Last Updated: 2026-09-23
The short version
- We collect what you give us (your account and the content you create) plus basic technical data to keep the Service working.
- We don't sell your data, and we don't show you ads.
- We don't use your content to train AI models, and neither does the AI provider behind Pamela's assistant.
- You can export everything or delete your account yourself, any time, from Settings.
- Questions: support@delaene.com
Delaena Limited Company, DBA Delaene ("we," "us," "Company"), a Georgia LLC, operates Pamela (the "Service") at pamela.delaene.xyz. We are the data controller for the personal data described below.
Contact for privacy matters: support@delaene.com
Account data: name, email, password (hashed) or OAuth identity (Google/GitHub/Discord), profile info you provide.
Content you create: notes, documents, calendar events, to-dos, chat messages, project data, and other content you enter into the Service ("User Content").
Connected-account data: if you connect Google Calendar, we store OAuth tokens and sync calendar event data you authorize. If you choose to import your profile photo from LinkedIn, we save a copy of that photo as your avatar; we don't keep any other LinkedIn data or access to your LinkedIn account.
AI assistant data: if you use Pamela's chat assistant, the messages and files you send it, plus the items from your apps it needs to answer (for example, the to-dos, calendar events, notes, or projects you ask about). See "AI features" below.
Technical & usage data: IP address, browser/device information, performance metrics (page load times, error events), collected automatically via Sentry when you use the Service. When you sign up or sign in, a bot check (Cloudflare Turnstile) looks at basic browser signals to confirm you're a person.
Communications data: if you email support or use in-app sharing features, we process the content of those communications.
We do not currently use advertising trackers or sell data to data brokers.
| Purpose | Legal basis |
|---|---|
| Provide and operate the Service (store your notes, sync your calendar, etc.) | Performance of a contract with you |
| Authenticate you and secure your account | Performance of a contract / legitimate interest (security) |
| Answer your requests to the AI assistant | Performance of a contract |
| Prevent abuse (bot checks, rate limiting) | Legitimate interest (security) |
| Diagnose errors and monitor performance (Sentry) | Legitimate interest (keeping the Service reliable) |
| Send account-related emails (password reset, sharing notifications) via Resend | Performance of a contract |
| Comply with legal obligations (e.g., responding to lawful requests) | Legal obligation |
Where we rely on consent (e.g., optional marketing communications, if introduced later), you may withdraw consent at any time.
Pamela's chat assistant is powered by Google's Gemini API. Only when you use the assistant, we send Google your message, any file you attach, and the relevant items from your apps needed to answer — nothing is sent when you don't use it. We use Google's paid service, under which Google does not use this data to train or improve its models; Google may keep it for a limited time to detect abuse. We don't use your content to train AI models either.
Data from your connected Google Calendar may be included when you ask the assistant about your schedule. It's used only to answer that request.
We use the following subprocessors to operate the Service. Each processes data on our behalf under its own data processing agreement with us:
| Subprocessor | What it does | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage | All account and content data |
| Vercel | Hosts the Service | IP address and request data for every visit |
| Sentry | Error tracking, performance monitoring | Technical/usage data, IP address, error context (which may incidentally include fragments of app state at time of error) |
| Resend | Transactional email delivery | Email address, email content |
| Calendar sync, OAuth sign-in (optional, only if you connect it) | Calendar events, basic profile info | |
| Google (Gemini API) | AI assistant (only when you use it) | Your assistant messages, attachments, and related app items |
| Cloudflare | Bot check at sign-up and sign-in | Browser and device signals, IP address |
| We also use a rate-limiting service (Upstash) that briefly holds IP addresses to prevent abuse. |
Some features look things up with outside services: weather and places (Open-Meteo, Wikipedia, OpenStreetMap/Nominatim), pollen levels (Google), and flight status (AviationStack). These receive only the query you make (e.g., a city, coordinates, or a flight number), not your account identity.
We do not sell your personal information, as defined under the CCPA/CPRA.
Our main database is hosted in the United States (Virginia). Our subprocessors may process data in the United States or other countries outside your own. Where we transfer personal data from the EU/UK to a country without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) with those subprocessors.
Depending on your location, you have some or all of the following rights:
To exercise any right not available as a self-serve feature, email support@delaene.com. We will respond within the timeframe required by applicable law (typically 30 days under GDPR, 45 days under CCPA).
We use browser local storage to keep you signed in and to remember your app preferences (theme, layout, etc.) — this is strictly necessary for the Service to function and does not require consent under the ePrivacy Directive.
For users in the EU/UK/EEA/Switzerland, we ask for your consent before enabling optional session replay recording (used to help us diagnose bugs) via an in-app consent banner. You may decline at any time; declining does not affect your ability to use the Service.
We use industry-standard measures to protect your data, including encryption in transit (HTTPS), encryption of connected-account sign-in tokens (e.g., Google Calendar) before they're stored, database-level access controls (Row Level Security policies scoping every table to its owner), and restricted internal access to production systems. No system is perfectly secure, and we cannot guarantee absolute security.
If we experience a data breach affecting your personal data, we will notify affected users and relevant authorities as required by applicable law (e.g., within 72 hours of discovery under GDPR, where feasible).
The Service is not directed at children under 13, and we do not knowingly collect personal data from children under 13 (per COPPA). If we learn we've collected such data, we will delete it. Users aged 13–15 in jurisdictions requiring parental consent for data processing under GDPR must have that consent before use.
We may update this Privacy Policy from time to time. We'll notify you of material changes at least 30 days before they take effect via email or in-app notice.
Privacy questions or rights requests: support@delaene.com Mailing address: 8735 Dunwoody Place Ste R, Atlanta, GA 30350