Privacy Policy
Effective July 21, 2026
What this app is
Pentima is a personal self-tracking tool. The content you write — threads, areas, dated log entries, and any photos you attach — is yours. This policy explains what we collect, how it is used, who processes it on our behalf, and what we can and cannot see. Pentima is operated by A TO Z SHELF LLC, an Illinois limited liability company (“we”).
What we collect
- Account data: the email address you sign in with, and the account identifier created for you.
- Content you create: threads, areas, log entries, notes, numeric readings, and photos you upload.
What we don’t collect
There are no analytics or behavioral tracking of any kind in Pentima — no analytics scripts, no advertising identifiers, no tracking pixels, no third-party trackers. We also do not collect location, contacts, or device fingerprints.
How your content is used
Your content is used solely to provide the app to you — to store, display, and export your record. The app does not send your content to any AI service. If you want an AI to use your record, you choose to share it by exporting it yourself. Your content is never used to train any model, and is never sold or shared for advertising.
Service providers (data processors)
We rely on a small number of providers who process data on our behalf:
- Supabase — authentication (your email + sign-in sessions).
- Turso — the database storing your content.
- Vercel — application hosting, photo (blob) storage, and server logs.
- Resend — delivers sign-in emails (your email address and the one-time code; never your content).
What we can see
Your content is encrypted in transit and at rest by our providers, but it is not end-to-end encrypted. Like most apps with a server, we could technically access stored content in the database. In practice, we access content only to debug a problem you’ve asked us about, or where the law requires it.
On your device
- Sign-in session: your login session is kept in the app’s local storage so you stay signed in.
- Cached content: the app may keep a local cache of your recent content (and your browser caches viewed photos) so it opens instantly. This cache lives only on your device and is cleared when you delete the app or clear its data.
- Widget snapshot: on iOS, a small snapshot of your open threads is stored in the app’s private container so the home-screen widget can display them. It never leaves your device.
- Face ID: the optional app lock uses Apple’s on-device authentication. We never receive biometric data.
Server logs
Like any hosted service, our infrastructure keeps standard, short-lived operational logs (request paths, timestamps, IP addresses, error reports) used only to keep the service running and diagnose failures. These are not used for analytics or profiling.
Your controls
- Export: download your full record at any time from Settings.
- Delete: permanently delete your account and all associated content — threads, areas, entries, and photos — from Settings → Delete account. This is irreversible and removes your data from our database, photo storage, and authentication provider.
Retention
Your content is retained until you delete it or delete your account. Deleting your account removes your records and photos.
Children
Pentima is not directed at children under 13, and we do not knowingly collect data from them.
Changes to this policy
If this policy changes, we will update the effective date above and, for meaningful changes, note it in the app. This page is the canonical copy of the policy; the same text ships inside the app.
Contact
Questions about this policy or your data: hello@pentima.app.