Panzoe Blog
Privacy & Security15 August 20264 min read

How Panzoe Approaches Privacy and Data Protection

A plain-English tour of the protections actually built into Panzoe today — isolation, encryption, memory controls, export and deletion — and our ongoing responsibilities.

Panzoe Team · Panzoe Technologies
Layered translucent shield planes with flowing light traces, representing data protection layers

A personal AI platform asks for something significant: a slice of your life. Your plans, your projects, your questions at 11pm. That makes privacy and security not a legal page for us, but the foundation the entire product stands on.

This article explains, in plain English, the protections actually built into Panzoe today. Everything below describes implemented behaviour, not aspiration — and where our responsibilities are ongoing, we say so.

Your account is an island

The most fundamental protection is isolation: your data belongs to your account and workspace, and other users cannot reach it. Every piece of your content — conversations, memory, research, documents, files, generated work — is bound to your identity at the database level, and every request is checked against it. Another user asking for your document by its address does not get "access denied"; the system behaves as if it does not exist.

We test this aggressively and regularly, including attempts to access data across accounts the way an attacker would. Isolation is the control we treat as non-negotiable.

Signing in is defended

  • Passwords are never stored — only one-way cryptographic hashes, salted individually, so even we cannot read your password.
  • Brute-force protection locks out repeated failed attempts, including distributed ones.
  • Two-factor authentication (2FA) is available: an authenticator-app code on top of your password, with one-time backup codes.
  • Sessions are managed, not eternal: you can see your active devices and sign out any of them remotely, and password changes revoke old sessions.
  • Password reset never reveals whether an email has an account — a small detail that blocks a common snooping trick.

Connected services are encrypted and opt-in

When you connect a service like your calendar or email, the credentials that make that connection work are encrypted at rest with a dedicated key — separate from the database itself. Connections are individually permissioned, and disconnecting a service removes its data from your Panzoe Brain.

Nothing is ever connected on your behalf. No linked account, no access — it is that simple.

Your memory answers to you

Panzoe's shared memory makes the product dramatically more useful — and it is engineered to stay under your control:

  • View everything Panzoe has remembered, in plain language.
  • Delete any individual memory, or clear all of it.
  • Switch memory off entirely if you prefer.
  • Memory is used to help you — it is never shared with other users.

The reasoning behind this design has its own article: Why Shared AI Memory Matters.

Private by default

Your content is private unless you publish it. Research reports, documents, conversations — none of it is public unless you take an explicit action to share it, and research built on your private data cannot be published to the web at all. There are no dark-pattern defaults that quietly make things visible.

You can leave — with your data

Two rights we consider fundamental are built into Settings:

  • Download my data. A self-service export of your Panzoe information — profile, conversations, memory, research, documents and more — that excludes other people's data and any security-sensitive internals.
  • Delete my account. A real deletion: your profile, content, memory, files, connected-service credentials and sessions are purged. Billing records are anonymised (retained for accounting integrity without a link to you).

Even we have limited access

Administrative access inside Panzoe follows least privilege. Founder and admin tooling works on aggregated metadata — sign-ups, usage counts, revenue — not on your private content. Admin routes require elevated authorisation, and privileged actions are recorded in an audit log. Support tasks are designed to be performed without browsing anyone's conversations, documents or memory.

In transit and behind the scenes

All traffic between you and Panzoe is encrypted with HTTPS/TLS, enforced with modern browser security headers. Behind the scenes: security event logging that avoids capturing private content, alerting on suspicious activity, and consent-gated analytics — marketing trackers do not run unless you accept them in the cookie banner.

What we deliberately do not claim

You will not find "military-grade" badges here, and we do not claim certifications we do not hold. What we can honestly say: the controls above are implemented, tested, and documented internally — including a full data-protection review covering isolation testing, encryption, retention and incident response.

Most importantly: security and privacy are not features you finish. They are responsibilities you keep. Threats evolve, the product evolves, and the protections evolve with them — reviews, tests and hardening are part of our regular engineering rhythm, not a one-off project.

If you have a question or believe you have found a security issue, contact us at support@panzoe.ai. Security reports go to the top of the queue.


Learn more about Panzoe and control your AI experience — start free for 7 days at panzoe.ai.

#privacy#data protection#security#user control#encryption#trust
One AI for Life

Bring it all together with Panzoe

Your AI tools, research, writing and everyday organisation — together in one place, under your control.

Start your free 7-day trial

Get new articles by email

Personal AI, productivity and privacy — no spam, unsubscribe anytime.

Essential cookies only, plus optional analytics (Google). Policy