Penny

Политика конфиденциальности

Версия 1.0 · действует с 25 сентября 2026 г.

Документ опубликован на английском языке; английский текст имеет силу.

This policy explains how Mintry Software, Inc. ("Mintry", "we") handles personal data in connection with Penny, a team memory that reads the chats, mail, code and data a team connects and answers questions about them.

It is written for three groups of people:

  1. Penny users: people who sign up for Penny or join a team (section 3);
  2. People in connected chats and mailboxes who never signed up: colleagues, clients, contractors, email correspondents (section 4);
  3. Visitors to our website (section 3.5).

1. Who is responsible

DataWho decides how it is used (controller)Our role
Your Penny account, team membership, sign-in, billing and payments, support, security logs, websiteMintrycontroller
Everything a team connects to Penny (messages, mail, files, code, database results) and everything Penny derives from it (facts, summaries, embeddings, answers, digests)The team's organisation (our customer)processor, acting on the customer's instructions under our Data Processing Addendum
Messages Penny receives from a Telegram chat whose bot was added but which no team has claimed yet (held at most 7 days)Mintrycontroller, until a team claims the chat
Requests we receive from people who are not our users (for example, a removal request)Mintrycontroller for handling the request itself

A Penny customer can be a company or an individual. If you create a team as an individual, you are the controller of what you connect (data-protection law may treat purely personal use as outside its scope, but Mintry applies the same protections either way).

Penny is a product of Mintry Software, Inc., a Delaware corporation, 16192 Coastal Highway, Lewes, DE 19958, USA. Contact for privacy matters: privacy@ipenny.app.

  • EU representative (Art. 27 GDPR): being appointed; until named here, write to privacy@ipenny.app.
  • UK representative (Art. 27 UK GDPR): being appointed; until named here, write to privacy@ipenny.app.
  • Data Protection Officer: not appointed. Mintry has assessed that its processing is not yet "large scale" in the sense of Art. 37 GDPR and keeps that assessment on record; it reviews it as Penny grows. Privacy questions go to the contact above.

You may contact our representatives instead of us, about any issue relating to our processing of personal data.

2. Summary

  • We never sell personal data and never use it for advertising.
  • We never use the content of connected chats, mail, files, code or databases to train AI models, and we configure our AI providers not to train on it or retain it (section 6).
  • Content is stored in Google Cloud in Belgium (europe-west1). Some processing happens in the United States and elsewhere (section 7).
  • If your messages are in a chat or mailbox connected to Penny, the team that connected it decides what happens to them. Ask that team first; we will help (section 4.4).

3. Penny users and website visitors (Mintry is controller)

3.1 What we collect

CategoryExamplesSource
Accountemail, name, Google account id and profile picture if you sign in with Google, sign-in method, language, simple/advanced modeyou, Google
Teamteam name, memberships, invites (who invited whom, when)you, your team
Linked chat identitiesyour Telegram user id and username when you link Telegram; your Slack user idyou, Telegram, Slack
Billingbilling email, billing address, tax id, card brand, last four digits and expiry, payments, invoices, Balance and usage history, auto-recharge settings. Full card numbers go to Stripe and never reach us.you, Stripe
Abuse preventionIP address at sign-up, normalised email, free-credit grantsyour device
Usage and securitysign-in times, IP address, browser, API and MCP token use, errors, audit eventsyour device, our systems
Communicationssupport emails, notices we send you (low balance, digests by email, magic links)you, our systems
Acceptance recordswhich version of the Terms, Privacy Policy and DPA you agreed to, the text of the box you ticked, when, from which IP address and browseryou
PurposeLegal basis
Create and run your account and team, sign you in, send magic linksContract (Art. 6(1)(b))
Charge for usage, auto-recharge, invoices, taxesContract; legal obligation for tax and accounting records (Art. 6(1)(c))
Service notices (low balance, changes, security, recharge changes emailed to all members)Contract; legitimate interests in keeping members informed
Prevent abuse of the free credit, fraud, and attacksLegitimate interests (Art. 6(1)(f)) in protecting the service and our customers
Security logging, incident investigationLegitimate interests; legal obligation where breach rules apply
SupportContract; legitimate interests
Aggregate product metrics (counts, costs, error rates; no content)Legitimate interests in improving Penny
Product news by emailConsent where required, otherwise legitimate interests; you can unsubscribe at any time
Legal claims and compliance with authoritiesLegal obligation; legitimate interests

Where we rely on legitimate interests, you can object (section 9).

3.3 Retention

Account data: until you delete your account (by request to support@ipenny.app until self-service deletion exists), then deleted within 30 days (backups roll off within a further 7 days). Billing and tax records: for the period accounting and tax law requires. Sign-up IP addresses: with the free-credit record, to prevent repeated free-credit grants. Acceptance records (which Terms and Privacy Policy version you agreed to, when, from which IP and browser): for as long as your account exists and afterwards for as long as needed to establish or defend legal claims. Security logs: 30 days for application logs, up to 400 days for infrastructure audit logs. Details are in the Retention and Deletion Policy.

3.4 Cookies and similar technologies

Penny uses only strictly necessary storage. We use no analytics, advertising or social-media cookies, and our fonts are served by us, not by Google Fonts.

NameTypePurposeLifetime
brain_sessioncookie, HttpOnly, Securekeeps you signed in; carries your account and current team14 days
OAuth state cookiescookie, HttpOnly, Secureprotect sign-in and connection flows against forgery10 minutes
brain.mode, languagebrowser local storageremembers Simple or Advanced mode and your languageuntil cleared

When you pay, Stripe's checkout page sets its own cookies for fraud prevention under Stripe's privacy policy. Because we only use strictly necessary storage, no consent banner is shown.

3.5 Website visitors

Our web servers log IP address, time, requested page and browser for security, kept for 30 days.

4. People in connected chats, mailboxes, repositories and databases (Mintry is processor)

4.1 Why Penny has your data

A Penny customer (a company or team) may connect:

  • Slack channels of their workspace, including history from before Penny was added;
  • Telegram groups and channels by adding the Penny bot (@penny_memory_bot), and chat history they export from Telegram Desktop and upload, including messages from before the bot was added;
  • a member's Gmail mailbox (read-only);
  • the Google Calendar calendars a member can see and chooses to share (read-only);
  • GitHub repositories (read-only), including commit authors' names and email addresses;
  • a PostgreSQL database they operate (read-only), which may contain data about their own customers.

If you write in such a chat, email someone whose mailbox is connected, attend a meeting in a connected calendar, commit to a connected repository, or appear in a connected database, Penny processes your data on that customer's behalf, even if you have never used Penny. When Penny joins a Telegram group, it posts a notice there that the chat is being remembered. In Slack, Penny does not post in channels by itself: it sends the person who connected the channels a notice to share with the people in them.

4.2 What Penny processes

Your name, username, user id and profile details as the platform shows them; the messages, emails and files you send (text, attachments, links, reactions and edits, and their time); your email address and those of other correspondents; the meetings you attend in a connected calendar (their time and title, and your name, email address and response); things said about you by others; commit metadata; database rows the customer's queries return; and what Penny derives from this: facts (such as decisions and promises attributed to you), summaries, entities, search indexes and embeddings.

Special categories of data (for example health) are not what Penny is for, but may appear in what people write. Penny masks many secrets (passwords, tokens) it recognises, and for Gmail it holds back threads that look personal or irrelevant so the team does not see them, but these safeguards are not perfect.

4.3 What the customer does with it, and who sees it

  • Everyone in the customer's Penny team can search and ask about everything the team has connected.
  • Anyone in a chat where Penny is present can ask Penny questions, and Penny's answers are visible to that whole chat. Answers may draw on the team's whole memory (other chats, mailboxes, repositories), unless the team has switched on "Answer only from this chat" for that chat. Penny is meant for a team's internal work chats; the team is told this when it binds a chat, and is responsible for binding chats with outsiders.
  • The customer's own AI assistants may read the memory through Penny's MCP connection, under the customer's control.
  • Scheduled digests summarise recent activity to team members.

The customer is responsible for having a lawful basis for this (typically its legitimate interests in keeping track of its work, or a contract), for telling you about it, and for answering your requests.

4.4 How to exercise your rights (non-users)

  1. Ask the team that connected the chat or mailbox. Its members can remove a source, and (when available) delete what Penny holds about a person.
  2. Or write to us at privacy@ipenny.app with: the chat or channel name and platform (for example, "Telegram group 'Acme x Studio'"), your username or email, and what you want (a copy, correction, deletion, or objection). We will verify your request, identify the team and forward it to them within 5 business days, and tell you we have done so. We act on the team's instructions as their processor. If we cannot identify a team, or the team does not respond within 30 days, we may disable the source and will tell you what we did.
  3. In the chat, send /forgetme (Telegram) or /penny forgetme (Slack): Penny stops remembering your messages there and deletes what it stored from you there, normally within 24 hours and at the latest within 30 days.
  4. You can also leave the chat, or ask its admin to remove the Penny bot. Removing the bot (or uninstalling the Slack app) deletes everything Penny stored from that chat, normally within hours and at the latest within 24 hours; backup copies expire within 7 days.

See also the Third-Party Notice.

4.5 Unclaimed Telegram chats (Mintry is controller)

If someone adds the Penny bot to a Telegram group but no Penny team claims the chat, Penny holds the chat's messages for at most 7 days so that nothing is lost if a team claims it, then deletes them. Mintry is the controller of this short buffer, relying on its legitimate interest (and that of the person who added the bot) in setting up the service. Nobody can read or ask about these messages until a team claims the chat.

5. Who we share data with

We share personal data only with:

  • Subprocessors that host and run Penny for us: Google Cloud (hosting, database, file storage, secrets), Temporal Technologies (workflow orchestration), OpenRouter and the AI model providers it routes to (AI processing), Stripe (payments), Resend (email). The full list, with locations and purposes, is at Subprocessors.
  • The platforms you connect (Slack, Telegram, Google, GitHub), when Penny reads from them or posts answers and digests into them. They are independent controllers under their own policies, not our subprocessors.
  • Members of your team, and people in chats where Penny answers, as described in section 4.3.
  • Authorities, when the law requires, and professional advisers.
  • A buyer or successor of the Penny business, under the same protections.

We do not sell or "share" personal data for cross-context behavioural advertising as defined in the CCPA/CPRA.

6. AI processing

  • Penny sends excerpts of connected content to large language models and embedding models (currently from Anthropic, Google and open-weight models hosted by inference providers) through OpenRouter, to extract facts, build search indexes, answer questions and write digests.

  • We route requests only to providers that do not train on the data and do not retain it after the request (zero data retention), where OpenRouter offers that option (see Subprocessors).

  • We never use your content to train or fine-tune any AI model.

  • Penny does not make decisions with legal or similarly significant effects about anyone. Its output is shown to people, who decide.

  • When Penny answers in a chat, it is identified as an AI.

7. International transfers

Penny's database, files and secrets are stored in the EU (Google Cloud, europe-west1, Belgium); workflow orchestration runs in Temporal Cloud's Frankfurt region (europe-west3). Some subprocessors process data outside the EEA and UK, in particular in the United States (OpenRouter, AI model providers, Stripe, Resend). Mintry itself is a US company: when you or your team use Penny from the EU, UK or Switzerland, personal data is transferred to Mintry in the United States (for example, when Mintry's staff administer the service), even though it is stored in Belgium. Mintry is not certified under the EU-US Data Privacy Framework; transfers to Mintry rely on the Standard Contractual Clauses in our DPA.

We protect these transfers with the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum and Swiss amendments), plus supplementary measures (encryption in transit, zero data retention at AI providers, data minimisation), or rely on the EU-US Data Privacy Framework where the recipient is certified. You can ask us for a copy of the relevant safeguards at privacy@ipenny.app.

8. Security

Each team's data is isolated in the database by row-level security, encrypted in transit and at rest, and accessible to Mintry staff only when needed to run, secure or support the service. Details: DPA Annex II.

9. Your rights

EU/EEA, UK and Switzerland. You have the right to access, correct, delete, restrict or port your data, to object to processing based on legitimate interests, to withdraw consent at any time, and to complain to a data-protection authority (in particular where you live or work; in the UK, the ICO). Because Mintry has no establishment in the EU, any EU data-protection authority may handle your complaint. For content a customer connected, see section 4.4.

California and other US states. Subject to applicable thresholds, you have the right to know, access, correct and delete personal information, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we use it only to provide the service), and not to be discriminated against for exercising your rights. You may use an authorised agent. For content a customer connected, we act as the customer's service provider and will refer your request to them.

We answer within one month (GDPR) or 45 days (CCPA), extendable where the law allows. We may need to verify your identity, for example by an email from the address concerned or a message from the chat account concerned.

10. Children

Penny is for adults. You must be 18 or older to create an account, whether you use Penny for work or personally. We do not knowingly collect data from children under 16. If you believe a child's data is in Penny, write to privacy@ipenny.app.

11. Google user data (Gmail, Calendar)

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. Penny's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Penny requests read-only access to Gmail (gmail.readonly) only when a member connects their mailbox, and read-only access to Google Calendar (calendar.events.readonly and calendar.calendarlist.readonly) only when a member connects their calendars. From Calendar, Penny reads the list of calendars the member can see, and the events of the calendars the member then ticks: calendars they can see and choose to share, not every calendar they can see, and never a calendar they did not tick. It uses mail and calendar data only to provide Penny's features to that member's team (memory, search, answers, meetings in digests); it does not use Gmail or Calendar data for advertising, does not sell it, does not transfer it except to provide those features, and does not let people at Mintry read it except with the member's explicit consent for a specific item, for security, to comply with law, or in aggregated and anonymised form for operations. The member can disconnect Gmail or Calendar in Penny at any time, untick a calendar, or revoke access at https://myaccount.google.com/permissions.

Google Workspace APIs are not used to develop, improve, or train non-personalized AI and/or ML models. Gmail and Calendar content that Penny sends to AI models is processed only to answer or remember for the member's own team, through providers configured not to retain it or train on it.

When a member connects Gmail, the visible threads of that mailbox become searchable by the member's whole Penny team; the member agrees to this on the connect screen. Threads that look personal are held back.

When a member connects Google Calendar, the meetings they share from the calendars they tick become visible to the member's whole Penny team; the member agrees to this on the connect screen and chooses, per calendar, to share meetings, everything, or busy times only. Private events are stored as busy times only, with no title, description or attendees; declined events are not stored. Attendees' email addresses are stored (with their names and responses) to link each attendee to the same person in the team's chats and mail; they are never put into the searchable text of an event. An attendee who is not a Penny user can have their address removed as described in section 4.4 and the Third-Party Notice.

11a. Telegram, Slack and GitHub

  • Telegram. This policy is the privacy policy of the Penny bot (@penny_memory_bot) for the purposes of Telegram's Bot Platform Developer Terms. The bot stores the messages of groups and channels it is added to (it runs with privacy mode off), for the team that connected the chat. It does not read personal chats other than direct messages sent to it. Send /privacy to the bot for this link, and /forgetme in a chat to stop Penny remembering your messages there and have them deleted (normally within 24 hours, at the latest 30 days). When the bot is removed from a chat, everything stored from that chat is deleted within 24 hours. History uploaded from a Telegram export is imported only 48 hours after the bot has posted a notice in the chat, so participants can opt out first. Telegram data is never used to train AI models or to build datasets.
  • Slack. Penny stores messages and files from the channels a workspace enables, for that workspace's team only, and never uses Slack data to train AI models or for any other customer. /penny forgetme works as above. When Penny is uninstalled from a workspace or its tokens are revoked, that workspace's data is deleted immediately (within 24 hours; backups within 7 days).
  • GitHub. Penny reads selected repositories read-only through the "Penny Memory" GitHub App; commit authors' names and emails are processed as part of the repository.
  • AI models used (as of September 2026): Anthropic Claude Sonnet (answers, extraction, digests), Google Gemini Flash Lite (classification), BGE-M3 (embeddings), Cohere / Qwen rerankers (search ranking). Answers can be inaccurate. Data is stored in the EU; model providers retain nothing after the request (zero data retention).

12. Changes

We will post changes here and, for material changes, notify users by email or in the product before they take effect.

13. Contact

Mintry Software, Inc., 16192 Coastal Highway, Lewes, DE 19958, USA · privacy@ipenny.app · billing@ipenny.app · EU and UK representatives: see section 1.