Legal
Privacy Policy
Last updated: May 8, 2026
PhantomPen ("we," "our," or "us") is operated by Polsia, Inc. This Privacy Policy explains how we collect, use, store, and protect your information when you use PhantomPen at phantompen.polsia.app.
By using PhantomPen, you agree to the practices described in this policy. If you do not agree, do not use the service.
1. Information We Collect
We collect the following categories of information:
- Account data: Email address, name, and hashed password (bcrypt, 12 rounds) when you create an account.
- LinkedIn OAuth tokens: Access tokens and refresh tokens obtained when you connect your LinkedIn account. These tokens authorize us to post content to your LinkedIn profile on your behalf.
- LinkedIn profile data: Your LinkedIn profile URL, display name, and profile identifiers needed to identify your account and publish posts.
- Onboarding preferences: Your writing voice samples (LinkedIn posts you share with us), content topics, posting frequency preferences, and target audience description.
- Content data: Posts we generate on your behalf, your approval or rejection decisions, and scheduling preferences.
- Usage data: Activity logs of actions taken within the service (posts published, approvals, scheduling activity).
- Payment data: Subscription status and billing metadata. Full payment card data is processed by Stripe and never stored on our servers.
- Session data: Encrypted session identifiers stored in our database and as a secure, HTTP-only cookie in your browser.
2. How We Store OAuth Tokens
LinkedIn OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM before storage in our database. Encryption keys are stored separately from the database. Tokens are never logged, never transmitted in URLs, and never exposed to client-side JavaScript.
Tokens are only decrypted server-side at the moment they are needed to make an authenticated LinkedIn API call.
3. How We Use Your Information
- To provide the service: Generate LinkedIn posts in your voice and publish them to your profile using the LinkedIn API, with your authorization.
- To authenticate you: Maintain your session and verify your identity.
- To communicate with you: Send transactional emails (account verification, trial status, subscription receipts).
- To improve the service: Analyze aggregated usage patterns (never individual content) to improve post quality and user experience.
- To process payments: Manage your subscription through Stripe.
We do not sell your personal data. We do not use your data to train AI models for other customers. We do not use your LinkedIn posts or voice samples for any purpose other than generating content for your account.
4. What We Do With Your LinkedIn Content
The LinkedIn posts you share during onboarding are used solely to analyze your writing style and generate new posts that match your voice. This content is stored in your account profile and used only for your content generation — it is never shared with other users or used to train shared models.
Posts we generate are presented to you for review before being published. You control whether any post goes live on your LinkedIn profile.
5. Data Retention
- OAuth tokens: Permanently deleted when you disconnect LinkedIn or delete your account.
- Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
- Generated posts: Retained in your account for your review history. Deleted with your account.
- Activity logs: Retained for 12 months for debugging and service improvement, then deleted.
- Payment records: Retained for 7 years as required by financial regulations.
6. Third-Party Services
- LinkedIn: We use the LinkedIn API to publish content to your profile. LinkedIn's own privacy policy governs data on their platform. LinkedIn Privacy Policy
- Stripe: Payment processing. Stripe stores your card details; we only store subscription status. Stripe Privacy Policy
- Neon / PostgreSQL: Our database provider, hosted in the United States.
- Render: Our hosting provider, located in the United States.
- OpenAI: We use OpenAI's API to generate post content. Prompts include your writing style data. OpenAI's data usage policies apply to API usage. OpenAI API Policy
7. Your Rights
You have the following rights regarding your data:
- Disconnect LinkedIn: Remove our access to your LinkedIn account at any time from your settings page or directly from LinkedIn's app settings.
- Delete your account: Request full deletion of your account and all associated data by emailing us at phantompen@polsia.app.
- Export your data: Request an export of your data (posts generated, onboarding profile, account information) by emailing us.
- Correct your data: Update your account details at any time in your settings.
- Opt out of communications: Unsubscribe from non-essential emails using the unsubscribe link in any email we send.
8. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- The legal basis for processing your data is your consent (provided at signup) and the performance of our contract with you (providing the service).
- You have the right to data portability, restriction of processing, and erasure ("right to be forgotten").
- You have the right to lodge a complaint with your local data protection authority.
To exercise any GDPR right, contact us at phantompen@polsia.app.
9. CCPA Compliance (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information we collect and how it is used.
- The right to delete your personal information.
- The right to opt out of the sale of personal information. (We do not sell personal information.)
- The right to non-discrimination for exercising your CCPA rights.
To submit a CCPA request, email phantompen@polsia.app.
10. Security
We take the following security measures to protect your data:
- OAuth tokens encrypted at rest with AES-256-GCM.
- Passwords hashed with bcrypt (12 rounds).
- All data in transit protected by TLS/HTTPS.
- Session cookies are HTTP-only, Secure, and SameSite=Lax.
- Database access uses parameterized queries to prevent SQL injection.
- Sandbox isolation prevents agent code from accessing production credentials.
No system is 100% secure. If you discover a security vulnerability, please email us at phantompen@polsia.app before disclosing publicly.
11. Children's Privacy
PhantomPen is not intended for users under the age of 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy as our practices evolve. We will notify you by email at least 14 days before material changes take effect. Continued use of the service after changes constitutes acceptance of the updated policy.
Contact Us
Questions about this Privacy Policy? Email us at phantompen@polsia.app. We respond within 2 business days.