Skip to content

Privacy Policy

Last updated: January 2025

1. What we collect

  • Account data — name, email address, and authentication identifiers (including passkey / OAuth identifiers if you use them).
  • Uploaded panic logs — the Panic Full files you upload. These files are generated by iOS and may contain device identifiers such as serial numbers, build versions, and incident IDs. Treat them as customer data; upload only with the device owner's authorization.
  • Analysis data — parsed fields, rule matches, AI analyses, reports, tags, and technician notes you add.
  • Billing data — plan, payment history, and credit ledger. Card details are handled by our payment processor (Stripe) and never touch our servers.
  • Usage data — login history, activity logs, and aggregate platform metrics used to operate and secure the service.

2. How we use it

  • To provide the service: parse, analyze, store, and report on your uploads.
  • To operate billing, credits, and subscriptions.
  • To secure the platform: virus scanning, audit logs, rate limiting, abuse prevention.
  • To improve future suggestions: technician feedback (correct / incorrect diagnosis, repair outcome) is anonymized before being used for improvement. Deterministic rules remain the primary source of consistency.
  • Transactional email (verification, receipts, analysis-ready notices).

3. How we protect it

  • Encryption in transit (TLS) and encrypted storage for uploaded files.
  • Signed, short-lived upload URLs; files are not publicly listable.
  • Virus scanning on every upload.
  • Role-based access control and audit logging on the platform.
  • API keys are hashed at rest; sensitive fields are encrypted at rest.

4. Who we share it with

We do not sell your data. We share data only with the processors needed to run the service:

  • Stripe — payment processing (billing details only).
  • Resend — transactional email delivery (email address, message content).
  • AI provider — the parsed log data, rule results, and original log needed to produce an analysis. No account or billing data is sent to the AI provider.
  • Cloud infrastructure providers that host the platform under equivalent safeguards.

Shareable report links you create are accessible to anyone with the link until they expire or you revoke them — share them like you would a printed report.

5. Retention and deletion

Uploads, analyses, and reports are kept in your history while your account is active. You can delete individual items or your entire account from the dashboard; account deletion removes your uploads, analyses, and personal data from active systems, with encrypted backups expiring on their normal rotation. Billing records are retained as required for accounting and tax purposes.

6. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Most of these are self-service in the dashboard (profile, history, account deletion). For anything else, sign in and contact us via dashboard support.

7. Changes

If we change this policy materially, we will announce it in the dashboard before it takes effect and update the date above.