Our Privacy Commitment
Your files are yours. Poly's business is the software that helps you work with them. This page explains what we store, how we protect it, and what we never do with it.
What Poly stores
When you upload a file to Poly, we store:
- The file itself: encrypted at rest in a secure, privately hosted content network with both in-datacenter and offsite data redundancy.
- Extracted metadata: file type, size, dimensions, EXIF data, and other format-specific attributes
- A search index: extracted text and vector embeddings that power search
- Thumbnails: generated previews for supported file types
- Version history: previous states of the file, retained for the lifetime of your account, or based on your lifecycle rules.
All of this is associated with your account and is not accessible to other users unless you explicitly share it.
Encryption
- At rest: All files and associated data are encrypted using modern encryption in our secure Poly content network.
- In transit: All data transmitted between your devices and Poly's servers uses TLS 1.2 or higher. There are no unencrypted connections.
- Authentication: Poly uses short-lived, opaque tokens to authenticate your sessions. Tokens are stored securely and rotated automatically, dozens of times an hour.
Local device computaton
The Poly desktop app syncs your files from a local folder to Poly. Files outside of this folder are never read, indexed, processed, or uploaded. We do not "scan" your computer or otherwise perform background computation outside of the express goal of providing the sync feature for your local folder.
What Poly does not do with your files
- We do not sell your files or file metadata to any third party.
- We do not use your files to train AI models Your files are used only to serve you.
- We do not access your files unless you explicitly request support and grant temporary access as part of that process.
- AI features run on your behalf: when you ask the Poly agent to read a file, it reads that file to answer your question. That context is not retained across sessions or shared with other users. However, if you use a third-party agent (e.g., ChatGPT or Claude) with Poly, that agent may retain the context of your files according to its own privacy policy.
- We do not restrict what kinds of data you store in Poly, including sensitive data. However, you are responsible for complying with any applicable laws and regulations regarding the storage and sharing of such data.
Who can see your files
Your files are private by default. The only people who can access a file are:
- You
- Anyone you've explicitly shared it with (via a link or direct invitation)
- Members of a Shared Drive that contains the file (for files in Shared Drives)
Poly employees cannot browse your files. In the rare event that troubleshooting requires file access, we will ask for your explicit permission first.
Data retention
- Active account: all files and version history are retained for as long as your account is active.
- Deleted files: files you archive remain in your account. From there you can permanently delete files and they are removed and scrubbed from our indices.
- Closed account: upon account deletion, all files and associated data are permanently deleted within 30 days. This is irreversible.
Reporting a security issue
If you discover a security vulnerability in Poly, please report it responsibly to [email protected]. We take all reports seriously and aim to respond within 48 hours.