Legal

Privacy Policy

Last updated: September 2, 2026

Back to Home

Pen2Pencil ("we", "us", "our") is an AI workspace and learning platform. It combines interactive courses, an online code editor, an AI assistant ("Ask"), goal-driven project workspaces ("Spaces") with automation and document tools, an AI app builder ("Vibe Coding"), a resume and portfolio builder, PDF and document tools, a live job search, a community space, and optional integrations with third-party services you connect (such as Google, GitHub, and Slack). This Privacy Policy explains what information we collect across those features, why, and the choices you have.

1. Information We Collect

Account information. Name, email address, and password (stored as a salted hash — we never store your raw password) when you sign up, or your Google profile name/email/photo if you sign in with Google.

Profile & career information you add. Bio, skills, desired role, location, resume content, portfolio content, GitHub/LinkedIn links, and uploaded files (resume PDFs, portfolio images, documents you process with our PDF tools).

Learning activity. Course progress, quiz results, code you write in the Online IDE, chapter completions, streaks, and reward points.

AI feature inputs. Prompts and content you submit to the AI assistant, tutor, mock interview, resume-rewrite, ATS checker, Vibe Coding, Space automation, or PDF AI tools (e.g. summarization/translation) — these are sent to an AI provider to generate a response, as described in Section 4.

Connected accounts. If you connect a third-party service (Google, GitHub, Slack, Notion and others) on the Integrations page, we store the OAuth access and refresh tokens — or the API key — that service issues, encrypted at rest and only for as long as the integration stays connected. See Section 5.

Community content. Posts, comments, and notes you create in Discussion, Study Groups, and Notes — including content you mark private, which is visible only to you and anyone you explicitly share it with.

Job search activity. Search filters (location, role, remote-only), and which listings you apply to or save, if you use the Jobs feature.

Payment information. If you upgrade to a paid plan, payments are processed by Razorpay; we store the plan, amount, and transaction status, but never your full card or bank details — those are handled entirely by Razorpay.

Usage & device data. IP address, browser/device type, pages visited, and referring site, collected automatically via cookies and analytics (see Section 6).

2. How We Use Your Data

We use your data to: operate your account and keep you signed in; save and sync your course progress, code, resumes, portfolios, and notes; generate AI responses (tutoring, mock interviews, resume feedback) using the content you submit; match and rank job search results against your profile and filters; power the referral and AI-credit system (crediting both sides of a successful referral); process payments and manage your subscription; send account-related emails (verification codes, password resets, application confirmations); and improve the platform through aggregate, de-identified usage analysis.

We do not sell your personal information to third parties.

3. Public & Shared Content

Some content you create is intentionally public or shareable, and behaves differently from your private account data: a public portfolio (if you enable one) is visible to anyone with its link, including via search engines; a shared resume link is visible to anyone with that link; Discussion posts and comments are visible to other signed-in users; and Group Notes content is visible to members of that group only. You control each of these individually — a private resume or portfolio is never exposed unless you explicitly publish or share it.

4. AI Features & Third-Party Processing

Features like the AI assistant (Ask), AI Tutor, Mock Interview, Resume Rewrite, ATS Checker, Vibe Coding, Space automation, and the AI-powered PDF tools (summarizer, translator, PDF-to-Markdown) send the relevant text you provide to an AI provider to generate a response. By default we route these requests through the Vercel AI Gateway to large language models operated by providers that currently include OpenAI, Anthropic, Google, xAI (Grok), and DeepSeek; the specific provider and model may change as we tune quality and cost. If you connect your own AI provider key on the Integrations page, your requests run on that provider instead of ours. In every case the content is transmitted securely, is subject to the receiving provider's own data-use terms, and is not used to train Pen2Pencil's own models. Most non-AI PDF tools (merge, split, compress, rotate, watermark, etc.) run entirely in your browser — those files are never uploaded to our servers at all.

5. Connected Services & Google User Data

Some features let you connect a third-party account so Pen2Pencil can act on your behalf — for example connecting Google to send an email from your own Gmail address, add an event to your Google Calendar, create a Google Sheet, read a Google Doc you select, or list your YouTube channel; or connecting services such as GitHub, Slack, Notion, HubSpot, Vercel, Supabase, Figma, Dropbox, and others.

When you connect an account we store the access and refresh tokens (or API key) that service issues, encrypted at rest and tied to your Pen2Pencil account. We use them only to perform the specific action you ask for, only while you keep the integration connected, and you can disconnect at any time from the Integrations page — which deletes the stored credentials.

Google API disclosure. When you connect Google, Pen2Pencil accesses your Google user data through Google APIs solely to provide the features you invoke (sending mail, calendar events, Sheets, Docs, and YouTube channel data). We do not use this data for advertising, we do not sell it, we do not use it to train AI models, and we do not transfer it to others except as needed to provide the feature you requested or as required by law. Pen2Pencil's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Job Search Data

Live job listings on Pen2Pencil are aggregated from public company career pages and job boards; when you apply "on-site" via a listing, you leave Pen2Pencil and interact directly with that employer's own site under their own privacy terms. Company-posted listings and your applications submitted through Pen2Pencil are stored so you can track your application history.

7. Cookies & Analytics

We use a small number of cookie/storage categories:

  • Necessary — keeps you signed in and remembers basic preferences (e.g. language). Always active; the site cannot function without these.
  • Analytics — Google Analytics (via Google Tag Manager), which helps us understand which pages and features are used, so we can improve them. Only active if you allow it.
  • Advertising — Google AdSense, which may show ads on the site and, if you consent, personalize them based on your activity. Only active if you allow it.

You choose which of these you allow the first time you visit, and can change your choice at any time via the "Cookie Preferences" link in the site footer or, when signed in, underSettings → Privacy & Security. We use Google's Consent Mode, which means analytics and advertising cookies only start collecting data after you grant permission.

8. Data Sharing

We share data only with: service providers that help us run the platform (hosting, our database and file-storage providers, Razorpay for payments, our AI providers — currently OpenAI, Anthropic, Google, xAI (Grok) and DeepSeek, via the Vercel AI Gateway — for AI features, and Google for sign-in/analytics/ads); the third-party services you explicitly connect on the Integrations page, only to carry out the actions you request (see Section 5); other users, for content you make public or share (see Section 3); and law enforcement or regulators, only when required by law. We do not sell your personal information.

9. Data Retention

We keep your account data for as long as your account is active. If you delete your account, we remove your personal profile data and private content within a reasonable period, except where we're required to retain records (e.g. payment records) for legal or accounting purposes.

10. Data Security

Passwords are hashed, not stored in plain text; data in transit is encrypted (HTTPS); and access to production data is restricted. No system is completely secure — if you believe your account has been compromised, contact us immediately at the email below.

11. Children's Privacy

Pen2Pencil is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we'll remove it.

12. Your Rights & Choices

You can access or update most of your data directly from your Profile and Settings pages — including your resumes, portfolio, notes, and account details. You can request a copy of your data, request deletion of your account, or change your cookie preferences at any time. To exercise any of these, email us at the address below.

13. Changes to This Policy

We may update this Privacy Policy as the platform evolves. Material changes will be reflected by updating the "Last updated" date above; continued use of Pen2Pencil after a change means you accept the updated policy.

14. Contact

For privacy questions or requests, email us at lab@pen2pencil.com.