Privacy Policy
Last updated: 10 August 2026
This policy explains what Penomaly ("we", "us") collects when you use penomaly.com and the Penomaly service, why we collect it, and what you can do about it.
We have tried to write this in plain English. Where a term has a specific legal meaning we say so.
1. Two different kinds of data, and why the difference matters
Penomaly handles personal data in two distinct roles, and your rights differ depending on which one applies.
Your data, where we are the controller. If you sign up for a Penomaly account, join the waitlist, or contact us, we decide how that information is used. We are the "data controller" for it.
Your subscribers' data, where we are only the processor. If you are a Penomaly customer and you upload or collect a list of subscribers, those people are your contacts. You decide what happens to their data. We only store and process it to provide the service to you, on your instructions. You are the controller and we are the "processor".
If you are a subscriber on an author's Penomaly list and you want your data removed, contact that author. They control it. We will help them act on your request, but we cannot make that decision for them.
Customers processing personal data of people in the EU or UK should also read our Data Processing Addendum, which forms part of our agreement with you.
2. What we collect
If you join the waitlist
- Your email address
- Optionally, which email platform you currently use and roughly how large your list is
- The date and time you signed up
The two optional questions shape what we build first. Leaving them blank does not affect anything.
If you create an account
- Name and email address, handled by our authentication provider
- Your pen name, genre and the platform you are migrating from, if you tell us
- A physical postal address, which anti-spam law requires to appear in commercial email you send
- Billing information. We never see or store your full card number. Our payment processor handles it. We keep a token, the last four digits, the card brand, and a one-way hash of a card fingerprint used to enforce one free trial per person
When you use the service
- Content you create: campaigns, lists, book details, swap listings
- Subscriber records you upload or collect
- Sending records, including delivery, bounce and complaint events
- Basic technical logs: IP address, browser type, and timestamps, kept for security and troubleshooting
What we do not collect
We do not use advertising cookies, advertising pixels, or third-party analytics trackers on our marketing site. We do not sell personal data. We do not share it with advertisers.
3. Why we use it, and our lawful basis
| What we use it for | Lawful basis under GDPR |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Taking payment | Performance of a contract |
| Sending service emails, such as billing or security notices | Performance of a contract |
| Waitlist emails about the launch | Consent, given when you signed up |
| Preventing abuse, fraud and trial farming | Legitimate interests |
| Protecting sender reputation for all customers | Legitimate interests |
| Meeting legal obligations, including tax and anti-spam law | Legal obligation |
You can withdraw consent for the waitlist at any time by replying to any waitlist email or writing to privacy@penomaly.com. It will not affect anything we did before you withdrew.
4. Who we share it with
We use a small number of service providers, and only for the purposes below. They are contractually barred from using your data for their own ends.
| Provider | Role | Location |
|---|---|---|
| Clerk | Authentication and account management | United States |
| Railway | Application hosting and database | United States |
| Amazon Web Services | Email delivery, file storage | United States |
| Stripe | Payment processing | United States |
| Cloudflare | Content delivery and denial of service protection | Global |
| Anthropic | Optional AI features you choose to use, such as importing a campaign from a screenshot | United States |
A current list, with more detail, is kept in our Data Processing Addendum.
We will also disclose data if the law requires it, or to protect our rights, safety, or the safety of others. If we are ever compelled to hand over your data, we will tell you unless we are legally forbidden from doing so.
If Penomaly is acquired or merged, data may transfer as part of that transaction. You will be told before it happens and before any new privacy policy applies to you.
5. Where your data lives, and international transfers
Our infrastructure is in the United States.
If you are in the EU, the UK, or another region with data transfer rules, your data will be transferred to and stored in the United States. Where that transfer needs a safeguard, we rely on the Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where applicable. Copies are available on request.
6. How long we keep it
| Data | Retention |
|---|---|
| Waitlist entries | Until launch, then deleted within 90 days unless you become a customer |
| Account data | For as long as your account is open, then 90 days after closure |
| Subscriber data you uploaded | Until you delete it, or 90 days after your account closes |
| Suppression records | Kept indefinitely, deliberately. These record that somebody unsubscribed or complained. Deleting them would allow a future import to email that person again, which is exactly what they asked not to happen |
| Consent records | Kept while the subscriber exists and for 3 years after, as evidence that consent was given |
| Billing records | 7 years, as tax law requires |
| Security logs | 12 months |
7. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you
- Correct anything inaccurate
- Delete your data, subject to the retention rules above
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent where consent is the basis
- Complain to your data protection authority. In the UK that is the ICO; in the EU it is your national authority
Write to privacy@penomaly.com. We will respond within 30 days. We do not charge for this and we will not make it difficult.
Californian residents have equivalent rights under the CCPA and CPRA, including the right to know, to delete, to correct, and to opt out of sale or sharing. We do not sell or share personal information as those laws define it, so there is nothing to opt out of. We will not discriminate against you for exercising any right.
8. Cookies
We use only what is necessary to make the site work:
- Session cookies set by our authentication provider, so you stay signed in
- Security cookies that protect against cross-site request forgery
There are no advertising cookies and no third-party analytics on the marketing site. If that ever changes we will update this policy and ask for consent first where the law requires it.
9. Security
We encrypt data in transit using TLS. Databases sit on a private network and are not exposed to the public internet. Access to production systems is limited and authenticated. Card numbers never touch our servers.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your personal data we will notify you and the relevant authority within the timescales the law requires, which under GDPR is 72 hours from becoming aware.
10. Children
Penomaly is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, write to privacy@penomaly.com and we will delete it.
11. Changes
If we change this policy we will update the date at the top. For changes that materially affect your rights we will email you at least 30 days beforehand.
12. Contact
Penomaly P.O. Box 94 Poteet, TX 78065 United States
Privacy questions: privacy@penomaly.com Everything else: support@penomaly.com