Privacy Policy
Last updated: August 24, 2026
Pentra ("we," "our," or "us") operates the pentra.dev website and platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and authentication credentials through our third-party provider (Clerk).
Website Data
When you connect a website to Pentra, we collect:
- Your website domain and page content (via automated crawling)
- Site metadata, keywords, and niche information
- Brand identity data (colors, logo URL, fonts) extracted programmatically
- Publishing credentials (GitHub tokens, WordPress credentials, webhook URLs)
Generated Content
We store all articles, topic clusters, and metadata generated by our AI pipeline on your behalf.
Outreach Mailbox Data
When you separately connect a dedicated outreach mailbox, we store the OAuth credentials required for the outreach mode you choose. In manual mode, Pentra sends only a message that an owner separately approves and triggers. If authority autopilot is available, explicit, versioned tenant-level consent authorizes Pentra to send one verified initial outreach email and at most two timed follow-ups in the same provider thread for an eligible opportunity. Remaining follow-ups are cancelled after a reply, exact-recipient STOP request, hard bounce, verified link acquisition, tenant parking, consent withdrawal, or sender-configuration change. Disabling authority autopilot prevents new delivery claims, although a provider attempt already claimed before disablement may still settle once so Pentra can record its actual outcome; it cannot create a later sequence step after authorization changed.
New Gmail connections do not grant Pentra permission to read your mailbox. Gmail OAuth is a consented-recipient-only channel: a public address listing, address discovery, or sender approval is not recipient consent. Before a Gmail message can be approved or sent, Pentra requires a current affirmative opt-in record for that recipient and binds its source, timestamp, purpose, and non-reversible evidence digest into the message's versioned policy receipt. Revocation or expiration invalidates unsent messages. Pentra stores the evidence digest, not the raw form, contract, request, registration, or relationship record.
Before prospect sending is enabled, an owner-triggered fixed-recipient canary must prove that hard-bounce notifications for that exact mailbox reach the current audited receiving-only relay. Each outbound message uses an unguessable, message-specific reply address whose secret is independent from its outbound message identifier. The relay forwards signed, bodyless results for authenticated replies, structured hard bounces, and exact-recipient STOP requests. Pentra's application database never stores inbound MIME, attachments, subjects, or bodies: the audited receiving provider and adapter are configured to discard attachments and content after bounded transient classification, subject to the provider retention terms disclosed for the service. We retain only resulting status, bounded identifier digests, timestamps, suppression entries, replay keys, and non-reversible evidence digests. Existing connections that previously granted Gmail readonly access may continue bounded human-reply and exact-recipient opt-out monitoring until migration; that legacy path does not automatically suppress addresses from DSNs.
Payment Information
Payment processing is handled by Stripe through Clerk Billing. We do not store your credit card details directly. Stripe's privacy policy governs payment data handling.
2. How We Use Your Information
- To crawl and analyze your website for content generation
- To generate keyword strategies and article content
- To fact-check generated content against web sources
- To publish articles to your connected platforms
- To deliver outreach you manually approve or explicitly authorize through tenant-level authority-autopilot consent, subject to recipient-level opt-in for Gmail OAuth, and to honor replies, bounces, consent revocation, and opt-out requests
- To manage your subscription and account
- To send you service-related notifications
- To improve service quality using operational telemetry and feedback that excludes Google Workspace or Gmail user data
3. Data Sharing
We share your data with the following third-party services, strictly for providing our service:
- Anthropic (Claude) — AI content generation and fact-checking
- OpenAI — web research, image generation, YouTube search
- Clerk — authentication and billing
- Convex — database and backend infrastructure
- Vercel — website hosting
- Stripe — payment processing (via Clerk)
- Google Workspace and Gmail APIs — only to provide mailbox features that you connect and explicitly request
- Inbound email relay provider — only to receive message-specific outreach replies and routed delivery-status notices, discard attachments/content under the audited retention configuration, and deliver signed receiving-only events to Pentra
We do not sell your personal data to third parties.
4. Google API Limited Use
Pentra's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace and Gmail user data, including data derived from it, is used only to provide or improve the specific user-facing mailbox feature you request. It is never used to train, retrain, or improve a generalized or non-personalized AI or machine-learning model, and it is not used for advertising, profiling, credit decisions, or sale.
Humans do not read Google Workspace, Gmail, or relayed inbound message content except when you give affirmative permission for a specific support or security investigation, when access is necessary to investigate abuse or a security incident, or when required by applicable law. Automated reply, structured-bounce, and opt-out classification is deterministic and bounded; Pentra's database stores only the status and bodyless digest receipts described above.
5. Data Retention
We retain account and site data while your account is active. Ordinary site deletion does not delete pseudonymous, account-wide outreach suppression and contact-cooldown records; they remain available to honor STOP requests and prevent duplicate contact if a site is recreated or another site in the account encounters the same recipient. You can request full-account deletion through the available account controls or by contacting us at pentrahelp@gmail.com. Once that request is verified, Pentra stops new automated execution, revokes stored publishing, search, and outreach credentials, and purges the account-wide suppression and contact-cooldown records through a bounded, resumable process after any already-claimed external operation settles.
A non-reversible, global hashed sender reputation and pacing record may be unlinked from your account and retained for no more than 90 days across account deletion or sender transfer. This bounded safety record prevents deletion, transfer, or reconnect from resetting sender warm-up and pacing; it does not contain message content, a reusable credential, or retained site content. We may also retain or pseudonymize minimal billing, abuse-prevention, quota, and provider-spend receipts when required for legal, security, or accounting purposes.
6. Data Security
We implement industry-standard security measures to protect your data, including TLS encryption in transit and encryption at rest. Publishing credentials (GitHub tokens, WordPress passwords) are stored securely in our database and only accessed during the publishing process.
7. Your Rights
Under applicable data protection laws (including GDPR), you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to or restrict processing of your data
- Withdraw consent at any time
To exercise these rights, contact us at pentrahelp@gmail.com.
8. Cookies
We use essential cookies only for authentication and session management. We do not use tracking cookies or third-party advertising cookies. Google Analytics may be used for anonymous usage statistics with your consent.
9. International Data Transfers
Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international data transfers in accordance with GDPR requirements.
10. Children's Privacy
Pentra is not intended for use by individuals under 16 years of age. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the service.
12. Contact Us
If you have questions about this Privacy Policy, contact us:
Email: pentrahelp@gmail.com
Support: pentrahelp@gmail.com
Phone: +49 1520 9530880
Address: Pentra Legal Team
Kerpener Straße 6, 50170 Kerpen, Germany