Panols is designed to organize and split panoramic photos primarily on your device. This policy explains what information Panols processes, what leaves your device, why it is used, and the choices available to you.
Photos and location
Panols accesses the photos you choose to make available through Apple's Photos permission. Photo and video content, filenames, library identifiers, albums, captions, faces, and embedded photo location metadata are normally processed on your device and are not uploaded to Panols, PostHog, or RevenueCat.
If you explicitly choose Post to Instagram, Panols re-encodes the one photo you selected as a JPEG without unnecessary embedded metadata and temporarily transfers that copy through Panols' dedicated publishing service so Instagram can retrieve it. Panols does not create a photo library, listing, thumbnail, history, or staff-facing media browser. The temporary copy is deleted as soon as the posting attempt reaches a terminal result, with an independent cleanup limit of no more than one hour if immediate deletion cannot finish. Temporary media is excluded from backups. Infrastructure administrators may technically access server storage during the brief processing interval; Panols does not claim that this transfer is end-to-end encrypted or inaccessible to the hosting provider.
If you grant location permission, Panols uses your current location on your device to help position the Globe. Panols does not send precise or coarse location to its analytics or purchase processors.
Product analytics and diagnostics
Analytics is enabled by default and can be disabled at any time in Panols Settings. When enabled, Panols sends allowlisted interaction events, app and device-family metadata, and bounded crash or performance diagnostics to PostHog. Panols uses a random installation identifier; it does not send your name, email address, Apple ID, advertising identifier, photo content, photo metadata, exact coordinates, or free-form text with analytics events.
Panols disables automatic screen capture, element capture, session replay, and geolocation enrichment. Analytics is used to understand feature reliability, improve the app, and diagnose crashes and performance problems. The current PostHog project retains events for up to 84 months. Disabling Analytics stops future PostHog collection from the app; it does not automatically delete data already collected. You may request deletion using the contact below.
Apple may provide aggregate App Analytics and MetricKit diagnostics under Apple's privacy terms and the choices configured on your device.
Instagram connection and direct posting
Instagram connection is optional and is not used to create or authenticate a Panols account. Instagram owns the sign-in and consent screens, and Panols never receives your Instagram password. A one-time authorization code is exchanged through Panols' dedicated service because Meta's app secret cannot be stored in the iOS app. The resulting Instagram access token, account identifier, username, account type, and expiration date are returned immediately to your device. The access token is stored only in the iOS Keychain for that device; Panols does not retain a server-side copy.
When you choose to post, Panols sends the selected temporary JPEG and caption to Instagram only to complete that request. Instagram may retain the content and account activity as part of your Instagram account under Meta's terms and privacy notice. Panols does not use Instagram account information, captions, or media for analytics, advertising, personalization, training, or marketing.
The hosting provider's front-end access logs retain network address and bounded HTTP request metadata for seven days for security and service operation. Those logs are excluded from backups and do not contain Instagram passwords, access tokens, captions, image bytes, or Panols account identities. Panols-managed application and proxy logging is disabled for these sensitive routes.
To protect the connection service from impersonation and replay, Panols keeps encrypted, pseudonymous App Attest integrity records for up to 90 days after their last activity. These records contain hashed key and transaction identifiers, encrypted Apple attestation receipt and public-key material, assertion counters, signed app-integrity signals, and timestamps. They do not contain an Instagram password, token, account identifier, username, caption, photo, IP address, or Panols account, and are used only for app functionality and security. The encrypted database is excluded from hosting-provider backups; its encryption key is stored separately.
Disconnecting Instagram in Panols deletes the device-only credential. You can also revoke Panols in Instagram's account-access settings. The manual Share to Instagram option remains available without connecting an account or using Panols' direct-posting service.
Purchases
Purchases are processed by Apple and RevenueCat. Panols and RevenueCat receive purchase, receipt, subscription, restore, and entitlement information needed to provide Panols+ and understand purchase reliability. RevenueCat also receives the same random installation identifier and bounded app, device, distribution, and entitlement-state attributes. Panols does not receive your payment-card details.
Purchase information is kept for the service relationship and as needed for fraud prevention, accounting, legal obligations, and restoring access. A RevenueCat customer profile can be deleted at the controller's request, but deletion does not cancel a subscription managed by Apple.
Support requests
When you send feedback, Panols processes the email address and message you provide so the team can respond and improve the app. Panols opens the native Mail composer or your selected email app with the support address, subject, and support details prefilled. Those details include a random Support ID, app version/build, distribution channel when available, device model, OS version, and timestamp. The Support ID can correlate the report with privacy-safe PostHog and RevenueCat records. Panols does not transmit the message or support details automatically or through its own network stack; they are sent only if you send the email.
Resolved support messages are deleted within 90 days unless a longer period is legally required. Support messages are not used for advertising or added to product analytics.
Tracking, advertising, and sale of data
Panols does not use collected data to track you across apps or websites, does not use IDFA, does not show third-party advertising, and does not sell personal information.
Service providers
Panols uses:
- Apple for Photos, location frameworks, purchases, App Analytics, and diagnostics;
- Meta for Instagram authentication and user-initiated publishing;
- Opalstack for the dedicated Instagram connection and short-lived media service;
- PostHog for product analytics and Settings-controlled diagnostics;
- RevenueCat for purchase and entitlement management; and
- your and Panols' configured mail providers to deliver support requests.
These providers process information only for the described services and under their own terms, privacy notices, and applicable data-processing agreements. Panols requires service providers handling Panols-controlled data to apply protections consistent with this policy and applicable platform requirements.
Your choices and requests
You can change Photos and location permissions in iOS Settings, turn Analytics off in Panols Settings, manage subscriptions in your Apple Account, and request access to or deletion of information controlled by Panols. Because Panols does not require an account and uses a random installation identifier, Panols will explain any verification information needed to locate a processor record. You can disconnect Instagram from within Panols to delete the credential stored on that device, and you can separately remove Panols from Instagram's connected apps or account-access settings.
Contact hello@panols.co for privacy or deletion requests.
Children, security, and international processing
Panols is not directed to children under 13. Panols uses reasonable technical and organizational safeguards, but no transmission or storage system is completely secure. Providers may process information in the United States or other countries where they operate, subject to applicable safeguards.
Changes
Panols may update this policy when the app or its processors change. Material changes will be reflected by a new “Last updated” date and, where required, an in-app or other appropriate notice.
Contact
Questions about this policy may be sent to hello@panols.co.
