is operated by Hellenic Development. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our desktop application and website (collectively, the "Service"). Please read this policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
Account Information
When you create an account or sign in with your Google account, we receive your name, email address, and profile picture from Google. This information is used solely to identify your account and provide the Service.
Local Data
All your working data (your conversations, the keys to your AI accounts, your files, and your settings) is stored only on your own machine, encrypted with AES-256-GCM. We have no access to any of it.
Usage Analytics
We may collect anonymous, aggregated usage metrics such as feature usage counts and error rates to improve the product. No personally identifiable information, code content, or conversation data is included in these analytics.
Install Count
The desktop app counts installs so we know how many people run Plexon and on which operating system. A random number is created on your computer and sent when it is created, once a day while the app runs, and when Plexon is uninstalled. It carries your operating system and app version and nothing else: no name, email, account, IP address, file names, folder paths, or anything from your conversations. It is never linked to your account, and it is not derived from anything about your machine, so deleting the file that holds it (install-id.json in your Plexon folder) makes your computer a new install with no way for us to connect the two. Turn it off in Settings, under Advanced, in the Privacy section. Turning it off sends one last message so your copy stops being counted, and then nothing further.
3. Google User Data
The use of raw or derived user data received from Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we ask Google for
Signing in with Google gives us your email address, name, and profile picture, and nothing else. If you connect the Google Drive Suite, Plexon asks for the files it creates or you open with it, plus Docs, Sheets, Slides, and Calendar, and you can untick any of those four before you grant them. If you connect Gmail, it asks for your mail, labels, and basic settings. Each of these is a separate consent screen, and you can revoke either one at any time from your Google account.
What happens to it
Google data is read or changed only when you ask the assistant to, in a chat or in an automation you set up yourself. Your Google sign-in tokens are stored encrypted on your own computer and never leave it. When you ask the assistant to act on a document, an event, or a message, that content passes once through our routing server to reach the AI service answering your request, and is kept nowhere: the server stores no Google data, logs no content, and keeps nothing between one request and the next.
What we never do with it
We do not use Google user data for advertising. We do not sell it. We do not use it to build or train any AI model, and we do not send it to an AI service that would. The managed Plexon provider runs on an AI service whose terms exclude customer content from model training (see section 5). If you bring your own AI account and that service's terms do not rule out training on what it receives, Plexon keeps the Google connectors switched off while it is selected and tells you so in the app. If you point Plexon at a model running on your own computer, your Google data is processed there and is never shared with the model's maker for training or any other secondary purpose. We do not share Google user data with anyone else except to comply with applicable law, or as part of a merger, acquisition, or sale of assets, and we do not use it for anything unrelated to what Plexon does for you.
4. How We Use Your Information
We use the information we collect to: create and manage your account; provide, maintain, and improve the Service; communicate with you about the Service, including support requests; send you technical notices and security alerts; comply with legal obligations; and protect against fraudulent, unauthorized, or illegal activity.
5. Where Your Conversations Go
To answer you, Plexon has to send your request to an AI model. Which model, and where it runs, is your choice, and the three options are genuinely different. Here is each one plainly.
A model running on your own computer
Point Plexon at a model running on your own machine, through Ollama, LM Studio, vLLM, or any compatible local endpoint, and your conversations stay on that machine. There is no API key to paste, no account to hold, and no other company involved. You keep complete control of the content and of the model itself. This is the setup to choose for regulated work, client records, or anything you would rather not put in someone else's cloud. Local and custom endpoints are available on the Premium plan.
A provider you choose, on your own key
Pick a provider in Settings and paste your own API key. Your requests go to the company you selected, under the agreement you hold with them, and your key is stored encrypted on your own machine. You can switch provider whenever you like, and you can use different providers for different modes.
The managed Plexon provider
One subscription, with no keys to manage. We choose and operate the AI service on your behalf so you do not have to hold an account with anyone else. We only use a service whose terms for API customers exclude your content from being used to train or improve its models. Your request passes through our routing service to reach it and is used only to produce your answer. The routing service keeps no copy of it: it stores no conversations and logs no message content.
What we never do with your conversations
We do not use your conversations to train any AI model. We do not sell them, and we do not use them for advertising. Your files, your chat history, and your credentials stay on your own machine, encrypted at rest, and Session Lock can put a single chat behind a passcode that nobody can lift, including us. When you bring your own AI account, that service handles your content under the agreement you hold with it, and picking one whose terms exclude training is your call; on OpenRouter, Plexon marks every request so it is routed only to services that do not collect or train on it. We do not publish which service sits behind the managed Plexon provider, and we will name the current one on request at contact@hellenic.dev.
6. Data Sharing & Disclosure
We do not sell your personal information. We may share your information only in the following circumstances: with AI providers (Anthropic, OpenAI, Google, etc.) when you use their services through Plexon AI, where your prompts are sent according to their respective privacy policies; with service providers who assist us in operating the Service (e.g., hosting, analytics), under strict data processing agreements; to comply with applicable laws, regulations, or legal processes; and to protect the rights, property, or safety of Hellenic Development, our users, or the public.
7. Data Retention
Account information is retained for as long as your account remains active. Our server keeps nothing between one request and the next: no conversations, no caches, no logs. All your working data (your files, your conversations, and the keys to your AI accounts) stays on your own machine and is never stored on our servers beyond the moment a single request takes to answer.
8. Data Security
We use proven, industry-recommended security measures to protect your data. The keys to your AI accounts are encrypted with AES-256-GCM while in transit. The server unlocks one only for as long as a request needs it, and never writes it down. Because your working data is never stored on our side, a breach there could not expose it. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
9. Your Rights & Choices
Depending on your location, you may have the following rights regarding your personal data: the right to access the personal data we hold about you; the right to request correction of inaccurate data; the right to request deletion of your account and associated data; the right to data portability; and the right to withdraw consent at any time. Since the vast majority of your data resides locally on your machine, you can manage, export, or delete it at any time. To exercise rights regarding your account data, contact us at contact@hellenic.dev.
10. Cookies & Tracking
Our website uses essential cookies required for authentication and session management. We do not use advertising cookies or third-party tracking cookies. You can configure your browser to refuse cookies, but some features of the Service may not function properly without them.
11. Children's Privacy
The Service is not intended for children under 13 years of age (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will delete that information promptly. If you believe we have inadvertently collected data from a child, please contact us at contact@hellenic.dev.
12. International Data Transfers
Your information may be processed in countries other than your country of residence. We ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection laws.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at contact@hellenic.dev.