Penro
← Back to site
Last updated 8 September 2026

Privacy & security

Penro reads your messages to find promises. That is a lot of trust, so here is exactly what it touches, what it stores, and what it will never do.

Never used for training

Your messages are never used to train any model — ours or a vendor's. Zero-retention terms are contractual with every provider we call.

Read-only access

Penro cannot send, delete, or edit anything. Every integration is granted with the narrowest read scope the provider offers.

Loops, not transcripts

We keep the extracted promise, who made it, and when. The surrounding conversation is discarded after processing.

Deleted means deleted

Disconnect a source and its loops are purged within 24 hours. Delete your account and everything goes within 30 days, backups included.

What we collect

Three buckets, nothing outside them.

Account

Name, email, workspace, billing details handled by our payment processor. We never see your card number.

Connected sources

Message text is fetched, scanned for commitments, and dropped. What persists is the loop: the promise, the people, the deadline, the link back to the original message.

Errors

When something breaks we get a crash report: what failed and where in our code. It carries no message content, no screenshot, and nothing identifying you — so it cannot be tied back to a person.

How it is protected

Reviewed annually by an independent auditor.

Encryption

TLS 1.3 in transit, AES-256 at rest. Source tokens sit in an isolated vault.

Access

No engineer reads customer content by default. Break-glass access is time-boxed, approved, and logged.

Residency

EU or US region, chosen at signup. Data does not leave the region you pick.

Certification

SOC 2 Type II and GDPR-aligned. DPA available on request.

Your rights

Exercisable in-app, or by email — no ticket queue.

ExportDownload every loop as JSON or CSV, any time.
CorrectEdit or dismiss any loop Penro got wrong. Corrections stay private to you.
EraseDelete your account from settings. 30 days to full removal, backups included.
ObjectTurn off automated loop detection for any source and keep the rest running.

Still have a question about your data?

Our data protection officer answers directly, usually within two working days.

privacy@penro.app