# Privacy policy.

**Last updated: September 18, 2026**

This Privacy Policy describes how **Panolayer, Inc.** (“Panolayer,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the Panolayer desktop application, the website at [panolayer.com](https://panolayer.com), accounts, billing, and related services (the “Service”).

It should be read together with our [Terms of service](/terms-of-service). If you have questions, contact [privacy@panolayer.com](mailto:privacy@panolayer.com) or [hello@panolayer.com](mailto:hello@panolayer.com).

## 1. Who we are

Panolayer, Inc. provides a desktop engineering workspace used by humans and coding agents, with an in-process gateway (Guardian) that brokers model access and applies configured policy. We are the controller of personal information we collect through the Service, except where we process information solely on behalf of an organization customer under a separate agreement.

## 2. Information we collect

We collect information in the following categories.

### Account and identity

When you sign in or create an account we may collect:

- name and email address;
- authentication identifiers from our identity provider (currently Clerk) and, if you choose them, social sign-in providers such as GitHub or Google;
- organization or workspace membership if you join a team;
- support messages you send us.

We do not ask you to store a Panolayer password for email-code or Clerk-based sign-in. Desktop session tokens are stored locally (macOS Keychain, with a local database fallback) and are not held by the website frontend.

### Billing

If you purchase a plan or credits, our payment processor (Stripe) collects payment-method and transaction details. We receive limited billing metadata such as customer ID, plan, period, and payment status. We do not store full card numbers on our servers.

### Product and device information

To operate downloads, updates, and the website we may collect:

- app version, OS version, and basic device or locale information;
- installer and update diagnostics (for example, whether a release manifest could be fetched);
- log-in timestamps and security events;
- approximate location derived from IP address for abuse prevention.

### Website analytics

If website analytics are enabled, we may record coarse, allowlisted events such as a download click or a documentation page view. We do not intend this channel to include email addresses, authentication codes, tokens, search text, or source code. A production collector may be configured separately; until then, events may stay local to your browser.

### Customer Content you choose to process

If you open a repository or run an agent, the app processes source code, diffs, prompts, architecture maps, verification results, and related project files **on your machine** and, when a model-backed feature runs, with the providers configured for that workflow. That material is not collected by us as a marketing database. See [Section 4](#4-ai-agents-and-model-providers).

### Communications

If you join a waitlist, contact us, or send product feedback, we collect the information you provide (typically email and message content) and delivery metadata.

We do not knowingly collect information from children under 16. The Service is intended for professional engineers.

## 3. How we use information

We use information to:

- provide, secure, and improve the Service;
- create and authenticate accounts, and keep you signed in;
- process payments and prevent fraud;
- send transactional messages (sign-in codes, security notices, billing receipts);
- respond to support and feedback;
- measure aggregate product usage where you have not opted out and where a collector is configured;
- comply with law and enforce our Terms.

We do **not** sell your personal information. We do not use Customer Content to train Panolayer foundation models. Model providers you configure may have their own training and retention terms; review those terms before sending code to them.

## 4. AI, agents, and model providers

Panolayer is designed so that **Panolayer-owned model calls go through Guardian**, which can apply policy, inject shared context, and audit requests. Depending on your configuration, a request may include source excerpts, prompts, tool results, or repository metadata.

Please understand:

- **Local processing.** Indexing, UI state, and many verification steps can run on your device.
- **Provider processing.** Using agents, autocomplete, or other model-backed features may transmit relevant context to OpenAI-compatible endpoints or other providers you (or a managed route) select.
- **Third-party agents.** Host CLIs and Marketplace plugins can make their own network calls. Their publishers — not Panolayer — control those practices unless we operate the route.
- **Managed search.** Optional web search may use a key you supply or, for signed-in managed users, a proxied search service.

You should not send secrets, credentials, or regulated data to a model provider unless your own policy allows it. You control which projects you open and which workflows you run.

## 5. How we share information

We share information only as needed:

- **Service providers** that process data for us, such as identity (Clerk), email delivery, payments (Stripe), infrastructure, and (if enabled) analytics — under contracts that limit their use;
- **Model and search providers** you invoke through the product, as described above;
- **Your organization** if you use a team or company-managed workspace;
- **Professional advisors** and authorities when required by law or to protect rights, safety, and security;
- **A buyer** of all or part of our business, subject to this policy or successor notice.

Marketplace publishers receive only what you choose to send them by installing or running their agent.

## 6. Where information is stored

Account and website data may be stored in the United States and in other countries where we or our processors operate. Desktop project data, tokens, and local indexes typically remain on your computer under `~/.panolayer/` and related application paths unless you sync or transmit them.

If you are in the EEA, UK, or Switzerland, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) where required.

## 7. Retention

We keep account information for as long as your account is active and for a reasonable period afterward to provide support, meet legal obligations, and resolve disputes. Billing records are kept as required by tax and accounting rules. Support emails are kept as long as needed to complete the request and maintain a support history.

You can delete local project data from your machine at any time. Uninstalling the app does not automatically delete your website account; contact us to close an account.

## 8. Security

We use administrative, technical, and organizational measures appropriate to a developer tool that handles source code and credentials, including:

- TLS for website and API traffic;
- local storage of desktop tokens in the platform keychain when available;
- scoped, short-lived desktop sessions;
- policy and audit controls on Guardian-mediated model calls;
- sandboxing for Marketplace container agents, with declared permissions.

No method of transmission or storage is completely secure. You are responsible for access to devices that have the app installed and for the repositories you open.

## 9. Your rights and choices

Depending on your location, you may have the right to access, correct, delete, or export personal information, to object to or restrict certain processing, and to withdraw consent. You may also appeal a denial of a request.

To exercise these rights, email [privacy@panolayer.com](mailto:privacy@panolayer.com). We may need to verify your identity. You may lodge a complaint with a supervisory authority; we would appreciate the chance to address your concern first.

California residents may request the categories and specific pieces of personal information we have collected, and we will not discriminate against you for exercising privacy rights. We do not “sell” or “share” personal information as those terms are defined in the CCPA/CPRA for cross-context behavioral advertising.

You can:

- sign out and revoke sessions;
- decline optional analytics if a control is offered;
- choose which model providers and plugins to enable;
- stop using the Service.

## 10. Cookies and similar technologies

The website may use strictly necessary cookies or local storage for sign-in, locale (`NEXT_LOCALE`), and an explicit theme preference. We do not use advertising cookies. Browser sign-in for the desktop app opens `https://panolayer.com/desktop/sign-in` and does not require a custom URL scheme or loopback listener.

## 11. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us and we will delete it.

## 12. Third-party sites

Links to Marketplace listings, documentation sources, payment pages, or other sites are not covered by this policy. Review those parties’ policies before providing information to them.

## 13. Changes

We may update this Privacy Policy. The “Last updated” date will change, and we will provide additional notice if changes are material. Continued use after the effective date means you acknowledge the updated policy.

## 14. Contact

**Panolayer, Inc.**  
Privacy: [privacy@panolayer.com](mailto:privacy@panolayer.com)  
General: [hello@panolayer.com](mailto:hello@panolayer.com)  
Website: [https://panolayer.com](https://panolayer.com)

If we appoint an EU or UK representative, we will publish those details here.
