Skip to main content

How PlyOps protects local, cloud, and marketplace data

See where PlyOps stores local and cloud data, how marketplace tokens stay on the server, and what checks run before a connected action.

How does PlyOps approach security?

PlyOps keeps browser-local, cloud, and marketplace data separate. Local work stays in the browser unless you export it or move it into PlyOps Cloud. Cloud and marketplace requests check the signed-in user, workspace, plan, and requested action on the server.

Updated

Local storage
IndexedDB in the current browser profile
Cloud access
Signed-in, workspace-scoped authorization
Marketplace secrets
Server-side only, excluded from browser backups
Listing writes
Preview the fields, fix errors, then confirm

Check access before private data loads

Browser filters do not protect private data by themselves. Before a sensitive read or change, the server checks the signed-in user, workspace, role, and plan access again.

Keep secrets out of the browser

Service-role keys, marketplace client secrets, access tokens, and refresh tokens do not belong in browser bundles, local storage, URLs, screenshots, backups, or support messages. Connected provider credentials are handled on the server and returned to the interface only as safe account metadata and action summaries.

Show marketplace changes before sending them

Imports show the proposed product matches before anything changes. Creating or updating a listing is a separate action with marketplace-specific checks. PlyOps does not automatically retry a destructive action or manage live marketplace quantities.

Understand the shared responsibility

No web application can promise absolute security. Protect your devices and browser profiles, keep local backups, use current sign-in credentials, and do not send passwords, tokens, or customer data through support. PlyOps documents where data is stored and what each connection can access.

Common questions

Are marketplace access tokens included in JSON backups?

No. Marketplace tokens and server secrets are excluded from browser storage, JSON backups, client code, and user-facing job summaries.

Does a public Supabase key grant access to private records?

No. Public configuration identifies the project. Authorization still depends on authenticated sessions, row-level policies, workspace membership, role checks, and server-side validation.

Does PlyOps automatically publish marketplace changes?

No. PlyOps shows the listing fields and any errors, then waits for you to confirm. Provider restrictions can block an action entirely.