Companion Privacy Policy
Last updated: September 13, 2026
This policy covers the PlotLens Companion desktop application (including builds distributed via direct download and, when listed, the Microsoft Store). For the general PlotLens service, see our main privacy policy. Product detail on local vs cloud data flow also appears in Companion privacy & data flow.
Overview
PlotLens Companion is a desktop companion for writers who keep working in tools such as Scrivener. It watches a project on disk, detects scenes that changed, and runs Manuscript Check against your PlotLens Story Bible in the cloud. It is not a replacement for your editor or for a human-maintained story bible. It does not write, generate, or rewrite prose. Continuity findings reflect rules a check actually examined.
Data We Collect
Local project files (on your machine)
- What: The Companion reads your project files on your computer (for example Scrivener
.scriv/ related binder files; Final Draft.fdxwhen that path is enabled in the product). - How: Files are opened read-only. The Companion does not edit, repair, or write to your source files. Parsing and change detection run locally.
- What is not uploaded as files: Your
.scrivbundle /.fdxfile is not uploaded as a whole file archive.
Scene text and identifiers sent to PlotLens
- What: Text of changed scenes (or equivalent units) needed for Manuscript Check; project mapping (which PlotLens project the local project is linked to); stable scene/binder identifiers so findings can point back to the right place.
- When: When you save / when the Companion syncs changes (including after reconnect if an offline queue flushes).
- Why: Validation runs in PlotLens cloud — the same Manuscript Check family as the web app. Fully offline validation is not offered.
- Retention: Once scene text reaches PlotLens, your account's normal PlotLens retention, team-sharing, and Security / Trust Center rules apply.
Authentication data
- What: PlotLens session credentials so the Companion can call the PlotLens API as you.
- Where stored: Session token is stored by the native app (not merely in an embedded web view's browser storage), per current product design.
- Retention: Until you sign out or the session expires; delete local app data on uninstall per OS norms.
Usage analytics / telemetry
- Product analytics (PostHog): Production builds with analytics enabled send sanitized lifecycle / product events to PostHog (
us.i.posthog.com). Autocapture is off. Events use hashed identifiers. Manuscript text, scene content, and Story Bible text are not included (manuscript_text_included: false). See Trust Center (PostHog — product analytics; no manuscript content). Web cookie consent governs browser surfaces only — not this native Companion path. This section is the Companion analytics disclosure. - Auto-update: Separately, update checks fetch a static latest-version manifest (
latest.json) and may send a User-Agent (app/OS). Not manuscript. - Crash data: Crash bundles remain local unless you explicitly choose to share them. We do not auto-upload crashes to Sentry, AppCenter, or any third-party crash service (none used).
- Events such as:
companion.app_installed,companion.app_started,companion.signed_in,companion.auth_session_expired,companion.entitlement_blocked,companion.source_linked,companion.initial_index_completed,companion.watcher_started,companion.change_detected,companion.sync_started,companion.sync_completed,companion.sync_failed,companion.validation_started,companion.validation_completed,companion.validation_failed,companion.issue_viewed,companion.navigated,companion.relink_required,companion.cloud_warning_shown,companion.transport_offline,companion.update_check_completed,companion.update_failed,companion.error. That is the complete allow-listed event taxonomy in the Companion client.
Your content is yours
We do not use your creative content to train AI models. Scene text is processed to provide continuity checks and related Service features, not to train foundation models on your work under our provider terms as described on Security.
How We Process Data
- Local parse — On your machine, the Companion watches the project folder, reads source files read-only, and determines which scenes changed.
- Cloud Manuscript Check — Changed scene text is sent to the PlotLens API over HTTPS and may be processed by cloud LLM services (including Azure OpenAI) to produce continuity findings against your Story Bible. Azure OpenAI may retain prompts and completions for up to 30 days as part of Microsoft’s abuse-monitoring process. Retained data is accessible only to authorized Microsoft reviewers and is not used for training.
- Findings return — Results return to the Companion. Opening a finding in your linked editor (for example Scrivener) uses local open handlers; manuscript excerpts are not logged as part of that open action beyond what the product docs describe.
Third-Party Services
- PlotLens API — Validation and account/project APIs. Receives scene text and auth.
- Clerk — PlotLens account authentication (sub-processor), where sign-in uses Clerk.
- Azure OpenAI (and processors named on Security / Trust Center) — May process scene text for continuity analysis. Not used to train on your manuscripts under our provider terms as described there.
- PostHog — Product analytics (sanitized lifecycle / product events; hashed IDs; no manuscript; US region
us.i.posthog.comper Trust Center). - Microsoft Store (if you install from the Store) — Microsoft's store and update policies apply in addition to this policy.
- Stripe — Billing for paid PlotLens plans via the web/app; not required to download the Companion installer itself.
Data Storage & Security
- Local source files stay on your machine; the Companion is designed so the OS read-only open path rejects writes to those files.
- Data in transit to PlotLens is encrypted via TLS.
- PlotLens server-side data is encrypted at rest.
- See Security / Trust Center for infrastructure and sub-processors.
Your Rights
- Access / export / deletion: Via the PlotLens web app account and project settings, plus deleting local Companion data / uninstalling the app.
- Stop cloud processing: Sign out, unlink the project, or uninstall; note that queued offline changes may send when you reconnect if the app is still authorized.
Children's Privacy
PlotLens is not directed at children under 16. We do not knowingly collect personal information from children under 16.
Changes to This Policy
We will notify users of material changes via email and/or in-product notice.
Contact
- Email: privacy@plotlens.ai
- Support: plotlens.ai/support
- Data-flow explainer: plotlens.ai/docs/companion-privacy