Penro reads your messages to find promises. That is a lot of trust, so here is exactly what it touches, what it stores, and what it will never do.
Your messages are never used to train any model — ours or a vendor's. Zero-retention terms are contractual with every provider we call.
Penro cannot send, delete, or edit anything. Every integration is granted with the narrowest read scope the provider offers.
We keep the extracted promise, who made it, and when. The surrounding conversation is discarded after processing.
Disconnect a source and its loops are purged within 24 hours. Delete your account and everything goes within 30 days, backups included.
Three buckets, nothing outside them.
Name, email, workspace, billing details handled by our payment processor. We never see your card number.
Message text is fetched, scanned for commitments, and dropped. What persists is the loop: the promise, the people, the deadline, the link back to the original message.
When something breaks we get a crash report: what failed and where in our code. It carries no message content, no screenshot, and nothing identifying you — so it cannot be tied back to a person.
Reviewed annually by an independent auditor.
TLS 1.3 in transit, AES-256 at rest. Source tokens sit in an isolated vault.
No engineer reads customer content by default. Break-glass access is time-boxed, approved, and logged.
EU or US region, chosen at signup. Data does not leave the region you pick.
SOC 2 Type II and GDPR-aligned. DPA available on request.
Exercisable in-app, or by email — no ticket queue.
Our data protection officer answers directly, usually within two working days.
privacy@penro.app