Privacy policy.
Last updated: August 18, 2026
What we collect, why we collect it, and what happens to it afterwards. This covers the pangoling website and the pangoling app, including every workspace on it.
What pangoling is
pangoling is a content marketing platform. A workspace can research search demand, draft content, and report on how that content performs. Autopilot drafts and publishes only when that workspace has turned it on. Each customer brand gets its own workspace. Everything inside a workspace (the drafts, the settings, the connected accounts, the performance data) is visible only to the people invited to that workspace.
Two people are involved in most of what follows: the customer, who runs a workspace, and the individual user, who signs in and does the work. When we say “your data” below, we mean both the account that identifies you and the material in the workspace you belong to.
Your account
Signing in has no password. You give an email address, we send a one-time link through our email provider, and following that link signs you in. There is no password to store or leak.
We keep, for as long as your account exists:
- Your name and email address.
- Your email and notification preferences.
- A session record for each sign-in: when it was created, when it expires, and the IP address and browser user agent it came from.
The session is carried in a cookie. That cookie is scoped to the app domain and shared across its subdomains, so one sign-in works across every workspace you have access to. It is a sign-in cookie and nothing else. We do not run advertising or cross-site tracking cookies.
You can edit your name, change your email preferences, sign other sessions out, and delete your account from the account page inside the app.
What you put in a workspace
Content drafts and published pieces, prompts, brand knowledge documents, keyword lists, plans, the website domain you are working on, and notes your team writes. It is your material. We store it so the product works, and we do not use it to build anything for anyone else.
Workspaces can connect other services (a CMS to publish to, an SEO data provider, a search analytics account). API keys and tokens for those connections are encrypted with AES-256-GCM before they are written to the database, using a key held outside the database.
Google user data
One feature connects a workspace to Google Search Console. It is optional and off until someone in the workspace turns it on. This section describes exactly what that connection touches.
What we ask for
- Your email address (the
openidandemailscopes). We show it in settings so you can see which Google account is connected and spot a wrong one. - Read-only Search Console access (the
webmasters.readonlyscope). This lets us read the list of properties you have verified in Search Console, and the search performance rows for the property you pick: queries, pages, clicks, impressions, click-through rate, and average position.
The scope is read-only. We cannot change anything in your Search Console account, submit anything to it, or see any other Google service.
What we do with it
- Display it in the workspace: the results and rankings views, the performance charts, and the monthly report email to that workspace.
- Inform the recommendations shown to that workspace. Queries you already get impressions for, especially the ones sitting just below the top of page one, become suggestions your team can act on.
It is visible only to members of the workspace that connected it. The small team that operates pangoling can reach workspace data when doing support, maintenance, or debugging, and does so only for those reasons.
What we do not do with it
- We do not sell it.
- We do not use it for advertising, and we do not build advertising profiles.
- We do not share it with anyone outside the service providers listed further down, who process it on our behalf to run the product.
- We do not use it to train AI or machine learning models. Text generation in pangoling runs on Anthropic’s API over your prompts, brand documents and drafts. Search Console rows are not part of that input. If someone in the workspace imports Search Console queries into the keyword list, those keywords can be part of what the writing step sees; Anthropic’s commercial API terms state that it does not train its models on API input.
How it is stored
- The OAuth refresh token is encrypted with AES-256-GCM and kept in a per-workspace secret store. The encryption key lives in the application environment, outside the database. Short-lived access tokens are held in memory only.
- The performance data is written to database rows tagged with your workspace. Those tables have Postgres row-level security forced on, so a query made without that workspace’s context returns nothing at all.
Disconnecting and deletion
- Disconnect Search Console in the app under Settings, Connections. That sends the refresh token to Google’s revoke endpoint, deletes the token from our systems, and removes the connection. We can no longer reach your Search Console after that.
- You can also revoke access from your Google account at myaccount.google.com/permissions.
- Performance data already synced stays in the workspace so past charts still make sense. Email us at [email protected] and we will delete it.
Limited Use
pangoling’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Service providers
We use a short list of outside services to run the product. They handle data on our behalf and only for the purpose named.
- Anthropic: AI text generation. Receives the prompts, brand documents and drafts a generation run needs.
- Resend: transactional email. Receives the recipient address and the message (sign-in links, reports, notifications).
- Google: the Search Console API, as described above.
- Search data providers: SEO metrics about websites, such as keyword volumes and backlinks. They receive domains and keywords, not personal data. Naming no supplier here is deliberate: the entry describes what leaves the product, which does not change when a supplier does.
- Stripe: payments, where a workspace pays by card. Card details go to Stripe and never reach us; we keep the customer and subscription identifiers Stripe gives back.
A workspace can switch on further optional integrations from its settings, such as image generation, social posting, or a CMS to publish into. Those send only what the feature needs, and only after someone in the workspace connects them.
The application and its database run on servers we manage.
How long we keep things
- Account data: while the account exists. Deleting your account anonymizes it.
- Sessions: until they expire or you sign them out. Sign-in links are one-time and expire in ten minutes.
- Workspace content and synced performance data: while the workspace exists, so the history stays useful. Deleted on request.
- Connection secrets: until the connection is removed, then deleted.
Your rights
You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Write to [email protected] from the address on the account and we will handle it. Some of it you can do yourself from the account page: edit your profile, end other sessions, delete your account.
If a workspace you belong to is run by an agency or an employer, that customer decides what goes into the workspace and who can see it. Requests about workspace content are best raised with them first, and we will help either way.
Changes
If this policy changes we update the date at the top of this page. If a change meaningfully affects what we do with your data, we will say so by email before it takes effect.
Contact
Questions, requests, or anything that reads wrong here: [email protected].