Privacy Policy

Last updated: August 5, 2026

This policy describes what personal data Penci.ly collects, why we collect it, who else processes it, how long we keep it, and what you can ask us to do with it. It is written to be read, not to be survived.

1. Who We Are

Penci.ly ("we," "us") is a visual workspace application operated by Daniel Halabi, a sole operator based in Germany. For users in the EU, EEA, and UK, Penci.ly is the data controller for your account and board data.

Contact for anything on this page: privacy@penci.ly. We are not required to appoint a data protection officer and have not appointed one; requests go to that address and are handled by the operator directly.

2. What We Collect

Account data

  • Email address, username, display name, and profile image URL.
  • Account creation and update timestamps.
  • Authentication data held by Clerk, including your sign-in methods and, if you enable it, two-factor authentication settings. We never see or store your password.

Content you create

  • Boards, cards, free text, to-do lists, buttons, link bookmarks, color swatches, and the connections you draw between them.
  • Board names, cover images, and icons.
  • Who a board is shared with, including collaborator emails and roles, and who starred or favorited it.

Board content is whatever you put in it. If you put personal data about other people on a board, you are responsible for having a basis to do so.

Uploaded media

Images and cover or icon uploads you add to boards are stored with Cloudinary and referenced from our database. Uploads pass through our own server, which checks the file type and size and records the stored size against your plan's quota.

Presence and activity data

We process which board you currently have open and when you were last active on it to power live "who's here" indicators. We do not retain this as a historical activity log.

Usage and rate-limit data

We count how much storage your account uses, how much media it has delivered this month, and how often it calls rate-limited operations. These counters exist to enforce plan limits and to stop abuse, and are not used to build a profile of you.

Technical data

Our hosting and infrastructure providers automatically process standard request and connection metadata, such as IP address, browser or device information, and timestamps, for security and abuse prevention.

Payment data

Once billing is live, Paddle, acting as merchant of record, will handle payment processing, PCI-DSS compliance, and tax collection. We never see or store your card details.

Product analytics

If you accept the analytics banner, we use PostHog (hosted in the EU) to record page views, the domain that referred you, and a short list of named product events such as signing up, creating a board, sharing one, starting or completing a checkout, and exporting a PDF. Once you are signed in these are associated with your account identifier and your plan.

We never send your email address, your name, or any board content to PostHog. Nothing is collected until you accept, nothing is collected at all if your browser sends a Do Not Track signal, and session recording is switched off.

Analytics requests are routed through our own domain at penci.ly/ingest rather than directly to PostHog, so that an ad-blocker does not silently distort what we measure. That is a reliability choice, not a way around your decision: declining the banner stops collection regardless of how the request would have travelled.

What we deliberately do not collect: we do not run third-party advertising trackers or analytics that build cross-site profiles, and our analytics does not use autocapture, which would record every click on every element. It is a fixed list of about a dozen named events chosen to answer specific questions. We do not make automated decisions producing legal or similarly significant effects about you, and we do not profile you for advertising.

3. How We Use It

  • To provide the core product: rendering your boards, syncing changes in real time, and enforcing who can view or edit them.
  • To authenticate you and manage your account through Clerk.
  • To generate link previews when you paste a URL.
  • To enforce fair-use and rate limits and prevent abuse.
  • To process payments through Paddle once billing is live.
  • To communicate essential service updates, including security notices and changes to these terms.

We do not use your data for advertising targeting or sell it to third parties.

4. Who We Share It With

We do not sell your personal data or board content.

We share data only with the collaborators you explicitly invite, our infrastructure providers as needed to operate the service, and legal authorities when required by valid legal process.

ProviderRoleWhat they process
VercelHosting and edge networkRequest metadata and application delivery
ConvexDatabase and real-time syncBoard and account content
ClerkAuthenticationEmail, name, credentials, two-factor settings, and session tokens
CloudinaryMedia storage and CDNUploaded images and other media
PaddlePayments (planned)Billing and payment data, but never through our systems
ResendEmail deliveryYour email address, your display name, and the contents of the emails we send you, such as the name of a board you were invited to. Never your board content beyond that
PostHog (EU region)Product analytics, only with your consentPage views, referring domain, named product events, your account identifier and plan. Never your email, name, or board content

Each provider is contractually bound through its terms or data processing agreement to process data only as needed to provide its service to us. If we add or replace a provider we will update this table and, where the change is material, tell users directly.

In the event of a sale or transfer of the service, account and board data may transfer with it. We would tell you before that happened and give you the chance to export your data and close your account first.

5. Data Retention and Deletion

  • Your content persists for as long as your account exists.
  • Deleting a board removes it, every element on it, every board nested inside it, and the images and files uploaded to any of them. The storage they used is returned to your account.
  • Deleting your account removes your boards and their contents, your uploaded files, your profile, and your subscription and usage records. It also removes you from boards owned by other people, including invitations sent to your address that you never accepted.
  • We keep a record of security-relevant actions (who was added to or removed from a board, and when) for up to 180 days. When an account is deleted, its email address is removed from those records.
  • Actions taken by our own staff on the service (granting a plan, exporting an account's data, deleting an account) are kept for up to 400 days, along with the reason given and the network address the action came from. That is longer than the 180 days above, deliberately: these are the records that make our own access to your account reviewable, and a period shorter than an annual review cycle would make them useless for that.
  • We keep a record of the emails we send you (the address, which kind of email it was, and whether it was delivered) for up to 90 days, so we can answer questions like “was my invitation ever sent?”. Deleting your account removes these records along with your notification preferences.
  • One exception survives account deletion. If an email to your address permanently bounces, or you mark one of our emails as spam, we keep a record of that address on a suppression list so we stop sending to it. We keep this even after an account is deleted, because deleting it is how someone ends up being emailed again after asking us to stop, for example if another user later invites the same address to a board. The list holds the address and the reason only, and nothing else about you.
  • Records of a purchase held by our merchant of record are kept for as long as tax and accounting law requires them, independently of your Penci.ly account.
  • Deletion of your content is immediate in our database; removing the associated files from our media provider runs straight afterwards and may take a few minutes. Provider backups may retain copies for a short period before they age out.
  • We do not currently apply an automatic deletion period based on account inactivity.

6. Email You Receive From Us

There are two classes of email, and the line between them is drawn on whether you would be worse off for never seeing the message, not on how much we would like you to read it.

  • Account email tells you about the account itself: a welcome message, a plan becoming active, a failed payment, a cancellation or expiry, a confirmation that your account was deleted. It is part of providing the service, carries no unsubscribe link, and cannot be switched off while the account exists.
  • Optional email covers board invitations, changes to your access on a shared board, the weekly summary, product updates, and marketing. Every one of these can be turned off individually in your notification settings, each carries a one-click unsubscribe, and turning one off stops it immediately.

Marketing email is off unless you turn it on. So is the weekly summary. Invitations, access changes, and product updates are on by default, because they are about something you or a collaborator did.

Clerk sends the emails that belong to authentication: verification codes, password resets, email-change confirmations. Those are part of signing in and are not covered by these preferences.

7. How We Protect Your Data

  • In transit: traffic to Penci.ly is served over HTTPS/TLS. Our infrastructure providers encrypt data in transit.
  • At rest: account and board data is encrypted at rest by Convex using AES-256. Uploaded media is encrypted at rest by Cloudinary.
  • Access control: boards are visible only to their owner and the collaborators explicitly added to them. Clerk handles authentication, so we never see or store your raw password, and two-factor authentication is available in your account settings.
  • Our own access: administrative access to accounts is restricted, requires re-authentication, and is recorded. See the 400-day record in section 5. We look at an account's data only to resolve a support request, investigate abuse, or comply with law.

This is not end-to-end encryption. Penci.ly's backend and, in principle, our infrastructure providers can read board content under their access controls, so that the service can render it, synchronize it in real time, and provide features such as link previews and PDF export.

Our infrastructure providers are independently audited, including Vercel (SOC 2 Type 2 and ISO 27001), Convex (SOC 2 Type II), Clerk (SOC 2 Type 2), and Cloudinary (SOC 2 Type II).

If a breach affecting your personal data occurs and the law requires it, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and tell affected users where the risk to them is high.

8. Your Rights

If you are in the EU, EEA, or UK, GDPR Articles 15–21 give you the right to access, correct, delete, restrict, or port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. Our GDPR Compliance page explains each of these and how to use them.

If you are in California, the CCPA and CPRA give you the right to know what personal information we collect and why, to request its deletion or correction, to receive it in a portable form, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by California law, and we do not use it for cross-context behavioural advertising, so there is nothing for an opt-out to switch off. We do not knowingly collect or sell the personal information of anyone under 16.

Account deletion and your notification preferences are self-service in your account settings. Requests for a full data export beyond board PDF export are currently handled manually. Write to privacy@penci.ly and we will produce it. We may need to verify your identity first so that we do not disclose or delete data for the wrong person, and we aim to respond within 30 days.

You may also lodge a complaint with the data protection supervisory authority of the EU or EEA country where you live or work. Because we operate from Germany, the German state data protection authority for the operator's place of business is also competent.

9. International Data Transfers

Our analytics provider is deliberately configured to its EU region, so that data stays within the EEA. Our other providers may process data outside your country, including in the United States. Where EU or UK personal data is transferred outside the EEA or UK, we rely on safeguards offered by those providers, such as Standard Contractual Clauses, the EU–US Data Privacy Framework where the provider is certified, or an equivalent mechanism. You can ask us at privacy@penci.ly which safeguard applies to a given provider.

10. Children's Privacy

Penci.ly is not directed at children under 13, and we do not knowingly collect data from them. If we learn that we hold data from a child under 13 without the involvement of a parent or guardian, we delete it. Our Terms of Service describe the age requirements for creating an account.

11. Cookies and Local Storage

We use the minimum needed to run the application:

  • Strictly necessary: Clerk authentication and session cookies. Without these you cannot stay signed in.
  • Preference: a light or dark theme setting, stored locally in your browser.
  • Preference: your analytics choice, stored locally in your browser. It is deliberately not sent to our servers: declining analytics should not itself create a record about you.
  • Analytics, with consent: PostHog's own identifier, written only if you accepted the analytics banner. Declining, or having Do Not Track set, means it is never written.

We do not use third-party advertising or cross-site tracking cookies. You can clear your browser storage at any time to reset every one of the above; clearing it while signed in will sign you out.

12. Changes to This Policy

We will update the "Last updated" date whenever the practices described here change, and make a reasonable effort to notify users directly of material changes, such as a new processor, a new purpose, or a change in legal basis, before they take effect.

13. Contact

For privacy questions or requests, contact privacy@penci.ly. For anything else, support@penci.ly.