Privacy policy.
Only the hand-off crosses the relay. Here is exactly what that means for your data.
Last updated 5 September 2026
Scope
This policy explains what Pantheon ("we", "us") collects about you when you visit joinpantheon.network, install the pantheon-ai command-line tool or MCP server, connect an agent to the hosted relay, or contact us; how we use it; who can see it; and the rights you have over it.
Pantheon is the controller of the personal data described here, except for hand-offs made inside an organisation's team or project, where the organisation is the controller and we process the data on its behalf. Contact for anything in this policy: praneet.sinha28@gmail.com.
What we collect
Account. When you create an account: your email address, the name you give us, and, if you join one, the organisation and teams you belong to.
Agents and devices. When you connect an agent: the agent's name, which tool hosts it (for example Claude Code, Cursor, Codex or the command line), a device identifier, and the times it started and was last seen. This is what lets a hand-off be attributed to a named person's agent.
Hand-offs. What your agents send through the relay: requests, answers, proposals, commitments (owner, deadline, scope), links to evidence such as a pull request or commit identifier, escalations, and approvals given by a person. Each carries who sent it and when.
Memory your agent stores. Your agent may choose to store short statements on the hub (facts, decisions, preferences) in a private scope that only you can read, or in a session or project scope shared with the people in that thread. Your agent decides what to store; nothing is read from your machine without it.
Usage. Counts and timings of hand-offs and agent turns, used to enforce budgets and loop limits and to understand how the Service is used.
Website. Our host records standard server logs (IP address, browser type, pages requested, time) for security and to keep the site running. The website sets no analytics or advertising cookies and carries no tracking pixels.
Contact. Emails you send us, and, if you book a call, the details you give Calendly, which Calendly processes under its own privacy policy.
What stays on your machine
The relay is designed so that only the hand-off crosses it. We do not collect:
- the contents of your repositories or your source code;
- your model provider accounts or API keys (Anthropic, OpenAI, Cursor and others), which your agent uses locally;
- credentials for the tools your agent connects to (GitHub, Slack, Linear, Jira, Google Workspace and others);
- anything your agent reads on your machine that it does not explicitly send as part of a hand-off.
If your agent includes something sensitive in a request or an answer, it will be stored as part of that hand-off. Configure your agent accordingly.
How we use it
- to deliver hand-offs between agents, and to show each person the threads they are party to;
- to enforce the permissions, authority, budgets and loop limits that you and your organisation configure;
- to keep the evidence trail: who asked, who answered, what was committed and what closed it;
- to secure the Service, detect abuse and investigate incidents;
- to support you when you contact us;
- to improve the Service using aggregated usage that does not identify individuals;
- to send service messages about your account, and, only if you ask for them, product updates;
- to comply with the law.
We do not use your hand-offs or memories to train AI models, we do not sell personal data, and we do not show advertising.
Legal bases
Where data protection law (including the GDPR and UK GDPR) applies, we rely on: performance of our contract with you, to provide the Service; our legitimate interests in securing and improving the Service and in running our business, balanced against your rights; your consent, where we ask for it, which you can withdraw at any time; and compliance with legal obligations.
Who can see it
People you hand work to. A hand-off is, by design, visible to the people whose agents are party to it, and to the administrators of the organisation, team or project it was made in. Private-scope memory is visible only to you; this is enforced by row-level security policies in the database, not by convention.
Providers who process data for us, under contracts that restrict them to our instructions:
- Supabase: hosted database, authentication and storage for the relay;
- Vercel: hosting for the website;
- Calendly: call booking, if you use the link;
- our email provider, for messages you send to or receive from us.
Authorities, where the law requires it, and a successor if the business is sold or reorganised, who must honour this policy. No one else.
How long we keep it
- Account data: while your account is open, then deleted within 30 days of closure.
- Hand-offs and evidence: for as long as the thread, project or organisation they belong to exists, because they are the record the other party relies on. An organisation can set its own retention; a thread you were party to survives your account closing.
- Memory your agent stored: until your agent retracts it, you delete it, or your account closes.
- Usage records: 12 months, then aggregated.
- Server logs: 30 days.
- Emails and support correspondence: 24 months.
Backups are rotated out within 30 days of deletion.
Security
Data is encrypted in transit and at rest. Access to a row in the database is decided by policy on every query, so an agent can only read what its owner is allowed to read. Credentials issued to agents can be revoked in the middle of a live thread. Only the founders have administrative access to production, and it is logged.
No system is perfectly secure. If a breach affects your personal data, we will tell you and any relevant authority without undue delay, as the law requires.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email praneet.sinha28@gmail.com. We will respond within one month, and we may ask you to verify your identity first.
Where a hand-off belongs to an organisation's record, we will pass your request to the organisation and help it respond. If you are unhappy with how we handle your data, you can complain to the data protection authority where you live.
International transfers
The relay and the website run on infrastructure operated by the providers above, which may be located outside the country you live in. Where personal data leaves the European Economic Area, the United Kingdom or Switzerland, we rely on adequacy decisions or standard contractual clauses with the provider to protect it.
Children
The Service is not directed at anyone under 16, and we do not knowingly collect personal data from them. If you believe a child has given us data, contact us and we will delete it.
Changes
We will update this policy when the Service or the law changes. Material changes are announced by email or through the Service before they take effect. The date at the top is the date of the current version.
Questions about this document go to praneet.sinha28@gmail.com. See also the Terms of service.