Pando

Privacy Policy

As of: 25 September 2026

This is a courtesy translation. The German Datenschutzerklärung is the authoritative version.

1. Controller

Pyfio UG (haftungsbeschränkt), Haferweg 30 b, 29614 Soltau, Germany. Managing director: Andreas Tissen. Email: kontakt@pyfio.com.

2. The principle first

Pando sets no advertising or tracking cookies and loads no third-party analytics scripts. Stored on your device are only: the session cookie after sign-in (strictly necessary), functional settings you choose yourself (for example the theme, or which branches are folded), and, while you are signed in, a copy of your own outline together with changes not yet sent, so the app starts fast and reads without a connection. Signing out or deleting the account removes that copy. That is why this website shows no cookie banner: there is nothing that would require consent under § 25 TTDSG.

3. What data we process, what for, and on which legal basis

a) Account and sign-in. There are two ways in, and you choose which one.

With Google. We receive the email address, name and profile picture from your Google account. Google's sign-in service is only loaded when you press the sign-in button. Basis: Art. 6 (1) (b) GDPR (contract).

With a link by email. You give us your email address and we send you a single-use sign-in link. For that we store your address and a checksum of the link, not the link itself, together with when it was made, when it expires and whether it was used. The link lasts 10 minutes and works once; we delete the row after 24 hours. This email is a sign-in message and nothing else: no advertising, no tracking pixel, no other content, and you only receive it when you ask for it. Google is not involved in this way in. Basis: Art. 6 (1) (b) GDPR (contract).

The calendar stays separate. The Google Calendar is its own explicit grant with its own Google consent, whichever way you sign in. Anyone who signs in by email link gives Google no access and has no calendar connection until they grant one themselves.

b) Your content. Pando's purpose is to store and serve your notes. Content is processed to provide the service: storing, syncing, sharing on your instruction, export. If you share a branch or invite people, they see your display name and, while you work at the same time, that you are present. The display name comes from your Google account or, when you sign in by email, from the part of your address before the @; you can change it in Settings. Basis: Art. 6 (1) (b) GDPR.

c) Agents (MCP). If you connect an AI agent, it processes only the branches you grant it and the area assigned to it for its own notes. You have access to both at any time: you can read, export and delete what is there. You authorize the connection explicitly and can revoke it at any time. Basis: Art. 6 (1) (b) GDPR.

d) Usage and diagnostic data. We process event and performance data about usage (for example which features are used, timestamps, error messages, magnitudes such as the number of entries, the identifier of your browser; no texts of your entries) to improve the product, find faults, prevent abuse and run the business, including internal analyses of usage behaviour. These analyses happen server-side; no advertising profiles are built and no data is given to advertising networks. Basis: Art. 6 (1) (b) and (f) GDPR; our legitimate interest is operating and developing the service.

e) Server logs. When you access the service, our infrastructure processes technically necessary data (IP address, time, requested address, user agent) for delivery, security and abuse prevention. Basis: Art. 6 (1) (f) GDPR.

f) Email. If you enable the daily digest (off by default), we send it to your account address. If you give an entry an email address, we process messages sent to it in order to file them into your tree. Basis: Art. 6 (1) (b) GDPR.

g) Payments. Payment features are handled by Stripe. We do not receive full payment data; Stripe is an independent controller for payment processing. Basis: Art. 6 (1) (b) GDPR.

h) Feedback. If you send a message through "Send feedback" in Settings, we process your words, your account address, the page you were on and your browser's user agent in order to read the message and answer you. The message is emailed to us and also kept on our infrastructure; we keep the last 200 messages. Basis: Art. 6 (1) (b) GDPR (answering your request) and (f) GDPR (improving the service).

i) Cancellations. If you cancel through the cancellation page, we process your name, your email address, the kind of cancellation, any reason you give and the date you ask for, in order to carry out the cancellation and to send you the confirmation the law requires. The declaration is emailed to us and also kept on our infrastructure; we keep the last 200 declarations. Basis: Art. 6 (1) (b) GDPR (performance of the contract) and (c) GDPR (§ 312k BGB).

j) Where you came from, at sign-up. When you create an account, we store with it, once, how you came to Pando: the campaign tag of a link we published ourselves (for example "?src=hn"), the name of the website you came from (for example news.ycombinator.com; the name only, not the address of the page), and the path of the first Pando page you opened on that visit (for example /blog/obsidian-mcp), without any identifiers in it. We take the website's name from the referrer your browser sends with every request anyway; if you connect Pando through an AI agent, it is the name of the service that asks for the connection. Until you sign up, these details are only in the address of the links you click, and, if you sign in by email, in the sign-in link; nothing is stored on your device for this. Later sign-ins do not change them. We use them to see which ways bring people to Pando; only we, as the operator, can see them. They are deleted with your account. Separately, we count page views without reference to any person: one number per day, page, referring website name and campaign tag, with no IP address, browser identifier or account. Basis: Art. 6 (1) (f) GDPR; our legitimate interest is knowing which ways bring us users.

4. Recipients and processors

No data is passed to other third parties unless we are legally required to do so.

5. Retention

We store account data and content until you delete your account. A backup made by us exists only if you set one up yourself in Settings; it then goes to your own Dropbox or Google Drive and is subject to their terms. Independently of that, the platform the database runs on keeps copies of its own as far as that belongs to its service; see section 4. Server logs are kept only briefly. Statutory retention duties (for example for invoice data) remain unaffected.

6. Security of processing

Art. 32 GDPR asks for appropriate measures, not for guarantees. What follows describes what the service does, and where a measure has limits, the limits are written next to it. It is a description and not a promise that no attack can succeed.

Sign-in without a password. Pando has no password field, and the database holds neither a column nor a field for a password or its hash. You get in through Google, through a one-time sign-in link by email, or with an access key. Of that sign-in link we keep only a SHA-256 hash in our database, not the link itself. On its way to you it is in the clear all the same: in the email, in your browser's address bar and therefore in its history. Treat it like a password.

Second factor. You can additionally protect your account with an authenticator app (TOTP, RFC 6238). Ten recovery codes come with it: they are shown once, kept here only as SHA-256 hashes, and each one works exactly once. Not every secret can be a hash. The authenticator app's secret has to be held in recoverable form, because every check recomputes the code from it; the same is true of the credentials with which you connected Google Drive or Dropbox to us.

Session. The session cookie is HttpOnly and SameSite=Lax, and over HTTPS also Secure. It carries only an identifier; everything else lives on the server.

Keys and share links. An API key for agents is shown exactly once and stored in the database only as a SHA-256 hash. It does not expire, and the second factor does not apply to it: it is valid until you revoke it. A public share link is a key too, not merely a reference. Whoever holds it sees the shared branch with no account and no second factor. Revoke what you no longer need; both can be revoked one at a time.

Limited attempts. The sign-in doors count attempts per sender within a time window and turn further ones away for a while. That brake is deliberately built to let traffic through if it fails itself, rather than lock you out.

Who here has access. For operating the service and for troubleshooting, an account with operator rights can reach content. We do not do so without cause, but it is technically possible, and we write it here rather than tell you that nobody but you can read your notes.

Transport and storage. pando.ink is served over HTTPS. Content lives in Cloudflare's database and stores. Encryption in transit and at rest is a property of that platform and not of our own code; we add no encryption of our own. On Cloudflare as a processor, see section 4.

7. No AI model training on your content

We do not use your content to train AI models, neither our own nor anyone else's, and we do not pass it to third parties for that purpose. That covers the text of your bullets, your notes and your files as well as metadata about them. The evaluation of usage and content metadata granted in § 5 of the Terms serves to improve and steer the service within the scope of this notice; training is expressly not part of it.

It is different when you connect an agent yourself, over MCP or over our API. What you share with an agent leaves Pando and sits with that agent's provider. Their terms apply there, including on whether it is trained on, and we have no influence over that. You make that decision when you share, and you can take it back by revoking that agent's key.

8. Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Export of your content is available directly in the app. Complaints can be lodged with any data protection supervisory authority, for example the data protection commissioner of Lower Saxony, Germany.

9. No automated decision-making

We make no automated decisions with legal effect about you within the meaning of Art. 22 GDPR.

10. Changes

We update this policy when the service or the legal situation changes. The version published here applies.