Plume sends data only to the Micropub endpoints you explicitly connect.
https://rmdes.github.io/plume/callback.html?code=…&state=…, so the code and
state pass through GitHub Pages in the URL and may appear in its server logs. That code is
single-use and bound to a PKCE verifier that never leaves your browser, so it's useless on
its own; nothing else is sent. A small script on that page reads the sign-in result from the
page's address and hands it to the extension. It runs nowhere else.
Full policy + source: github.com/rmdes/plume