Privacy.
Plain English: we collect the minimum we need to draft good posts for you, store it securely, never sell it, and let you erase it.
What we collect
- X profile and posts. When you connect X via OAuth, we read your handle, follower counts, recent tweets, and analytics on tweets we post. The tweets are used to build your voice profile.
- Account info. Name, timezone, email (optional), and a phone number only if you choose to link one for text updates.
- Payment info. Subscription state. Card details are handled by Stripe. We never see or store them.
- The emails we send you.For every message we send — reports and follow-ups, never marketing from anyone else — we keep the address, the subject, and whether it arrived, so we can answer “did that report go out?”. We keep that log for 24 months.
- Conversations. Drafts, edits, feedback, and chat messages between you and Penwell. We use these to train your voice profile and improve the product.
- Your code activity. If you connect GitHub, we read commit messages, pull request titles and release notes from the repositories you allow — so posts can be written from what you shipped. We never read your source code.
- Your site and search data. The pages of any site you add, and — if you connect Google Search Console — read-only performance data for it: which searches show your pages, their position, and how often they are clicked.
- Bookmarks you save on X.When you visit your bookmarks with the extension installed, we store the post id, the author's handle and the text, so a bookmark can become a draft.
- Public posts we consider replying to.To build your feed of reply candidates we store public posts from X — their text, author and media — the same posts anyone can see. They are other people's posts, so we keep only what the ranking needs.
- Usage analytics.Pageviews and events via PostHog so we can see what works and what doesn't. They are anonymous until you sign in; after that they are linked to your account, including the pages you visited before you signed up.
How we use it
- Drafting posts and replies in your voice.
- Coaching you on cadence, pillars, and quality.
- Billing and account operations.
- Improving the product (in aggregate; never sold).
How we store it
Data is hosted on Supabase (eu-west-1). X OAuth tokens are encrypted at rest with AES-256-GCM. Application traffic uses TLS in transit.
Who else sees it (sub-processors)
We use a small number of trusted services. They see only what they need to function:
- Anthropic. Generates drafts, and answers the weekly questions we ask AI assistants. Sees the prompts and context we send, including your voice profile. The weekly questions never name your product — that is what keeps the answer honest.
- OpenAI (via the Vercel AI Gateway). Answers the same weekly questions. It sees the question and your category, never your product name.
- Google (via the Vercel AI Gateway). Reads the video in a post you are replying to, including what is said in it, so the draft can respond. Also answers the same weekly questions.
- Perplexity (via the Vercel AI Gateway). Answers the same weekly questions. It sees the question and your category, never your product name.
- X (Twitter). Receives posts we publish on your behalf.
- GitHub. If you connect it, we read commit messages, pull request titles and release notes from the repositories you allow.
- Google Search Console.If you connect it, we read your site's search performance. Read-only — we never change anything in your Google account.
- Supabase. Primary database and auth.
- Vercel. Application hosting.
- Upstash. Rate limiting and short-lived caches. Holds visitor IP addresses and cached page content.
- Inngest. Runs the scheduled jobs that draft and post, so job payloads carry draft text.
- PostHog. Product analytics.
- Sentry. Error and crash reports, so we can fix what breaks. Configured not to send personal data, and we do not record your screen.
- Stripe. Subscription billing. Card details stay with Stripe; we never see them.
- Sendblue.Delivers Penwell's text messages to your phone.
- Resend.Delivers Penwell's emails. Sees the address we are writing to and the message itself, and tells us when one bounces or is reported as spam.
We do not sell your data.
Your controls
- Disconnect Xfrom Settings → Integrations at any time. We immediately delete that account's row: the OAuth tokens and everything tied to that account.
- Delete your account. Email hello@penwell.io and we delete your row, drafts, and voice profile within 30 days. There is no self-serve delete button yet.
- What deletion does not remove.The free trial is one per person, so we keep a one-way fingerprint (an HMAC, not the value) of the email address, card and X account a trial was granted on. It survives account deletion on purpose — otherwise deleting an account would be a way to take another free trial — and it cannot be reversed into your details. We delete it 24 months after the trial it records.
- Stop the emails.Every email we send carries an unsubscribe link, and one click is the whole of it — there is no confirmation step and no sign-in. Your address then goes on a suppression list that every send is checked against. That list outlives your account too, for the same kind of reason: otherwise closing one would be a way to start receiving mail again. We also keep a record of when you opted out, and of any time you turned the emails back on, for 24 months — that is how we can show your request was honoured.
- Export your data.Email us and we'll send a JSON dump within 7 days.
- EU/UK rights.If you're in the EU or UK, you have rights of access, rectification, erasure, and portability under GDPR. Email us to use them.
The free AI visibility check
Anyone can run a check at penwell.io/geo on any domain, including one they do not own, with no account. Everything it reads is already public: the site's robots.txt, llms.txt, sitemap and homepage, fetched the way a crawler fetches them. For each check we store the domain, that crawl report (including the site's title and description), the question we built from it, excerpts of what each AI model answered, the names of any other products a model named instead, and the draft post we wrote. We also use the visitor's IP address to count how many new checks have been started from that address that day, and for nothing else — so people sharing one connection share one cap.
The result is a public page at penwell.io/geo/<domain> that anyone with the link can open and that search engines are allowed to index. It stays up until we take it down — we do not delete these on a schedule. If a report about your site is up and you want it gone, email hello@penwell.io with the domain and we will remove the page and the stored report, and add the domain to a list that stops the check being run on it again — so it does not come back the next time somebody looks it up. You do not need an account with us to ask, and you do not have to explain why.
Cookies
We use a session cookie for your dashboard and a small analytics cookie via PostHog for pageview attribution. No third-party advertising trackers. The Chrome extension does not send us the X cookies your browser holds.
Children
Penwell is not for anyone under 18. We do not knowingly collect data from minors.
Contact
Privacy questions or data requests: hello@penwell.io.
last updated · August 28, 2026