Privacy Policy
Penholder is a governance layer between your AI agents and your data. We hold as little of your data as possible, we never sell it, and we never use it to train models.
1. Who we are
Penholder ("Penholder", "we", "us") operates a hosted service that gates AI-agent writes to spreadsheets and databases behind human approval. This policy explains what we collect when you visit this site or request access, and how we handle the data you connect to the service. For privacy questions, contact privacy@penholder.ai.
2. Information we collect
- What you give us. When you request early access or book a demo, we collect your work email, company, role, the databases you run in production, and the task description you provide.
- Technical data. Standard server logs and minimal analytics (IP address, browser, pages viewed) to keep the site running and secure.
- Your connected data. If you use the service, we process the spreadsheet and database content you connect on your behalf, plus the operation log of proposals and approvals. This is your data; see Section 4.
3. How we use it
- To respond to your access request and set up a demo on your scenario.
- To provide, operate, secure, and improve the service.
- To communicate with you about the beta and design-partner program.
We rely on your consent (for access requests) and our legitimate interest in running and securing the service. We do not sell personal data, and we do not use your connected data to train machine-learning models.
4. Your connected data
When you connect a spreadsheet or database, that content is processed under your control:
- Database credentials are held in an encrypted, account-scoped secret store — never written to the audit log and never exposed to an agent.
- Agents receive a proposal channel, not raw credentials. Your data is isolated per account and read subject to your per-cell access controls.
- We act as a processor of your connected data; you remain the controller. We delete it on request or on termination.
5. Sharing & subprocessors
We share personal data only with service providers that help us operate (for example, cloud hosting and email), under contract and only as needed. We do not sell your data. We may disclose data if required by law. A current list of subprocessors is available on request.
6. Data retention
We keep access-request data for as long as needed to evaluate and follow up, and site logs for a limited period. Connected data is retained only while your account is active and deleted on request or termination.
7. Your rights
Depending on where you live (including under GDPR and CCPA), you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise any right, email privacy@penholder.ai. You can also opt out of our emails at any time.
8. Security
We use encryption in transit and at rest, account isolation, least-privilege access, and a tamper-evident audit log. See the Security section of our site for the product-level posture. No system is perfectly secure, but we design so that agents never hold your keys and no protected write publishes without approval.
9. Cookies
We use only essential and basic analytics cookies. We do not use advertising cookies. You can control cookies through your browser settings.
10. International transfers
We may process data in countries other than yours. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
11. Changes
We may update this policy as the product evolves. Material changes will be posted here with a new "last updated" date.
12. Contact
Questions or requests: privacy@penholder.ai.