Privacy Policy
As of: 16 August 2026
This is a courtesy translation. The German Datenschutzerklärung is the authoritative version.
1. Controller
Pyfio UG (haftungsbeschränkt), Haferweg 30 b, 29614 Soltau, Germany. Managing director: Andreas Tissen. Email: kontakt@pyfio.com.
2. The principle first
Pando sets no advertising or tracking cookies and loads no third-party analytics scripts. Stored on your device are only: the session cookie after sign-in (strictly necessary) and functional settings you choose yourself (for example the theme, or which branches are folded). That is why this website shows no cookie banner: there is nothing that would require consent under § 25 TTDSG.
3. What data we process, what for, and on which legal basis
a) Account and sign-in. When you sign in with Google we receive the email address, name and profile picture from your Google account. Google's sign-in service is only loaded when you press the sign-in button. Basis: Art. 6 (1) (b) GDPR (contract).
b) Your content. Pando's purpose is to store and serve your notes. Content is processed to provide the service: storing, syncing, sharing on your instruction, export. Basis: Art. 6 (1) (b) GDPR.
c) Agents (MCP). If you connect an AI agent, it processes the branches you grant it and writes into its own memory branch. You authorize the connection explicitly and can revoke it at any time. Basis: Art. 6 (1) (b) GDPR.
d) Usage and diagnostic data. We process event and performance data about usage (for example which features are used, timestamps, error messages, magnitudes such as the number of entries) to improve the product, find faults, prevent abuse and run the business, including internal analyses of usage behaviour. These analyses happen server-side; no advertising profiles are built and no data is given to advertising networks. Basis: Art. 6 (1) (b) and (f) GDPR; our legitimate interest is operating and developing the service.
e) Server logs. When you access the service, our infrastructure processes technically necessary data (IP address, time, requested address, user agent) for delivery, security and abuse prevention. Basis: Art. 6 (1) (f) GDPR.
f) Email. If you enable the daily digest (off by default), we send it to your account address. If you give an entry an email address, we process messages sent to it in order to file them into your tree. Basis: Art. 6 (1) (b) GDPR.
g) Payments. Payment features are handled by Stripe. We do not receive full payment data; Stripe is an independent controller for payment processing. Basis: Art. 6 (1) (b) GDPR.
4. Recipients and processors
- Cloudflare, Inc. (hosting, storage, email delivery): a worldwide network, safeguarded by EU standard contractual clauses and the EU-US Data Privacy Framework.
- Google LLC (sign-in only, and only after your click): EU-US Data Privacy Framework.
- Stripe (payments only, where used): EU-US Data Privacy Framework.
- Resend (email delivery, where used): EU-US Data Privacy Framework.
No data is passed to other third parties unless we are legally required to do so.
5. Retention
We store account data and content until you delete your account. Backups are overwritten on a rolling schedule. Server logs are kept only briefly. Statutory retention duties (for example for invoice data) remain unaffected.
6. Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Export of your content is available directly in the app. Complaints can be lodged with any data protection supervisory authority, for example the data protection commissioner of Lower Saxony, Germany.
7. No automated decision-making
We make no automated decisions with legal effect about you within the meaning of Art. 22 GDPR.
8. Changes
We update this policy when the service or the legal situation changes. The version published here applies.