← lePanel

Privacy Policy

What we collect, why, what we send to whom, and your rights as a user.

Effective: 2026-05-26. Last updated: 2026-08-18.

We do not use your data to train AI models, and the providers that process it do so under terms that exclude training. See the subprocessor listbelow for exactly what we send to whom, and each provider’s retention terms.

1. Who we are

lePanel is operated by LEPANEL LIMITED of 38 Milson Drive, Auckland, 2110, New Zealand, under the laws of New Zealand. Contact for privacy questions: privacy@lepanel.app.

2. What we collect

Only what the service needs to run, and what you choose to give us. In full:

  • Account info: email, optional display name.
  • Workspace content: panels you compose, questions you ask (including the problem you describe during onboarding to build your panel), advisor responses, follow-up questions you put to a single advisor and its replies, debate turns from rounds where you have the advisors respond to each other after the panel has answered, signal events.
  • Profile details you choose to add: country, birth year, and how you heard about us — all optional, given at the post-onboarding card or in Settings → Profile, used to tailor advice and understand our audience (legitimate interest over data you volunteer). Editable or erasable at any time.
  • Marketing consent: whether you have opted in to occasional product-update emails, with a timestamp — recorded on a consent basis and withdrawable any time in Settings → Profile.
  • A first-party attribution cookie (panel_attr): the external site that referred you, any campaign (UTM) tags, and the page you landed on. Set only with your analytics consent and kept ~90 days as a cookie; if you create a panel, the captured values are also stored with your account profile and removed when you delete your account (see section 5). Used to understand how people find us, and never shared.
  • Billing metadata via Stripe (we never see your card number).
  • Operational telemetry: HTTP request timings, error stack traces (no request bodies, PII stripped).
  • Consent records: the Terms/Privacy versions you accepted, with a timestamp (and a best-effort IP/device string) — to demonstrate consent.

3. Why we collect it

To operate the service (run rounds, persist sessions, bill subscriptions), and to debug + improve the product. We do not sell data and we do not use your content to train models.

4. Subprocessors

We share data only with the processors needed to run the service, each receiving only what its function requires. Background jobs run inside Supabase (pgmq), not a separate processor. The per-processor detail — what each handles and where — is set out below.

Subprocessors: what each one does and where it processes
ProcessorWhat it doesWhere it processes
SupabaseDatabase and authenticationAustralia (Sydney) — your workspace data at rest
AnthropicGenerates the panel’s responsesUnited States
OpenRouterGenerates the panel’s responses where enabled (see below)United States
VoyageEmbeddings, so the panel can search your materialUnited States
StripeBilling and paymentsUnited States
ResendEmail deliveryUnited States
SentryError telemetryEU (Germany)
VercelApplication hosting — runs the server codeAustralia (Sydney) — your requests are processed there
CloudflareContent delivery for static files (images, fonts, scripts)Global edge network — served from the location nearest you

Every offshore processor handles your content solely to provide its service to us, under data-processing terms — not for advertising, resale, or training its own models.

LLM providers. Your questions, and any material you add for interview practice (the role, scenario, notes, or documents you provide), are sent to the model provider that generates the panel’s responses: Anthropic, and — where enabled — OpenRouter, which routes the request to one of a small set of United States serving providers we pin in advance. Routing cannot leave that allowlist, and we verify on every response which provider served it. All LLM processing is on a no-training basis, and content is retained only briefly — a short window, or not at all where zero-retention routing applies. These providers state their services are hosted in the United States; the specific physical region that processes a given request is not contractually guaranteed on the routed path.

Embeddings. Material you add is embedded for retrieval by Voyage. Training permission on our Voyage account has been switched off since 3 July 2026. No customer content was submitted under the provider’s earlier default terms: the only data sent before that date was our own pre-launch test content. (Note added 15 August 2026.)

Display name. If you set a display name in Settings → Profile, it is sent with your questions and your practice answers so the panel knows what to call you.

Bot & abuse protection (Cloudflare Turnstile). Our sign-up, sign-in, and waitlist forms use Cloudflare Turnstile to tell real people apart from automated abuse. When you use those forms it processes limited device and interaction signals (including your IP address) for that purpose only; it is not used for advertising and is not sold. See Cloudflare’s Turnstile Privacy Policy.

5. Retention

Most of what you create stays until you remove it. Where the law or a payment record makes us keep something longer, it is named here:

How long each kind of data is kept
DataRetention
Workspace dataPersists until you delete it.
Profile details you addPersist until you delete your account or clear the fields in Settings → Profile.
Marketing consentKept on a consent basis until you withdraw it.
Account deletionVia Settings → Privacy, schedules a hard-delete 30 days out; cancellable within the window.
Audit log rowsSurvive workspace deletion (with NULLed workspace_id) for compliance forensics.
Billing records (Stripe)Invoices and payment records are retained at Stripe for tax/accounting compliance after account deletion; the customer record itself is deleted, or anonymized where transactions exist.
Consent recordsRetained as an anonymized record of acceptance (versions + timestamps); IP address and browser details are removed on account erasure.
Feedback screenshotsDeleted after account erasure; abandoned uploads are swept within ~24 hours.
Account-deletion logThe scheduling record is retained (anonymized) as proof the erasure ran.

6. Your rights

You can see, take, correct or delete your data at any time, and most of it you can do yourself without asking us:

  • Export: download a machine-readable export of your workspace data — one JSON record per line, with a manifest listing exactly what it contains — via Settings → Privacy.
  • Delete: schedule account deletion (30-day grace) via Settings → Privacy.
  • Rectification: edit your profile (country, birth year, and how you heard about us) any time via Settings → Profile.
  • Marketing communications: withdraw consent to product-update emails any time via Settings → Profile — no email required.
  • Object: email privacy@lepanel.app to opt out of analytics.
  • 2FA: enable TOTP via Settings → Security.

7. Cookies & analytics

Strictly-necessary cookies only, by default. We set transactional cookies needed to run the service — your sign-in session, a CSRF token, and your theme preference. These require no consent and we never use them to track you across sites.

Optional analytics. With your consent we enable two optional, privacy-light extras: client-side error reporting (Sentry) to fix bugs faster, and a first-party attribution cookie (panel_attr, ~90 days) that remembers how you found us (see section 2). Both are off until you opt in: we ask via a cookie banner and only turn them on if you choose “Accept all.” Your choice is stored in a single first-party preference cookie (panel_cookie_consent, ~1 year) so we don’t ask again. If your browser sends a Global Privacy Control signal, we default to essential-only. You can change your mind at any time via on any legal page.

Server-side error monitoring (errors raised by our servers) runs on a legitimate-interest basis for security and reliability. It sets no cookies and no client-side tracker, and we strip personal data before any report leaves our systems — no request bodies, with cookies, auth headers, and sensitive URL parameters redacted.

8. Children

The service is for users aged 16 and over. We do not knowingly collect data from anyone under 16. You confirm you are at least 16 when you accept these policies.

9. Updates

Material changes to this policy are announced on our What’s new page with at least 14 days notice, and may require you to re-accept.

Home · Privacy · Terms · Copyright ·