Security & Privacy
Plain-English summary of what PM101 stores, who can see it and how to delete it. Last updated July 2026.
What we store
- Account: email, display name, optional avatar, role and industry preferences.
- Projects (PPM): the project data you enter, scope, requirements, risks, stakeholders, decisions, lessons, cost plan.
- Sources: files you upload to a project (PDF, DOCX, XLSX, CSV, TXT, MD) and the text we extract from them.
- Usage counters: prompt runs, video jobs and assistant chats per calendar month, so we can enforce free-tier limits.
- Search history (last 50 queries) and AI Assistant responses you've seen, used to improve relevance.
Access control
- Every table that holds user data is protected by row-level security: by default, only the row owner (and people they invite to a project) can read or change it.
- Storage buckets for uploaded files are private and scoped to your user ID, so even a leaked URL won't let someone else download your files.
- Server-side functions (AI drafting, document parsing, etc.) verify your session token on every call.
- Admins and moderators can see aggregate metrics and moderate community submissions, but cannot read your private project data.
How support access works
- PM101 staff cannot read your project, uploaded files or extracted text unless you explicitly grant access from Project → Settings → Support access.
- Each grant is read-only and auto-expires within 24 hours. You can revoke it at any time.
- Every field a support agent opens is written to an append-only audit log that you can see in the same panel.
- You'll be emailed automatically whenever support actually views any part of your project.
Where it lives
Data is hosted on Supabase (Postgres database, object storage, edge functions) in the EU region. AI drafting and assistant calls are routed through the Lovable AI gateway, which forwards them to OpenAI, Anthropic and Google models depending on the task. Voice generation uses ElevenLabs. Billing is handled by Stripe. We don't sell data and we don't permit these providers to train third-party models on your private project content. The full sub-processor list is in the Privacy Policy.
Your rights
- You can delete any project at any time from Project → Settings → Danger zone. This removes the project row, all uploaded files in storage, extracted text and collaborator invites.
- Email hello@pm101.co.uk to delete your entire account or request a data export.
- You can unsubscribe from non-essential emails from any message footer.
Transparency
Agents in the marketplace show their full system prompt before you run them. We call this a glass-box design. The PM Assistant cites the library pages it draws from. We never inject hidden instructions into your saved content.
Questions or a security report?
Email hello@pm101.co.uk and we'll respond within two working days. For suspected vulnerabilities, please include reproduction steps.
Looking for our marketing or cookie terms? See the Privacy Policy and Terms of Service.