Security
How PlainHub handles your files and your sign-in credentials.
Files and tokens
✓ PlainHub doesn't store your files
Your files are saved only in your own GitHub repository. They're read and saved directly between your browser and GitHub, and their contents are never sent to PlainHub's servers. PlainHub's servers are used only for signing in with GitHub (handing over and refreshing the token) and for a usage log (GitHub username and time, deleted automatically after 90 days). See the Privacy Policy for what is recorded, and Data Ownership for how we think about your data.
✓ Tokens are stored only on your side, never on PlainHub's servers
- Web: You sign in by approving PlainHub on GitHub's own page (a GitHub App). The token you receive is stored in this browser's storage (localStorage). The hand-over at sign-in and the refresh when the token expires go through PlainHub's server (on Cloudflare), but the token is not stored or logged there. Signing out removes the token from the browser
- CLI / MCP Server: Stored on your own computer at
~/.config/plainhub/token(created with permission 0600, so only the owner can read or write it) - AI API key: Stored in this browser. AI requests go directly from your browser to Anthropic, not through PlainHub's servers
✓ Limits on what code runs and where it connects
- The editor sets a Content-Security-Policy that limits where scripts can load from and which hosts it can talk to (GitHub, Anthropic, Cloudflare's analytics, and the library CDNs)
- Some libraries loaded from a CDN use Subresource Integrity (SRI), so the browser checks they haven't changed before running them
- The editor can't be embedded inside other sites (X-Frame-Options: DENY)
PWA Support
- Offline support — Offline operation via Service Worker
- Add to home screen — Install as an app on mobile or desktop
- Native app feel — Runs without the browser address bar
Supported Browsers
| Browser | Supported version |
|---|---|
| Chrome | 90+ |
| Firefox | 88+ |
| Safari | 14+ |
| Edge | 90+ |