privacy policy

last updated: september 13, 2026

this policy explains what data penna collects, why, and how it's used. it applies to the hosted version of penna — if you're self-hosting, see the note below.

what we collect

when you create an account, we collect your name, email address, and password. when you use penna to send newsletters, we also process the content you write, your subscriber lists, and delivery data (opens, clicks, bounces, and unsubscribes) so those features can work. billing details are collected and processed by our payment provider, paddle — we never see or store your card details directly.

how we use it

we use your data to run the product: authenticate you, send your newsletters, show you analytics, process payments, provide support, and protect platform integrity. when you send newsletters via the api, we analyze the content with ai to detect spam, phishing, and abuse that could harm deliverability. we don't sell your data, and we don't use your subscriber lists or content for any purpose other than delivering the service you signed up for.

cookies

we use a small number of cookies for authentication and to remember preferences like light or dark mode. we don't use third-party advertising or tracking cookies.

third-party services

we rely on a few trusted providers to run penna: hosting and infrastructure providers (neon for database, upstash for redis), aws ses for email delivery, paddle for billing, and groq for ai-based content moderation. each only receives the data it needs to do its job.

ai content moderation

when you send a newsletter, we analyze the subject line and content using groq (an ai service) to detect spam, phishing, scams, and other abuse that could harm deliverability for all users. this check happens before sending and takes a few seconds. the content is only sent to groq for moderation — it's not stored, trained on, or used for any other purpose. if you self-host penna, you can disable this by not setting the groq api key, and moderation will be skipped entirely.

data retention

we keep your data for as long as your account is active. if you delete your account, we remove your personal data and content within a reasonable period, except where we're required to keep records for legal or billing reasons.

self-hosting

penna is open-source. if you self-host it, this policy doesn't apply — you and your infrastructure provider are responsible for how data is stored and processed.

your rights

you can access, update, export, or delete your data at any time from your account settings. if you need help with any of this, email us and we'll sort it out.

changes to this policy

if we make meaningful changes to this policy, we'll update this page and, where appropriate, notify you by email.

questions

reach out at hello@idolo.dev if you have any questions about this policy.