Privacy Policy
What we collect, why, what we send to whom, and your rights as a user.
1. Who we are
lePanel is operated by LEPANEL LIMITED of 38 Milson Drive, Auckland, 2110, New Zealand, under the laws of New Zealand. Contact for privacy questions: privacy@lepanel.app.
2. What we collect
Only what the service needs to run, and what you choose to give us. In full:
- Account info: email, optional display name.
- Workspace content: panels you compose, questions you ask (including the problem you describe during onboarding to build your panel), advisor responses, follow-up questions you put to a single advisor and its replies, debate turns from rounds where you have the advisors respond to each other after the panel has answered, signal events.
- Profile details you choose to add: country, birth year, and how you heard about us — all optional, given at the post-onboarding card or in Settings → Profile, used to tailor advice and understand our audience (legitimate interest over data you volunteer). Editable or erasable at any time.
- Marketing consent: whether you have opted in to occasional product-update emails, with a timestamp — recorded on a consent basis and withdrawable any time in Settings → Profile.
- A first-party attribution cookie (
panel_attr): the external site that referred you, any campaign (UTM) tags, and the page you landed on. Set only with your analytics consent and kept ~90 days as a cookie; if you create a panel, the captured values are also stored with your account profile and removed when you delete your account (see section 5). Used to understand how people find us, and never shared. - Billing metadata via Stripe (we never see your card number).
- Operational telemetry: HTTP request timings, error stack traces (no request bodies, PII stripped).
- Consent records: the Terms/Privacy versions you accepted, with a timestamp (and a best-effort IP/device string) — to demonstrate consent.
3. Why we collect it
To operate the service (run rounds, persist sessions, bill subscriptions), and to debug + improve the product. We do not sell data and we do not use your content to train models.
4. Subprocessors
We share data only with the processors needed to run the service, each receiving only what its function requires. Background jobs run inside Supabase (pgmq), not a separate processor. The per-processor detail — what each handles and where — is set out below.
| Processor | What it does | Where it processes |
|---|---|---|
| Supabase | Database and authentication | Australia (Sydney) — your workspace data at rest |
| Anthropic | Generates the panel’s responses | United States |
| OpenRouter | Generates the panel’s responses where enabled (see below) | United States |
| Voyage | Embeddings, so the panel can search your material | United States |
| Stripe | Billing and payments | United States |
| Resend | Email delivery | United States |
| Sentry | Error telemetry | EU (Germany) |
| Vercel | Application hosting — runs the server code | Australia (Sydney) — your requests are processed there |
| Cloudflare | Content delivery for static files (images, fonts, scripts) | Global edge network — served from the location nearest you |
Every offshore processor handles your content solely to provide its service to us, under data-processing terms — not for advertising, resale, or training its own models.
LLM providers. Your questions, and any material you add for interview practice (the role, scenario, notes, or documents you provide), are sent to the model provider that generates the panel’s responses: Anthropic, and — where enabled — OpenRouter, which routes the request to one of a small set of United States serving providers we pin in advance. Routing cannot leave that allowlist, and we verify on every response which provider served it. All LLM processing is on a no-training basis, and content is retained only briefly — a short window, or not at all where zero-retention routing applies. These providers state their services are hosted in the United States; the specific physical region that processes a given request is not contractually guaranteed on the routed path.
Embeddings. Material you add is embedded for retrieval by Voyage. Training permission on our Voyage account has been switched off since 3 July 2026. No customer content was submitted under the provider’s earlier default terms: the only data sent before that date was our own pre-launch test content. (Note added 15 August 2026.)
Display name. If you set a display name in Settings → Profile, it is sent with your questions and your practice answers so the panel knows what to call you.
Bot & abuse protection (Cloudflare Turnstile). Our sign-up, sign-in, and waitlist forms use Cloudflare Turnstile to tell real people apart from automated abuse. When you use those forms it processes limited device and interaction signals (including your IP address) for that purpose only; it is not used for advertising and is not sold. See Cloudflare’s Turnstile Privacy Policy.
5. Retention
Most of what you create stays until you remove it. Where the law or a payment record makes us keep something longer, it is named here:
| Data | Retention |
|---|---|
| Workspace data | Persists until you delete it. |
| Profile details you add | Persist until you delete your account or clear the fields in Settings → Profile. |
| Marketing consent | Kept on a consent basis until you withdraw it. |
| Account deletion | Via Settings → Privacy, schedules a hard-delete 30 days out; cancellable within the window. |
| Audit log rows | Survive workspace deletion (with NULLed workspace_id) for compliance forensics. |
| Billing records (Stripe) | Invoices and payment records are retained at Stripe for tax/accounting compliance after account deletion; the customer record itself is deleted, or anonymized where transactions exist. |
| Consent records | Retained as an anonymized record of acceptance (versions + timestamps); IP address and browser details are removed on account erasure. |
| Feedback screenshots | Deleted after account erasure; abandoned uploads are swept within ~24 hours. |
| Account-deletion log | The scheduling record is retained (anonymized) as proof the erasure ran. |
6. Your rights
You can see, take, correct or delete your data at any time, and most of it you can do yourself without asking us:
- Export: download a machine-readable export of your workspace data — one JSON record per line, with a manifest listing exactly what it contains — via Settings → Privacy.
- Delete: schedule account deletion (30-day grace) via Settings → Privacy.
- Rectification: edit your profile (country, birth year, and how you heard about us) any time via Settings → Profile.
- Marketing communications: withdraw consent to product-update emails any time via Settings → Profile — no email required.
- Object: email privacy@lepanel.app to opt out of analytics.
- 2FA: enable TOTP via Settings → Security.
7. Cookies & analytics
Strictly-necessary cookies only, by default. We set transactional cookies needed to run the service — your sign-in session, a CSRF token, and your theme preference. These require no consent and we never use them to track you across sites.
Optional analytics. With your consent we enable two optional, privacy-light extras: client-side error reporting (Sentry) to fix bugs faster, and a first-party attribution cookie (panel_attr, ~90 days) that remembers how you found us (see section 2). Both are off until you opt in: we ask via a cookie banner and only turn them on if you choose “Accept all.” Your choice is stored in a single first-party preference cookie (panel_cookie_consent, ~1 year) so we don’t ask again. If your browser sends a Global Privacy Control signal, we default to essential-only. You can change your mind at any time via on any legal page.
Server-side error monitoring (errors raised by our servers) runs on a legitimate-interest basis for security and reliability. It sets no cookies and no client-side tracker, and we strip personal data before any report leaves our systems — no request bodies, with cookies, auth headers, and sensitive URL parameters redacted.
8. Children
The service is for users aged 16 and over. We do not knowingly collect data from anyone under 16. You confirm you are at least 16 when you accept these policies.
9. Updates
Material changes to this policy are announced on our What’s new page with at least 14 days notice, and may require you to re-accept.