Privacy Policy
Last updated: August 28, 2026
Plainly is built to be used without giving up much about yourself. This page explains, plainly, what we collect and why.
No accounts, no profiles
Plainly doesn't require sign-up, doesn't use accounts, and doesn't build a profile of you. There's no login, no saved search history tied to a person, and no email collection on the main site.
What we do collect
- Word lookups. When you search a word, that word is sent to our backend (hosted on Supabase) to fetch and simplify a definition. Looked-up words and their definitions are cached so future visitors get instant results - this cache isn't tied to who searched it.
- IP addresses, for rate limiting. Our public API issues up to 3 keys per day per IP address to prevent abuse. Your IP is checked against this limit but isn't stored as part of a personal profile.
- Standard server logs. Our hosting providers (Vercel and Supabase) automatically log request metadata - IP address, timestamp, requested path, user agent - as a normal part of running any website. These logs are used for security and debugging, not for tracking individuals.
- Basic analytics. We use Vercel Web Analytics and PostHog to see aggregate traffic and how people use the site (like which words get looked up most). Neither is used to build an advertising profile of you or to track you across other, unrelated sites.
Third parties we rely on
Plainly is built on a small number of services, each of which processes some data on our behalf:
- Vercel - hosting and analytics
- Supabase - database and backend functions
- Mistral AI and Groq - the word you look up is sent to one of these to generate the plain-English rewrite
- PostHog - product analytics, so we can see which parts of the site are actually used
- dictionaryapi.dev - the source for raw dictionary definitions before simplification
These providers may process data outside of Indonesia. We choose providers with their own privacy and security practices, but we'd rather be upfront that your lookup isn't staying on a single server in one place.
Cookies
Plainly doesn't use cookies for advertising or cross-site tracking. Since there are no accounts, there's no authentication cookie either.
Children's privacy
Plainly isn't directed at children and we don't knowingly collect personal information from anyone under 13.
Your rights
Because we don't hold accounts or personal profiles, there's generally very little of "your data" for us to give back or delete. If you believe we're holding something about you specifically (for example, in a server log) and want it removed, contact us and we'll look into it.
Changes to this policy
If how we handle data changes meaningfully, we'll update this page and change the "last updated" date above.
Contact
Questions about this policy: hello@plainly.my.id
This policy describes our actual data practices as plainly as we can. It isn't a substitute for legal advice, and if your use of Plainly has specific compliance requirements (for example, as part of a regulated business), please review it with your own counsel.