PenomalyBack to site

Privacy Policy

Last updated: 10 August 2026

This policy explains what Penomaly ("we", "us") collects when you use penomaly.com and the Penomaly service, why we collect it, and what you can do about it.

We have tried to write this in plain English. Where a term has a specific legal meaning we say so.


1. Two different kinds of data, and why the difference matters

Penomaly handles personal data in two distinct roles, and your rights differ depending on which one applies.

Your data, where we are the controller. If you sign up for a Penomaly account, join the waitlist, or contact us, we decide how that information is used. We are the "data controller" for it.

Your subscribers' data, where we are only the processor. If you are a Penomaly customer and you upload or collect a list of subscribers, those people are your contacts. You decide what happens to their data. We only store and process it to provide the service to you, on your instructions. You are the controller and we are the "processor".

If you are a subscriber on an author's Penomaly list and you want your data removed, contact that author. They control it. We will help them act on your request, but we cannot make that decision for them.

Customers processing personal data of people in the EU or UK should also read our Data Processing Addendum, which forms part of our agreement with you.


2. What we collect

If you join the waitlist

  • Your email address
  • Optionally, which email platform you currently use and roughly how large your list is
  • The date and time you signed up

The two optional questions shape what we build first. Leaving them blank does not affect anything.

If you create an account

  • Name and email address, handled by our authentication provider
  • Your pen name, genre and the platform you are migrating from, if you tell us
  • A physical postal address, which anti-spam law requires to appear in commercial email you send
  • Billing information. We never see or store your full card number. Our payment processor handles it. We keep a token, the last four digits, the card brand, and a one-way hash of a card fingerprint used to enforce one free trial per person

When you use the service

  • Content you create: campaigns, lists, book details, swap listings
  • Subscriber records you upload or collect
  • Sending records, including delivery, bounce and complaint events
  • Basic technical logs: IP address, browser type, and timestamps, kept for security and troubleshooting

What we do not collect

We do not use advertising cookies, advertising pixels, or third-party analytics trackers on our marketing site. We do not sell personal data. We do not share it with advertisers.


3. Why we use it, and our lawful basis

What we use it forLawful basis under GDPR
Providing the service you signed up forPerformance of a contract
Taking paymentPerformance of a contract
Sending service emails, such as billing or security noticesPerformance of a contract
Waitlist emails about the launchConsent, given when you signed up
Preventing abuse, fraud and trial farmingLegitimate interests
Protecting sender reputation for all customersLegitimate interests
Meeting legal obligations, including tax and anti-spam lawLegal obligation

You can withdraw consent for the waitlist at any time by replying to any waitlist email or writing to privacy@penomaly.com. It will not affect anything we did before you withdrew.


4. Who we share it with

We use a small number of service providers, and only for the purposes below. They are contractually barred from using your data for their own ends.

ProviderRoleLocation
ClerkAuthentication and account managementUnited States
RailwayApplication hosting and databaseUnited States
Amazon Web ServicesEmail delivery, file storageUnited States
StripePayment processingUnited States
CloudflareContent delivery and denial of service protectionGlobal
AnthropicOptional AI features you choose to use, such as importing a campaign from a screenshotUnited States

A current list, with more detail, is kept in our Data Processing Addendum.

We will also disclose data if the law requires it, or to protect our rights, safety, or the safety of others. If we are ever compelled to hand over your data, we will tell you unless we are legally forbidden from doing so.

If Penomaly is acquired or merged, data may transfer as part of that transaction. You will be told before it happens and before any new privacy policy applies to you.


5. Where your data lives, and international transfers

Our infrastructure is in the United States.

If you are in the EU, the UK, or another region with data transfer rules, your data will be transferred to and stored in the United States. Where that transfer needs a safeguard, we rely on the Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where applicable. Copies are available on request.


6. How long we keep it

DataRetention
Waitlist entriesUntil launch, then deleted within 90 days unless you become a customer
Account dataFor as long as your account is open, then 90 days after closure
Subscriber data you uploadedUntil you delete it, or 90 days after your account closes
Suppression recordsKept indefinitely, deliberately. These record that somebody unsubscribed or complained. Deleting them would allow a future import to email that person again, which is exactly what they asked not to happen
Consent recordsKept while the subscriber exists and for 3 years after, as evidence that consent was given
Billing records7 years, as tax law requires
Security logs12 months

7. Your rights

Wherever you live, you can ask us to:

  • Access the personal data we hold about you
  • Correct anything inaccurate
  • Delete your data, subject to the retention rules above
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent where consent is the basis
  • Complain to your data protection authority. In the UK that is the ICO; in the EU it is your national authority

Write to privacy@penomaly.com. We will respond within 30 days. We do not charge for this and we will not make it difficult.

Californian residents have equivalent rights under the CCPA and CPRA, including the right to know, to delete, to correct, and to opt out of sale or sharing. We do not sell or share personal information as those laws define it, so there is nothing to opt out of. We will not discriminate against you for exercising any right.


8. Cookies

We use only what is necessary to make the site work:

  • Session cookies set by our authentication provider, so you stay signed in
  • Security cookies that protect against cross-site request forgery

There are no advertising cookies and no third-party analytics on the marketing site. If that ever changes we will update this policy and ask for consent first where the law requires it.


9. Security

We encrypt data in transit using TLS. Databases sit on a private network and are not exposed to the public internet. Access to production systems is limited and authenticated. Card numbers never touch our servers.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your personal data we will notify you and the relevant authority within the timescales the law requires, which under GDPR is 72 hours from becoming aware.


10. Children

Penomaly is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, write to privacy@penomaly.com and we will delete it.


11. Changes

If we change this policy we will update the date at the top. For changes that materially affect your rights we will email you at least 30 days beforehand.


12. Contact

Penomaly P.O. Box 94 Poteet, TX 78065 United States

Privacy questions: privacy@penomaly.com Everything else: support@penomaly.com