Your data, in plain English.
Privacy Pal’s connected agent is an invitation-only pilot for ten adults in the United States. The public story playground needs no account. Pip reads concerns you choose to submit, explains supporting evidence, and helps you prepare next steps. Last updated: September 28, 2026.
Your story playground and local Pocket
Story progress, saved checklists, and checklists you mark reviewed are stored in this browser. Playing does not submit them to an agent or inspect your accounts. Clear them from Pocket or by clearing browser data. If browser storage is unavailable, they last only for the current visit. Story sharing sends a public story link, without your progress or checklists. Copying your checklists is a separate action you choose. Loading pages still sends ordinary hosting requests to Vercel.
What you choose to share
We process your sign-in email, submitted links, text, screenshots, preferences, case history, and exact action approvals. Connecting your phone or Outlook is optional. Do not submit passwords, authentication codes, or information you are not authorized to share.
The open waitlist
Anyone can submit an email address to express interest. We store that address and the time you asked to join in our private US-hosted Supabase database. We use it only for waitlist updates and a possible pilot invitation; it does not create an account, unlock private checks, or subscribe you to a newsletter. For spam prevention, a keyed digest of the network address is kept for up to one day; the raw address is not stored in waitlist records. Waitlist records are automatically removed after 12 months. The first live pilot remains for invited adults in the United States.
Who helps Pip
- Supabase: sign-in, a US-hosted database, and private screenshot storage.
- Resend: your email address and authentication email content to deliver sign-in links and, if invited, pilot invitations from Supabase.
- Vercel: hosting, API requests, and durable workflows.
- OpenAI: submitted content, selected evidence, and relevant case context for interpretation. API response storage and agent tracing are disabled in our application. Provider security and abuse-monitoring retention can still apply.
- Twilio, when enabled: verified phone numbers, SMS/MMS, and speech recognition for calls. Privacy Pal does not retain raw call audio.
- Microsoft, when connected: OAuth and Outlook operations. Read and send permissions are requested separately.
- Browserbase, after browser actions are qualified: short isolated browser sessions. Browser writes are currently disabled.
- Expo, if you enable native notifications: device push tokens and generic case-ready notifications.
Provider configuration and live testing are separate from code availability. The app identifies unavailable connections. We do not sell personal information or use it for advertising. This pilot does not include behavioral advertising analytics.
What stays, and for how long
Uploaded screenshots expire after 24 hours. Private conversations and case evidence expire after 30 days. Cleanup runs daily; expired uploads are inaccessible through the application before physical cleanup. Cases and evidence are inaccessible after expiry. Explicitly saved preferences and Pocket keepsakes stay until you remove them. Minimal spending records are retained to enforce monthly limits, and are disassociated from you when the account is deleted. Providers may maintain backups and operational records under their own retention terms.
Your connections and controls
The Outlook permission granted by Microsoft can be broader than Privacy Pal’s application filter. Pip only processes selected-service privacy request threads. You can revoke Pip’s stored connection and separately revoke Microsoft’s grant in your Microsoft account. Browser extension observations stay local unless you explicitly submit an origin or selected text, or enable a permitted-site origin check. Passwords, form values and unrelated history are excluded.
Pause stops new work and cancels queued actions. A request already dispatched to a provider may finish. You can export your account data, delete individual keepsakes, and delete your Privacy Pal account from My controls. This does not delete your accounts with the services you check.
Evidence, authority, and uncertainty
Published policies describe promises; they do not prove actual behavior. Pip distinguishes retrieved policy text, supplied permissions, observed settings, and unknowns. Missing or inaccessible evidence stays unverified. Findings can be incomplete or mistaken. Suspicious messages do not receive an unsupported “safe” verdict.
An approval applies only to the exact recipient, content, and action shown. Changes require another approval. MCP callers cannot approve actions on your behalf or give themselves standing authority. Disconnecting an account, submitting a deletion request, and confirming deletion are different events.
Contact and pilot support
Use Pip’s case history to retain a concern, or contact the pilot organizer through your invitation. Account export, deletion and connection revocation do not require contacting support.