Security & Privacy
Plain-English summary of what PM101 stores, who can see it and how to delete it. Last updated September 2026.
What we store
- Account: email, display name, optional avatar, role and industry preferences.
- Projects (PPM): the project data you enter, scope, requirements, risks, stakeholders, decisions, lessons, cost plan.
- Sources: files you upload to a project (PDF, DOCX, XLSX, CSV, TXT, MD) and the text we extract from them.
- Usage counters: prompt runs, video jobs and assistant chats per calendar month, so we can enforce free-tier limits.
- Search history (last 50 queries) and AI Assistant responses you've seen, used to improve relevance.
Access control
- Every table that holds user data is protected by row-level security: by default, only the row owner (and people they invite to a project) can read or change it.
- Storage buckets for uploaded files are private and scoped to your user ID, so even a leaked URL won't let someone else download your files.
- Server-side functions (AI drafting, document parsing, etc.) verify your session token on every call.
- Admins and moderators can see aggregate metrics and moderate community submissions, but cannot read your private project data.
How support access works
- PM101 staff cannot read your project, uploaded files or extracted text unless you explicitly grant access from Project → Settings → Support access.
- Each grant is read-only and auto-expires within 24 hours. You can revoke it at any time.
- Every field a support agent opens is written to an append-only audit log that you can see in the same panel.
- You'll be emailed automatically whenever support actually views any part of your project.
Where it lives
Data is hosted on Supabase (Postgres database, object storage, edge functions) in the EU region. AI drafting and assistant calls are routed through the Lovable AI gateway, which selects the current best-fit model from the configured model pool. The current pool is Google Gemini for text and image generation, and ElevenLabs for voiceover. Billing is handled by Stripe. We don't sell data and no provider trains third-party models on your private project content through our system. The full sub-processor list is in the Privacy Policy.
Your rights
- You can delete any project at any time from Project → Settings → Danger zone. This removes the project row, all uploaded files in storage, extracted text and collaborator invites.
- You can delete your entire account from Profile → Danger zone. It is immediate and cascades through your profile, projects, workspaces, uploads and usage history.
- Email hello@pm101.co.uk to request a data export.
- You can unsubscribe from non-essential emails from any message footer.
Transparency
Agents in the marketplace show their full system prompt before you run them. We call this a glass-box design. The PM Assistant cites the library pages it draws from. We never inject hidden instructions into your saved content.
Questions or a security report?
Email hello@pm101.co.uk and we'll respond within two working days. For suspected vulnerabilities, please include reproduction steps.
Want the full picture? Read the Data & AI Guide. Looking for marketing or cookie terms? See the Privacy Policy and Terms of Service.