Privacy Policy

Last updated: July 25, 2026

1. Who We Are

Penci.ly ("we," "us") operates penci.ly, a visual workspace application. For EU and UK users, Penci.ly is the data controller for your account and board data, as described in our Terms of Service.

2. What We Collect

Account data

  • Email address, username, display name, and profile image URL.
  • Account creation and update timestamps.

Content you create

  • Boards, cards, free text, to-do lists, buttons, link bookmarks, color swatches, and the connections you draw between them.
  • Board names, cover images, and icons.
  • Who a board is shared with, including collaborator emails and roles, and who starred or favorited it.

Uploaded media

Images and cover or icon uploads you add to boards are stored with Cloudinary and referenced from our database.

Presence and activity data

We process which board you currently have open and when you were last active on it to power live "who's here" indicators. We do not retain this as a historical activity log.

Technical data

Our hosting and infrastructure providers automatically process standard request and connection metadata, such as IP address, browser or device information, and timestamps, for security and abuse prevention.

Payment data

Once billing is live, LemonSqueezy, acting as merchant of record, will handle payment processing, PCI-DSS compliance, and tax collection. We never see or store your card details.

What we deliberately do not collect: We do not run third-party advertising trackers or analytics that build cross-site profiles.

3. How We Use It

  • To provide the core product: rendering your boards, syncing changes in real time, and enforcing who can view or edit them.
  • To authenticate you and manage your account through Clerk.
  • To generate link previews when you paste a URL.
  • To enforce fair-use and rate limits and prevent abuse.
  • To process payments through LemonSqueezy once billing is live.
  • To communicate essential service updates, including security notices and changes to these terms.

We do not use your data for advertising targeting or sell it to third parties.

4. Who We Share It With

We do not sell your personal data or board content.

We share data only with the collaborators you explicitly invite, our infrastructure providers as needed to operate the service, and legal authorities when required by valid legal process.

ProviderRoleWhat they process
VercelHosting and edge networkRequest metadata and application delivery
ConvexDatabaseBoard and account content
ClerkAuthenticationEmail, name, credentials, and session tokens
CloudinaryMedia storage and CDNUploaded images and other media
LemonSqueezyPayments (planned)Billing and payment data, but never through our systems

Each provider is contractually bound through its terms or data processing agreement to process data only as needed to provide its service to us.

5. Data Retention and Deletion

  • Your content persists for as long as your account exists.
  • Deleting a board removes it and its child elements from our database.
  • Deleting your account removes your owned boards and profile data.
  • Boards you collaborate on but do not own may retain your user ID in access or collaborator records until the owner removes you or deletes the board.
  • We do not currently apply an automatic deletion period based on account inactivity.

6. How We Protect Your Data

  • In transit: Traffic to Penci.ly is served over HTTPS/TLS. Our infrastructure providers encrypt data in transit.
  • At rest: Account and board data is encrypted at rest by Convex using AES-256. Uploaded media is encrypted at rest by Cloudinary.
  • Access control: Boards are intended to be visible only to their owner and explicitly added collaborators. Clerk handles authentication, so we never see or store your raw password.

This is not end-to-end encryption. Penci.ly's backend and, in principle, our infrastructure providers can read board content under their access controls so the service can render it, synchronize it in real time, and provide features such as link previews and PDF export.

Our infrastructure providers are independently audited, including Vercel (SOC 2 Type 2 and ISO 27001), Convex (SOC 2 Type II), Clerk (SOC 2 Type 2), and Cloudinary (SOC 2 Type II).

7. Your Rights (GDPR / CCPA)

If you are in the EU, EEA, UK, or California, you may have rights over your personal data, including access, correction, deletion, portability, restriction, and objection to processing. See our GDPR Compliance page for more information. Account deletion is currently self-service; requests for a full data export beyond board PDF export are handled manually.

8. International Data Transfers

Our providers may process data outside your country, including in the United States. Where EU or UK personal data is transferred outside the EEA or UK, we rely on safeguards offered by those providers, such as Standard Contractual Clauses or equivalent mechanisms.

9. Children's Privacy

Penci.ly is not directed at children under 13, and we do not knowingly collect data from them. Our Terms of Service describe the age requirements for creating an account.

10. Cookies and Local Storage

We use the minimum needed to run the application:

  • Clerk authentication and session cookies.
  • A light or dark theme preference stored locally.

We do not use third-party advertising or cross-site tracking cookies.

11. Changes to This Policy

We will update the "Last updated" date whenever the practices described here change and make a reasonable effort to notify users directly of material changes.

12. Contact

For privacy questions or requests, contact privacy@penci.ly.