Legal
Privacy Policy
This Privacy Policy describes how Penopta (“Penopta,” “we,” “us,” or “our”) collects, uses, and shares information when you use our websites, applications, and related services (the “Services”), including penopta.com and app.penopta.com.
Penopta is a shared workspace that helps teams connect AI agent threads (such as Claude and ChatGPT) into projects so teammates and agents can work from shared context.
1. Information we collect
Account and authentication information
When you create or sign in to an account, we may collect:
- Name, email address, and profile photo (including from Google Sign-In if you choose that option)
- Authentication credentials and security factors you set up, such as passkeys
- Organization membership and role information within Penopta
If you sign in with Google, we receive basic profile information Google provides for sign-in (typically name, email address, language preference, and profile image). We use Google Sign-In only to authenticate you and create or access your Penopta account. We do not request Google Drive, Gmail, Calendar, or other Google content scopes for sign-in.
Service and content data
Depending on how you use Penopta, we may process:
- Projects, organization settings, and collaboration metadata
- Agent thread titles, summaries, status, and related context you choose to sync into Penopta
- Integration configuration such as API keys, MCP connection records, and sync preferences
- Invite and notification emails you send or receive through the Services
Agent and project content is provided by you or your organization. We process it to operate the Services you request (for example, storing synced thread context so your team can view it).
Usage and technical information
We may automatically collect:
- Log data such as IP address, browser type, device information, and pages or features used
- Cookies and similar technologies needed for sessions, security, and basic product analytics
- Diagnostic information related to errors, sync runs, and service reliability
2. How we use information
We use the information we collect to:
- Provide, maintain, and improve the Services
- Authenticate users and secure accounts (including passkeys and session management)
- Operate organizations, projects, invites, and integrations
- Process and display content you sync or create in Penopta
- Send service-related communications (for example, invites and security notices)
- Monitor abuse, debug issues, and protect the Services
- Comply with legal obligations
We do not sell your personal information. We do not use Google user data obtained through Google Sign-In for advertising.
3. How we share information
We may share information with:
- Service providers that help us run Penopta (for example hosting, databases, email delivery, and authentication infrastructure), under contractual obligations to protect the data
- Organization members according to your project and organization settings (for example, teammates who can see threads synced into a shared project)
- Professional advisors or authorities when required by law or to protect rights, safety, and security
- A successor entity if we are involved in a merger, acquisition, or asset transfer, subject to this Policy or equivalent protections
Third-party AI providers (such as Anthropic or OpenAI) process your interactions when you use their products. Penopta receives content you choose to sync from those tools; those providers’ own privacy policies apply to your use of their services.
4. Google user data
Our use of information received from Google APIs complies with the Google API Services User Data Policy , including the Limited Use requirements. For Google Sign-In, we use the data only to provide and improve account authentication and related account features in Penopta.
5. Data retention
We retain account and Service data for as long as your account is active or as needed to provide the Services. You may request deletion of your account and associated personal data by contacting us. We may retain limited information as required for legal, security, or operational purposes (for example, fraud prevention or backup integrity).
6. Security
We use administrative, technical, and organizational measures designed to protect information, including encrypted connections (HTTPS), access controls, and secure session handling. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your choices and rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal information
- Export certain account information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
You can update some profile information in the product. To exercise other rights, email privacy@penopta.com. You may also disconnect Google Sign-In from your Google Account permissions settings.
8. Children’s privacy
The Services are not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps.
9. International transfers
We may process information in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards for cross-border transfers.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may be communicated through the Services or by email when appropriate.
11. Contact us
Questions about this Privacy Policy or our data practices:
Email: privacy@penopta.com
Web: https://penopta.com