Privacy Policy
Effective Date: September 30, 2026
High Agency, Inc. ("we," "our," or "us") values your privacy. This Privacy Policy explains what information we collect, why we collect it, and how you can control it.
1. What we collect
When you use pen.dev, we collect:
Account information
- Your email address
- Your name
- A username
- A password (or other authentication credential)
Organizations & shared workspaces. If you join or create an organization or shared workspace, we also process your name, email address, and role within that organization, which are visible to its administrators and members.
Service operation & security data. We collect limited device and log data (e.g., IP address, browser/IDE version, OS, timestamps). If you use our IDE/Editor extensions, we process authentication tokens and minimal usage/diagnostic events required to operate core features. We do not collect your source code or keystrokes.
Inputs & Outputs (content) — how they flow. pen.dev processes content you submit ("Inputs") and generates results ("Outputs") through different technical paths, depending on the feature:
- Text-based AI features using your own provider accounts (e.g., code generation, design assistance, chat completions via Anthropic, OpenAI, or GitHub Copilot). Inputs and Outputs are exchanged directly between your device and the third-party AI provider, using API credentials that you supply. They do not pass through, and are not accessible to, High Agency, Inc. servers at any time.
- pen.dev Pro models (when available). If you choose a pen.dev-provided AI model ("pen.dev Pro"), your Inputs and Outputs are routed from your device through our inference partners — an AI gateway and model hosting providers listed at pen.dev/sub-processors — using service credentials provisioned by High Agency, Inc. We do not store, record, log, or cache this content on our servers, and we do not use it to train AI models.
- Image and SVG generation, image editing, and stock image features (e.g., Google Gemini, OpenAI, Quiver AI, Recraft, Unsplash). Requests, including any image you choose to edit, are transmitted through High Agency, Inc. servers to the relevant third-party provider.
- Website import. If you import a web page by entering its URL in the web app, our servers load the public page you specify and return it to your browser as editable layers. The page is processed in real time and is not stored on our servers. Importing through the desktop app's built-in browser or our browser extension happens entirely on your device.
Any local storage of Inputs or Outputs occurs solely on your device (e.g., browser localStorage or OS filesystem) for your convenience.
2. How we use your information
We use your information to:
- Let you sign in and personalize your onboarding
- Provide the cloud storage and sharing features you use
- Credit partners who refer new users to pen.dev
- Improve pen.dev based on how people actually use it
- Communicate about updates, new features, or policy changes
- Keep our systems secure and reliable
3. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on: Consent (where we ask for it, e.g., analytics cookies on shared-file pages), Legitimate interests (service operation, security, abuse/fraud prevention, product improvement/analytics, product communications to our users, and referral attribution), Contract (providing requested access and features), and Legal obligations (responding to lawful requests).
4. Analytics
We use PostHog (US Cloud) to understand how people use pen.dev.
What we collect. PostHog collects usage data (e.g., clicks, time spent in features, device/browser information, and error logs). In our implementation, these events are linked to your profile so we can provide product analytics, support, and security. We do not use analytics to target advertising. We may also create aggregated or anonymized statistics that no longer identify you.
What we do not collect. Our PostHog implementation is configured to exclude user Inputs and Outputs from analytics events. This means no prompts, no AI-generated content, and no source code are captured by analytics. We use analytics only to understand feature usage, performance, reliability, and security signals — not to track your personal activity outside of pen.dev.
No sale of data. We do not sell or rent your data.
International transfers. PostHog is hosted in the United States. For users in the EEA/UK, we rely on appropriate transfer safeguards (Standard Contractual Clauses, and for the UK, the UK Addendum/IDTA).
Error monitoring. We use Sentry to detect and diagnose crashes and errors. Error reports include technical context such as IP address, user identifier, device and OS information, and stack traces. Our implementation is configured not to include your Inputs or Outputs in error reports.
Web analytics. We also use GoatCounter, a cookie-free web analytics service, to measure aggregate website traffic without collecting personal information.
Cookies and similar technologies. Our website and web app use cookies and browser storage that are needed to keep you signed in and to remember your settings. On the pen.dev website, PostHog also stores an identifier in cookies and browser storage to recognize returning visitors. In the web app (app.pen.dev), analytics stays off until you accept the cookie notice. You can block or delete cookies in your browser settings; sign-in and other essential features may then stop working.
Referral attribution. If you reach pen.dev through a referral or affiliate link, we store a cookie for 30 days that records the referral. If you then view our sign-up page, create an account, download the app, or make a purchase, we send a record of that event to our referral partner, Evangelist, so that the referrer can be credited. The record contains the referral identifiers, your IP address and browser user agent, and, where available, your account identifier, a hashed form of your email address, the purchase amount, and Meta (Facebook) click identifiers already stored in your browser.
4a. Third-party image and SVG providers
pen.dev uses third-party services to generate, edit, or source images and SVG graphics, including Google Gemini, OpenAI, Quiver AI, Recraft, and Unsplash.
How the image and SVG flow works. Image- and SVG-related features operate differently from text-based AI features and pen.dev Pro models. When you use image generation, SVG generation, image editing (such as background removal or vectorization), or stock-image features, your request and any content you intentionally submit, including an image you choose to edit, are transmitted through High Agency, Inc. servers to the relevant third-party provider. This transmission is the minimum technically necessary to fulfill your request and is performed in real time. We do not store, record, log, or cache this content on our servers — it is forwarded to the third-party provider and the response is returned to you along the same path. For image editing, the provider makes the edited result available at a temporary address, from which your device downloads it directly. For stock image search (Unsplash), pen.dev's agent generates search queries derived from your project context; your prompts are not transmitted verbatim to Unsplash.
Third-party retention. Once forwarded, content is subject to the third-party provider's own terms, privacy policies, and retention practices. We do not control, and are not responsible for, those practices. Your use of third-party services is also subject to the providers' own licensing terms, including any attribution or usage requirements.
International transfers. Image providers may process data outside the EEA/UK. We rely on appropriate transfer safeguards (e.g., Standard Contractual Clauses) where required.
4b. Cloud files, sharing, and collaboration
Some pen.dev features let you save files to your pen.dev workspace or share your work with others. These features work differently from the AI request flows described above: content you deliberately save or share is stored on our infrastructure (Google Cloud Platform) so we can provide these features.
What we store. When you use cloud or sharing features, we store the files and designs you save to your workspace (including their version history), preview thumbnails we generate from them, export archives you create, share links, and comments posted on shared files (including the commenter's name, the comment text, any images attached to the comment, and — for signed-in users — their account identifier).
This applies only to content you deliberately save or share using these features. The commitments above remain unchanged for everything else: AI requests continue to pass through in real time without being stored, and files you work with locally stay on your device.
Who can access shared content. By default, anyone with a share link can view, comment on, and download the shared file. Where available, sharing controls let you restrict access — for example to your organization or workspace members, specific people, or email domains — and choose what recipients can do (view, comment, or download). Restricted links require the recipient to sign in with a pen.dev account, Google, Microsoft, or a one-time code sent by email; we then process the recipient's email address and sign-in identifier to verify access and keep them signed in.
Comment notifications. When someone comments on a file you shared, we may email you a summary that includes the comment text and the file name. You can manage these emails in your account settings.
Deletion. You can delete stored files, versions, shares, and comments at any time. Deleted files and shares move to the workspace trash, where a workspace owner or admin can restore them or delete them permanently; permanent deletion removes them from our storage. Deleted comments are no longer shown. Deleting your account permanently deletes the content of your personal workspace and the shares you created, and removes your comments from shared files; content you saved in an organization's workspace stays with that organization.
5. International transfers
If we transfer personal data outside the EEA/UK, we use appropriate safeguards such as EU Standard Contractual Clauses (and, for the UK, the UK Addendum/IDTA) or rely on another valid transfer mechanism.
6. Emails, communication & sub-processors
Email. We use Twilio SendGrid to send onboarding, product communications, and transactional emails (e.g., access confirmations, account notifications, and comment notifications). To send product communications, we keep your name and email address in a contact list with this provider. You can unsubscribe from marketing emails anytime using the link inside the email. Transactional emails necessary to provide the service may still be sent.
Sub-processors. We share personal data with sub-processors acting on our instructions. A current list of our sub-processors and their purposes is maintained at pen.dev/sub-processors. We update that list prior to engaging any new sub-processor.
Data handled. These sub-processors process account data and operational metadata (e.g., email addresses, authentication tokens, usage events, error logs). Our infrastructure providers also store the cloud files and shared content described in Section 4b, and our email provider delivers comment notifications that include comment text. Sub-processors do not receive or store Inputs/Outputs from text-based AI features used with your own provider accounts, which are exchanged directly between your device and the relevant third-party AI provider. Where you use pen.dev Pro models, your Inputs and Outputs are routed through the inference partners identified at pen.dev/sub-processors and are not stored by us. Image, SVG, image editing, and stock image requests transit through our infrastructure in real time but are not stored.
Safeguards. We do not sell or rent your data. We enter into data-processing agreements with all sub-processors and require appropriate security measures. International transfers from the EEA/UK rely on Standard Contractual Clauses (and, for the UK, the UK Addendum/IDTA) or another valid transfer mechanism.
Data Processing Agreement (DPA). For regulated, enterprise, or business customers requiring a signed Data Processing Agreement, please contact hq@pen.dev.
7. How we store and protect data
Inputs and Outputs. Inputs and Outputs from text-based AI features used with your own provider accounts are not stored on our servers — they are exchanged directly between your device and the relevant third-party AI provider. Inputs and Outputs from pen.dev Pro models are routed through our inference partners in real time and are not stored, recorded, logged, or cached on our servers. Image, SVG generation, image editing, and stock image requests likewise transit through our infrastructure in real time and are not stored, recorded, logged, or cached. Inputs and Outputs may be stored locally on your device (e.g., localStorage or filesystem), and you can delete them by clearing local storage or removing local files.
Security. Account data, operational metadata, and the cloud files and shared content described in Section 4b are stored securely using modern encryption (in transit and at rest) and access controls. We keep data only as long as needed to run pen.dev or as required by law.
Deletion requests. If you delete your account or ask us to remove your information, we will do so within a reasonable timeframe unless we are legally required to retain it.
Typical retention periods
The retention periods below apply to account data, operational metadata, and cloud files & shared content. They do not include Inputs/Outputs from text-based AI features or pen.dev Pro models (not stored on our servers) or image, SVG, image editing, and stock image content (forwarded in real time, not retained).
| Data category | Retention |
|---|---|
| Account & onboarding data | 24 months after account deletion, or until you request deletion |
| Cloud files & shared content (workspace files, version history, thumbnails, export archives, comments) | Retained until you permanently delete the content from the trash or delete your account. Permanently deleted files are removed from our storage; residual copies in backups are purged within a short period thereafter. Deleted comments are no longer displayed, and their text is erased on request. |
| Diagnostic logs (system errors and crashes; do not contain Inputs/Outputs) | 12 months |
| Marketing contacts | Until you unsubscribe or request deletion |
| Suppression records (to honor unsubscribe) | Retained as required to honor your opt-out |
| Backups | Up to 30 days before they are overwritten |
Where legally required or necessary to establish, exercise, or defend legal claims, we may retain limited data for longer.
8. Your rights
Depending on your location (including the EU/UK), you may have the right to access, rectify, erase, object to or restrict processing, and request data portability. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal, and you can complain to your local data protection authority. To exercise your rights, contact hq@pen.dev. We may ask you to verify your identity and will respond within 30 days where required by law.
9. Children
pen.dev isn't intended for children under 16, and we don't knowingly collect their information.
10. Changes
We may update this Privacy Policy from time to time.
If we make major changes, we'll post an update here or notify you directly.
11. Contact us
Data controller. For the purposes of GDPR and UK GDPR, the controller of your personal data is High Agency, Inc.
Email: hq@pen.dev
Mailing address:
High Agency, Inc.
440 N BARRANCA AVE #2993
COVINA, CA 91723
USA
For data subject requests (access, rectification, erasure, portability, objection, restriction, or withdrawal of consent), please contact us at hq@pen.dev with the subject line "Data Subject Request."