privacy policy

last updated: august 13, 2026

this policy explains what data penna collects, why, and how it's used. it applies to the hosted version of penna — if you're self-hosting, see the note below.

what we collect

when you create an account, we collect your name, email address, and password. when you use penna to send newsletters, we also process the content you write, your subscriber lists, and delivery data (opens, clicks, bounces, and unsubscribes) so those features can work. billing details are collected and processed by our payment provider, paddle — we never see or store your card details directly.

how we use it

we use your data to run the product: authenticate you, send your newsletters, show you analytics, process payments, and provide support. we don't sell your data, and we don't use your subscriber lists or content for anything other than delivering the service you signed up for.

cookies

we use a small number of cookies for authentication and to remember preferences like light or dark mode. we don't use third-party advertising or tracking cookies.

third-party services

we rely on a few trusted providers to run penna: hosting and infrastructure providers, an email delivery provider to send newsletters on your behalf, and paddle for billing. each only receives the data it needs to do its job.

data retention

we keep your data for as long as your account is active. if you delete your account, we remove your personal data and content within a reasonable period, except where we're required to keep records for legal or billing reasons.

self-hosting

penna is open-source. if you self-host it, this policy doesn't apply — you and your infrastructure provider are responsible for how data is stored and processed.

your rights

you can access, update, export, or delete your data at any time from your account settings. if you need help with any of this, email us and we'll sort it out.

changes to this policy

if we make meaningful changes to this policy, we'll update this page and, where appropriate, notify you by email.

questions

reach out at hello@idolo.dev if you have any questions about this policy.