Privacy & security.

Last updated October 4, 2026.

Panorama is run by Panorama Technology, Inc., the “us” on this page.

Privacy

Panorama stores the verified email addresses and identities you sign in with, from Google or Apple, the name you chose, the address of your Google profile picture if you sign in with Google, your connections, your sessions, the apps you signed in to, your account preferences, including a display time zone if you choose one, the consents you give, and audit and operational records needed to run and debug the service. Google and Apple access tokens are not retained.

Sessions

In a session, each person talks privately with Panorama, the session’s AI host. The others in the session never see your messages or Panorama’s notes. The one exception is a Panorama administrator who is in the session with you, as described below. Panorama decides what to tell whom under its charter, which every session shows word for word, and it asks before sharing something you said privately unless you asked it to pass it on. When it tells everyone something at once, the message is marked as going to everyone.

What you write in a session is processed by AI model providers through OpenRouter. Requests are routed only to providers that keep no data, and OpenRouter does not log them. Panorama sees each person’s name with their email address beside it, so nobody can pass as someone else, which means everyone’s names and email addresses go to the model provider along with the session. Until someone has agreed to the current statement about how sessions are processed, Panorama is shown only their name. If you share your time zone, Panorama uses it to schedule sensibly; other people never see it.

The people in a session see each other differently. You see the full name and email address of everyone you’re connected with, and of whoever invited you while you decide whether to join. Everyone else in a session is shown to you by the first word of their name, with the first letter of their last name when someone else there has the same first name, and a number when even that is shared, never with their address. Notices in a session, such as someone joining or renaming it, name people that way too. Joining a session connects you with whoever invited you.

A session holds up to ten people. An invitation by email admits only the address it was sent to. Whoever sent an invitation can withdraw it until it is accepted, and once they have left the session, anyone still in it can; leaving a session withdraws the email and link invitations you sent that are still open. Blocking someone stops them from inviting you to sessions or asking to connect, and nobody is told who blocked them.

Inviting someone to connect works the same way. An invitation by email shows them your name and email address, as a request to connect if they’re on Panorama or as an email that lets that address join if they aren’t, and you can’t tell which. An invitation link works once, for whoever uses it first. You can also ask anyone you’re in a session with to connect: they see your name and email address, and you see them by their session name until they accept. Someone you block is shown to you in full only if you were ever connected or they asked you to connect.

Panorama encrypts each session’s name, picture, and messages itself before storing them, on top of the encryption Cloudflare, which hosts Panorama, applies to everything it stores. Panorama’s memory of a session is different: its record of everything said in it and its summaries of that, its notes, and the record of the requests it sends to the model, which hold messages and the names and email addresses of the people in the session, are encrypted only by Cloudflare, not by Panorama. Nothing in a session is end-to-end encrypted: the service reads all of it to run the session.

Administrators can’t open a session they aren’t in. Outside the sessions they are in, the only content an administrator can read is what someone chooses to send in a report from their own side of a session, and the reporter sees in their account activity whenever an administrator opens it. A report never includes anyone else’s side of the session, though it can include what Panorama passed along from others, and is kept for 90 days, even if the session is later deleted.

An administrator who is in a session can see everything Panorama has been told in it, as each request to the model sent it, including everyone’s messages, names, and email addresses and Panorama’s notes, and what each request cost. Everyone in the session is told there when an administrator looks at what Panorama was told. What each request sent is kept for the newest 200 requests; what each cost, for 90 days, up to the newest 5,000 requests.

Deleting your side of a session deletes your conversation with Panorama there and takes you out of the session at once. Panorama keeps what it learned from you, including your messages, your name, and your email address, in its memory of the session and its record of requests, and can keep talking with the others about it, still keeping private what you said privately, until everyone has deleted their side; then the whole session is deleted. Deleted content is removed from Panorama at once and from the hosting provider’s recovery storage within 30 days. A record that the session existed, with its participants, dates, and model usage but no names or messages, is kept for 400 days.

Your account

If you sign in with Google, Panorama keeps the address of your Google profile picture from your latest Google sign-in, to show it to you. Your browser loads the picture from Google. If Panorama has no Google picture for you, your browser asks Gravatar whether your email address has a picture there, by sending Gravatar a one-way hash of the address. You see your own picture only. Panorama doesn’t show it to anyone else.

Deleting your account deletes your side of every session you are in and erases your name, picture address, plan, budget and what was charged to it, sign-in identities, email addresses, devices, and consents from your account. If part of that can’t be reached at the moment you delete, Panorama keeps trying until it’s erased. People you were connected with see a deleted account. It doesn’t erase what Panorama learned from you: in each session you were in, Panorama’s memory and its record of requests keep your messages, your name, and your email address until that session is deleted, when everyone else has deleted their side. Notices already in other people’s sessions, such as that you joined, keep the name and address they showed, and a report someone sent from their own side of a session keeps what it held for its 90 days. An administrator’s account can’t be deleted while its address is on the service’s list of administrators. Invitations you sent to people without an account still let them sign up, but invitation emails not yet sent never go out. Panorama keeps, with no end date, a record that the account existed and when it was deleted, under the name “Deleted account” and without your email address or messages. If you join the waitlist, Panorama keeps only your verified address, encrypted, until it invites you.

Every account is on Free, on Premium, or on a budget Panorama sets, and what Panorama does in a session is paid for from the budgets of its sponsors, in proportion to their amounts; Free has no budget. Everyone in a session sees who sponsors it. Others in a session see a star beside your name if you’re on Premium, never your plan’s amount, your budget, or what you’ve used; your account page shows you all three, and administrators see your plan. Panorama records what is charged to your budget as amounts of money by day, never what a turn was about, and keeps them for 35 days, or until you delete your account. Each session also keeps how many turns and model requests Panorama made in it and what they cost, which its deletion record keeps for 400 days.

If you pay for Premium, Stripe processes the payment. Panorama sends Stripe your email address, your Panorama account ID, and the amount you chose. You enter your card and billing details on Stripe’s own page, so Panorama never sees or stores your card number. Stripe keeps its own records of you, your payment method, and your invoices under its privacy policy. Panorama keeps your Stripe customer and subscription IDs, the monthly amount you pay, and, while a cancellation is pending, the date Premium ends. It also keeps the IDs of the Stripe notifications it has processed, without their contents, for about 30 days, so that none is applied twice. Deleting your account cancels Premium at once and clears these IDs from it; the subscription ID is kept only until Stripe confirms the cancellation.

On the website, text you have typed but not sent, and messages still on their way to Panorama, are kept in your browser until they are sent or you sign out, so a reload, a closed tab, or a lost connection doesn’t lose them. Signing out, deleting your account, or someone else signing in to Panorama in that browser erases them from it, and deleting your side of a session erases what you had typed for it. If your sign-in ends another way, as when it expires or you sign out of other browsers from elsewhere, they wait in that browser until you sign in there again.

To keep the website and the app up to date, Panorama keeps a log of which of your sessions, connections, and account details changed, without what changed or what anyone wrote, for 30 days.

Notification emails are off until you turn them on, as you join or in Settings: when someone asks to connect, when someone invites you to a session, and when Panorama has written to you and you haven’t read it for about 15 minutes, at most once per session until you read it. When someone invites an email address that has no Panorama account, Panorama emails that address an invitation, which only that address can accept. These emails name the people involved, with the email addresses of whoever invited you or asked to connect and of the people you’re connected with, and everyone else in a session by first name as above, but never include what anyone wrote or a session’s name. Email destinations and details are encrypted while pending and erased after delivery, cancellation, expiry, or permanent failure.

Push notifications are off until the iPhone app arrives. They will carry no names or messages: your device fetches a session’s name from Panorama.

Administrators are the accounts whose email addresses are on the service’s list of administrators. Administration shows accounts and delivery state, including the email addresses of accounts, of people invited by email, and of people on the waitlist, but never session names, message text, or credentials, apart from what someone sends in a report; only an administrator in a session can see what Panorama was told there, as above. Administrative actions are audited.

Expired sign-ins, invitations, links, and authorization records are deleted on a schedule. Body-free operational events are kept for up to 90 days; daily usage totals and body-free audit records are kept for up to 400 days.

For an access, correction, or other privacy request, write to us from the Help page, choosing “A privacy request.”

Security

Report suspected vulnerabilities privately from the Help page, choosing “A security problem.” Do not disclose them publicly, and leave out access tokens, message content, invitation links, and other private data.