Public beta information

Privacy notice

Potential Pancake is designed for private group coordination. This notice explains the data the beta needs, where it goes, and the controls available to you.

Last updated 22 May 2025

What we process

We process your Clerk account identifier, display name, primary email, and optional profile image. Inside a plan, participants may add attendance, items, tasks, comments, journeys, ride requests, activities, polls, expenses, repayment confirmations, and private receipt evidence.

Why we process it

We use account and plan data to provide the coordination service, enforce private access, deliver essential invitations and updates, preserve financial audit history, prevent abuse, and respond to support requests. Billing and advertising profiles are not part of the private beta.

Private files and email

Receipt evidence and feedback screenshots are stored in private Azure Blob containers under random names. Authorized receipt downloads use short-lived links. Essential email is delivered through Azure Communication Services and respects notification preferences except where a security or account message is required.

Analytics

Product analytics is off by default and can be changed in Account & privacy. When enabled, it records coarse actions with opaque identifiers. It never includes plan titles, participant names, locations, comments, item names, expense descriptions or amounts, or receipt data. We do not use session replay.

Exports, departure, and deletion

You can export account data at any time. A plan owner can export the plan's structured data. Members can leave when they do not own the plan and have no unresolved repayment. Plan and account deletion each use a 30-day recovery window.

After account deletion, authentication linkage, personal settings, catalogs, saved groups, and personal templates are removed or anonymized. Shared plan and financial records retain a “Former participant” alias where deletion would damage other participants' history. Active plan records and receipt blobs are purged after a plan deletion window. Encrypted backups expire on their normal retention schedule.

Service providers and transfers

We use Clerk for authentication and Microsoft Azure for application hosting, PostgreSQL, private file storage, email, and operational telemetry. The current production target is Azure West Europe. See the processor list for purposes and review status.

Your choices and requests

Account & privacy provides export, analytics, membership, recovery, and deletion controls. For correction, access, restriction, objection, portability, or another data-subject request, use the support channel. We may need to verify that the request belongs to you.