PhantomPen ("we," "our," or "us") is operated by Polsia, Inc. This Privacy Policy explains how we collect, use, store, and protect your information when you use PhantomPen at phantompen.polsia.app.

By using PhantomPen, you agree to the practices described in this policy. If you do not agree, do not use the service.

1. Information We Collect

We collect the following categories of information:

2. How We Store OAuth Tokens

LinkedIn OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM before storage in our database. Encryption keys are stored separately from the database. Tokens are never logged, never transmitted in URLs, and never exposed to client-side JavaScript.

Tokens are only decrypted server-side at the moment they are needed to make an authenticated LinkedIn API call.

3. How We Use Your Information

We do not sell your personal data. We do not use your data to train AI models for other customers. We do not use your LinkedIn posts or voice samples for any purpose other than generating content for your account.

4. What We Do With Your LinkedIn Content

The LinkedIn posts you share during onboarding are used solely to analyze your writing style and generate new posts that match your voice. This content is stored in your account profile and used only for your content generation — it is never shared with other users or used to train shared models.

Posts we generate are presented to you for review before being published. You control whether any post goes live on your LinkedIn profile.

5. Data Retention

6. Third-Party Services

7. Your Rights

You have the following rights regarding your data:

8. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

To exercise any GDPR right, contact us at phantompen@polsia.app.

9. CCPA Compliance (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

To submit a CCPA request, email phantompen@polsia.app.

10. Security

We take the following security measures to protect your data:

No system is 100% secure. If you discover a security vulnerability, please email us at phantompen@polsia.app before disclosing publicly.

11. Children's Privacy

PhantomPen is not intended for users under the age of 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy as our practices evolve. We will notify you by email at least 14 days before material changes take effect. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact Us

Questions about this Privacy Policy? Email us at phantompen@polsia.app. We respond within 2 business days.