Privacy Policy
Last updated: February 2026
Pencil ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use the Pencil IDE extension, desktop application, and website (collectively, the "Service").
Information We Collect
We may collect the following types of information:
- Account information — your email address and display name when you create an account or sign in.
- Usage data — anonymous, aggregated information about how you interact with the Service, such as feature usage and session duration.
- Device information — operating system, IDE type and version, and Pencil extension or app version.
- Design files —
.penfiles you create are stored locally on your device. We do not access or transmit your design files unless you explicitly use a cloud-syncing feature.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Authenticate your account and manage your session.
- Understand usage patterns to prioritize features and fix bugs.
- Communicate with you about updates, security notices, and support.
- Comply with legal obligations and enforce our Terms of Use.
We do not sell your personal information to third parties, and we do not use your design files to train machine-learning models.
Data Storage
Your design files are stored locally on your device by default. Account and usage data are stored on secure servers with encryption at rest and in transit. We retain your data only for as long as necessary to provide the Service or comply with legal requirements.
If you delete your account, we will remove your personal information from our servers within 30 days, except where retention is required by law.
Third-Party Services
We rely on a small number of third-party services to operate Pencil. These providers have access only to the data necessary to perform their functions and are contractually obligated to protect it:
- Authentication — for account sign-in and identity verification.
- Hosting — for serving the Pencil website and backend APIs.
- Payment processing — if and when paid plans are introduced, a PCI-compliant processor will handle transactions. We never store your full payment details.
Analytics
We use GoatCounter for website analytics. GoatCounter is a privacy-friendly, open-source analytics platform that does not use cookies, does not track users across sites, and does not collect personally identifiable information. It provides us with aggregate page-view counts and referrer data to help us understand how visitors use the site.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your personal data.
- Portability — request your data in a structured, machine-readable format.
- Objection — object to certain types of processing, such as direct marketing.
To exercise any of these rights, please contact us using the details below. We will respond within 30 days.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, through in-app notifications or email. We encourage you to review this page periodically.
Contact
If you have any questions or concerns about this Privacy Policy or our data practices, please reach out to us: