← Back to Pamela

Privacy Policy

Last Updated: 2026-09-23


The short version

  • We collect what you give us (your account and the content you create) plus basic technical data to keep the Service working.
  • We don't sell your data, and we don't show you ads.
  • We don't use your content to train AI models, and neither does the AI provider behind Pamela's assistant.
  • You can export everything or delete your account yourself, any time, from Settings.
  • Questions: support@delaene.com

1. Who We Are

Delaena Limited Company, DBA Delaene ("we," "us," "Company"), a Georgia LLC, operates Pamela (the "Service") at pamela.delaene.xyz. We are the data controller for the personal data described below.

Contact for privacy matters: support@delaene.com

2. What We Collect

Account data: name, email, password (hashed) or OAuth identity (Google/GitHub/Discord), profile info you provide.

Content you create: notes, documents, calendar events, to-dos, chat messages, project data, and other content you enter into the Service ("User Content").

Connected-account data: if you connect Google Calendar, we store OAuth tokens and sync calendar event data you authorize. If you choose to import your profile photo from LinkedIn, we save a copy of that photo as your avatar; we don't keep any other LinkedIn data or access to your LinkedIn account.

AI assistant data: if you use Pamela's chat assistant, the messages and files you send it, plus the items from your apps it needs to answer (for example, the to-dos, calendar events, notes, or projects you ask about). See "AI features" below.

Technical & usage data: IP address, browser/device information, performance metrics (page load times, error events), collected automatically via Sentry when you use the Service. When you sign up or sign in, a bot check (Cloudflare Turnstile) looks at basic browser signals to confirm you're a person.

Communications data: if you email support or use in-app sharing features, we process the content of those communications.

We do not currently use advertising trackers or sell data to data brokers.

3. How We Use It & Our Legal Basis (GDPR Art. 6)

PurposeLegal basis
Provide and operate the Service (store your notes, sync your calendar, etc.)Performance of a contract with you
Authenticate you and secure your accountPerformance of a contract / legitimate interest (security)
Answer your requests to the AI assistantPerformance of a contract
Prevent abuse (bot checks, rate limiting)Legitimate interest (security)
Diagnose errors and monitor performance (Sentry)Legitimate interest (keeping the Service reliable)
Send account-related emails (password reset, sharing notifications) via ResendPerformance of a contract
Comply with legal obligations (e.g., responding to lawful requests)Legal obligation

Where we rely on consent (e.g., optional marketing communications, if introduced later), you may withdraw consent at any time.

AI features

Pamela's chat assistant is powered by Google's Gemini API. Only when you use the assistant, we send Google your message, any file you attach, and the relevant items from your apps needed to answer — nothing is sent when you don't use it. We use Google's paid service, under which Google does not use this data to train or improve its models; Google may keep it for a limited time to detect abuse. We don't use your content to train AI models either.

Data from your connected Google Calendar may be included when you ask the assistant about your schedule. It's used only to answer that request.

4. Who We Share It With (Subprocessors)

We use the following subprocessors to operate the Service. Each processes data on our behalf under its own data processing agreement with us:

SubprocessorWhat it doesData involved
SupabaseDatabase, authentication, file storageAll account and content data
VercelHosts the ServiceIP address and request data for every visit
SentryError tracking, performance monitoringTechnical/usage data, IP address, error context (which may incidentally include fragments of app state at time of error)
ResendTransactional email deliveryEmail address, email content
GoogleCalendar sync, OAuth sign-in (optional, only if you connect it)Calendar events, basic profile info
Google (Gemini API)AI assistant (only when you use it)Your assistant messages, attachments, and related app items
CloudflareBot check at sign-up and sign-inBrowser and device signals, IP address
We also use a rate-limiting service (Upstash) that briefly holds IP addresses to prevent abuse.

Some features look things up with outside services: weather and places (Open-Meteo, Wikipedia, OpenStreetMap/Nominatim), pollen levels (Google), and flight status (AviationStack). These receive only the query you make (e.g., a city, coordinates, or a flight number), not your account identity.

We do not sell your personal information, as defined under the CCPA/CPRA.

5. International Data Transfers

Our main database is hosted in the United States (Virginia). Our subprocessors may process data in the United States or other countries outside your own. Where we transfer personal data from the EU/UK to a country without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) with those subprocessors.

6. Data Retention

  • Active accounts: we retain your data for as long as your account is active.
  • Account deletion: when you delete your account, it is soft-deleted immediately (deactivated, hidden) and permanently purged 30 days later, unless you sign back in during that window, which cancels the deletion.
  • Shared/workspace content: if you're a member of a shared workspace, content you contributed that others depend on (e.g., a board you own with active members) may need to be transferred or removed before deletion completes, per our account deletion safeguards.
  • Backups: residual copies may persist briefly in backups after deletion. Backups are taken on an as-needed basis rather than a fixed automated schedule; residual copies are purged the next time backups are rotated.

7. Your Rights

Depending on your location, you have some or all of the following rights:

  • Access — request a copy of your data. You can self-serve this any time via the in-app export feature (Settings → Export Data), which produces a JSON file of everything you own.
  • Rectification — correct inaccurate data (editable directly in the app for most fields).
  • Erasure — delete your account and data (Settings → Delete Account; see retention terms above).
  • Portability — receive your data in a portable format (same export feature, machine-readable JSON).
  • Restriction / Objection — object to certain processing; contact us at support@delaene.com.
  • Withdraw consent — where processing is consent-based.
  • Lodge a complaint — with your local data protection authority (EU/UK users) or, for California residents, exercise CCPA/CPRA rights to know, delete, correct, and opt out of sale/sharing (we do not sell or share data as defined by CCPA).

To exercise any right not available as a self-serve feature, email support@delaene.com. We will respond within the timeframe required by applicable law (typically 30 days under GDPR, 45 days under CCPA).

8. Cookies & Local Storage

We use browser local storage to keep you signed in and to remember your app preferences (theme, layout, etc.) — this is strictly necessary for the Service to function and does not require consent under the ePrivacy Directive.

For users in the EU/UK/EEA/Switzerland, we ask for your consent before enabling optional session replay recording (used to help us diagnose bugs) via an in-app consent banner. You may decline at any time; declining does not affect your ability to use the Service.

9. Security

We use industry-standard measures to protect your data, including encryption in transit (HTTPS), encryption of connected-account sign-in tokens (e.g., Google Calendar) before they're stored, database-level access controls (Row Level Security policies scoping every table to its owner), and restricted internal access to production systems. No system is perfectly secure, and we cannot guarantee absolute security.

If we experience a data breach affecting your personal data, we will notify affected users and relevant authorities as required by applicable law (e.g., within 72 hours of discovery under GDPR, where feasible).

10. Children's Privacy

The Service is not directed at children under 13, and we do not knowingly collect personal data from children under 13 (per COPPA). If we learn we've collected such data, we will delete it. Users aged 13–15 in jurisdictions requiring parental consent for data processing under GDPR must have that consent before use.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We'll notify you of material changes at least 30 days before they take effect via email or in-app notice.

12. Contact

Privacy questions or rights requests: support@delaene.com Mailing address: 8735 Dunwoody Place Ste R, Atlanta, GA 30350

Change History

  • 2026-09-23 — Added a plain-language summary, an AI features section, and disclosure of hosting (Vercel), bot protection (Cloudflare), rate limiting (Upstash), and feature lookups (pollen, flight status). Noted where data is stored and that connected-account tokens are encrypted. Added optional LinkedIn profile photo import.
  • 2026-08-12 — First published version.