Privacy notes
What we keep, who can see it, and what we can't promise.
This page describes how the Panalo Students software works. It is not a reviewed legal privacy policy. Whoever runs a Panalo deployment for real students is responsible for publishing their own policy and terms, and for checking the rules that apply to them — for example on data protection and on parental consent for young users — before inviting anyone.
What is stored
| What | Where | Who can read it |
|---|---|---|
| Email and password | The authentication service. Passwords are stored as hashes. | Nobody else using Panalo. Your email is never shown to other people. |
| Month and year of birth | The database. | Only you. Used to know whether you're under 18 (a parent then has to agree) or under 13 (Panalo isn't for you yet). Never shown to anyone. |
| A parent's or guardian's consent (under 18) | The database: their email, name, relationship, year of birth, their decision and when. | Only the people who run this Panalo, as the record the law requires. |
| Username | Your profile. | People you share a conversation with. Others can only find you by typing your exact username. |
| Messages and files sent in conversations | The database and file storage, as ciphertext. | The people in that conversation, on their devices. See encryption. |
| Who is in which conversation, when messages were sent, read markers, reactions | The database, in the clear. | The server. This “metadata” is not encrypted. |
| Your days: when you first opened the app each day, your intention, how the day felt (mood, energy), one thing learned, one good thing | The database, in the clear. | Only your account. Used for the morning dawn, closing the day and your journal. Never shown to anyone, never analysed. |
| Tasks, focus sessions, calendar, goals, activity log, world name, interests | The database, in the clear. | Only your account. Access rules on the server stop anyone else reading them. |
| Archive files | A private file store (Supabase Storage, or Cloudflare R2 where the site has it turned on), in the clear. | You, or everyone in the conversation you shared a file with. Not end-to-end encrypted. |
| Security logs: when the app was used, the IP address and browser it was used from, sign-ins and errors | The database, in a locked table. Kept for 180 days, then erased automatically. | Only the people who run this Panalo, to investigate attacks or abuse, and the authorities when Indian law requires it (CERT-In Directions 2022). Never message content: that is encrypted. |
| Wrong passwords typed with a username | The database, in a locked table: the username and the time. | Nobody. Used only to stop password guessing (ten tries an hour), and erased after a day. |
| Blocks and reports | The database. | Your own blocks and reports are visible to you; reports are visible to whoever runs this Panalo. |
| Timer state, sound and motion preferences, world lighting, which Drift items you opened | Your browser, and a copy on your account so they follow you to your other devices. | Only your account. |
Encryption, exactly
- Messages and chat attachments are encrypted in your browser before they are sent. Each conversation has its own key, and only members hold a copy.
- Your private key is kept on the server, encrypted with a key derived from your password. That is what lets your history follow you to a new device. It also means that anyone who obtained both that stored key and your password could read your messages. For that reason we don't describe Panalo as “end-to-end encrypted”.
- The app itself is delivered by a web host. A compromised host could serve modified code — no browser-based app can rule that out.
- If you reset your password on a device that doesn't have your key cached, older encrypted messages can no longer be opened by you. Someone else in the conversation can share the key with you again.
- Archive files, study data and metadata are protected by server-side access rules, not by end-to-end encryption.
What Panalo does not do
- No advertising, and no selling or sharing of data with advertisers.
- No analytics or tracking scripts.
- No AI: nothing you write is sent to an AI service, and nothing is generated about you by one.
- No public profiles, follower counts or public feed.
The intro film's music, effects and any narration play from this site and your browser; nothing about you is sent anywhere to make them.
Rooms, codes and blocking
- A room's join code lets someone ask to join. A host decides who gets in; letting someone in is what gives them the room's key.
- Rooms end at the time their host set. After that they are hidden from everyone, and deleted a day later together with their messages. Files shared into a room stay in storage until their uploader deletes them or their account.
- Blocking someone hides their messages from you everywhere in Panalo and stops them adding you to conversations or rooms. They aren't told.
Under 18: a parent or guardian agrees first
- Everyone gives a month and year of birth when they join. Panalo is for people 13 and over; under 13, we can't keep an account.
- From 13 to 17, a parent or legal guardian must agree before anything is stored or shared. The student enters their parent's email; the parent gets a one-time code, signs in at the parent page with it (proving the email is theirs), reads what Panalo keeps, gives their name, relationship and year of birth, and says yes or no.
- Until they say yes, the student can't use Panalo: the server refuses to store their messages, files or study data. Reporting still works.
- A parent can withdraw at any time on the same page. The student's account is then deleted.
- Nobody is tracked, profiled or shown advertising — child or adult.
Deleting things
- You can delete your account from Safety & privacy. It removes everything of yours: your profile and keys, every message you sent (in every conversation), every file you uploaded, your study data and world, conversations only you were in, and the sign-in records kept about you. It can't be undone.
- One thing is kept, because Indian law requires it (IT Rules 2021, rule 3(1)(h)): the email address and username you registered with, and the dates you joined and left, for 180 days after you delete your account. They're locked away where nothing in the app can read them, and erased automatically after 180 days.
- Anything someone else already saved, copied or screenshotted is outside our reach. Reports you filed or that named you are kept for moderation, without your account attached.
- “Delete for everyone” removes a message from the server, but anyone could already have read or copied it.
Your rights, and how to use them
- See what's held about you. This page lists every kind of thing Panalo keeps, and inside the app you can see all of it: your profile, tasks, sessions, calendar, goals, world and files.
- Get a copy. Safety & privacy → Download my data gives you everything your account holds as a file.
- Correct it. Everything you entered can be edited where you entered it.
- Erase it. Delete your account from Safety & privacy, or delete any single thing you made.
- Withdraw consent. Deleting your account withdraws it; nothing is processed after that.
- Ask a question or make a complaint. In the app: Safety & privacy → Questions or complaints about your data. It goes straight to the people who run this Panalo, who will answer within 15 days.
Grievance Officer
K.V.Karnishh, Grievance Officer, Panalo · karnishh.education@gmail.com
For complaints about content, your data or a decision we made: email karnishh.education@gmail.com, or use Questions or complaints about your data in Safety & privacy. We acknowledge within 24 hours and resolve within 15 days (IT Rules 2021, rule 3(2)). Reports of intimate images shared without consent are acted on within 24 hours.
What it can't do yet
- Reports are stored for the people who run this Panalo to review; there is no automated moderation and no round-the-clock monitoring.
- There is no verified teacher role: a “class” is a group whose hosts are whoever created it or was made a host.
- No notifications reach you when the app is closed.
- Some preferences live only on the device you set them on.
- The full technical list is in the project's
LIMITATIONS.md.