Privacy Policy

Sync, OCR, search, and export your handwritten notes

Effective: May 17, 2026

1. Who We Are

Penlo is operated by Michał Włosik EFC, ul. Północna 16/5, 54-105 Wrocław, Poland (NIP: 8942747708). In this policy, "we", "us", and "our" refer to the operator. "You" and "your" refer to you, the user of the Penlo web application and associated services (collectively, the "Service").

2. What Penlo Does

Penlo is a web application that syncs handwritten notes from e-ink tablets via cloud storage providers (Dropbox, OneDrive, and Google Drive), performs AI-powered OCR to convert handwriting to searchable digital text, and exports the results to destinations such as Notion, Obsidian-compatible Markdown, and plain text files.

When your device saves a note as a PDF to your connected cloud storage, Penlo detects the change via webhooks, downloads the PDF, processes it through an AI model for handwriting recognition and text cleanup, and stores the resulting text in your Penlo account.

Penlo also provides an MCP (Model Context Protocol) integration on the Power plan. This lets you connect AI assistants such as Claude, ChatGPT, Cursor, or VS Code to your Penlo account, so the assistant can search and read your handwritten notes during a conversation. The integration is opt-in.

Penlo only accesses files in the specific folder you designate as your sync folder. It does not browse, index, or read any other files in your cloud storage accounts.

3. Eligibility

Penlo is intended for users aged 16 and older. By using the Service, you confirm that you are at least 16 years of age. We do not knowingly collect data from anyone under 16.

4. Data We Collect

4.1 Account data

When you create an account, we collect:

4.2 Cloud storage connection data

When you connect a cloud storage provider, we store OAuth access and refresh tokens, account email, and token expiry time for Dropbox, OneDrive, or Google Drive. Used exclusively to read PDFs from your designated folder and optionally write exported text files back. OAuth tokens are stored server-side and are never exposed in client-side code.

4.3 Notebook and note data

For each notebook synced, we store: notebook metadata (file path, display name, sync timestamps), note versions (content hash, PDF storage path, page count, OCR status, AI summary), PDF files (stored in Supabase Storage), OCR text and word coordinates, and user-created or AI-suggested tags.

4.4 Destination connection data

If you connect Notion, we store your Notion OAuth integration token and the selected parent page or database ID, used exclusively to create or update pages in your Notion workspace.

4.5 Settings and preferences

Your configuration choices are stored in your user profile, including: active sync provider, sync folder path, OCR and AI processing toggles, export format preferences, and Obsidian vault configuration.

4.6 API keys and webhook settings

If you use the Penlo REST API, we store a securely hashed version of your API key (the full key is shown once and never stored). If you configure a webhook, we store the endpoint URL and optional HMAC signing secret.

4.7 Shared note links

If you create a shareable link for a notebook, a public access token is generated. Anyone with the link can view the notebook's OCR text and thumbnail. You can revoke shared links at any time.

5. How We Use Your Data

6. Third-Party Services

Penlo relies on: Google Gemini (AI OCR and text processing), Supabase (backend infrastructure, hosted in EU West), Vercel (frontend hosting), and optionally Dropbox, Microsoft OneDrive, Google Drive, Notion, and AI assistants via MCP. Each integration accesses only the specific resources you authorise.

When you connect an AI assistant via MCP, your OCR text is returned to that assistant, which then forwards it to its AI provider (e.g. Anthropic, OpenAI). Penlo does not send your data to any AI provider directly through MCP — the client you installed does. You can revoke access at any time.

7. Data Sharing

We do not sell, rent, or trade your personal data. We share data only with: third-party service providers (Section 6), webhook recipients you configure, MCP-connected AI assistants you authorise, via shared links you create, when required by law, or in the event of a business transfer.

8. Data Retention

Account data, notebooks, PDFs, OCR text, connection tokens, API keys, webhook settings, and preferences are retained for as long as your account exists. If you delete your account, all data is permanently removed within 30 days. Your original files on cloud storage are never modified or deleted by Penlo.

9. Data Security

All communication uses HTTPS/TLS encryption. OAuth tokens are stored server-side. API keys are hashed using SHA-256. Authentication is managed via Supabase Auth with row-level security (RLS). Webhook payloads can be signed with HMAC-SHA256. The backend is hosted in the EU West region.

10. Your Rights

Depending on your jurisdiction, you may have rights to: access, rectification, erasure (also via Settings → Account → Delete Account), portability (also via the REST API), objection, and restriction. Contact hello@penlo.app to exercise these rights.

11. International Data Transfers

Our infrastructure is hosted in the EU via Supabase. Third-party services including Google Gemini may process data in the United States or other regions. By using the Service, you acknowledge that your data may be transferred to and processed in countries outside your country of residence.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date. Your continued use of the Service constitutes acceptance of the updated policy.

13. Contact

Michał Włosik EFC
ul. Północna 16/5, 54-105 Wrocław, Poland
Email: hello@penlo.app