Privacy Policy
Last updated: July 23, 2026
Panda's Recap (“we,” “us”) is a personal work-tracking tool: a board for your tasks, built-in time tracking, and a year-end review generator. This policy explains what data we handle and why. We keep it plain on purpose.
The short version: we only collect your basic Google profile (to sign you in) and the boards and time you create in the app (to save and sync them). If you subscribe to Pro, our payment provider Stripe handles your payment details, and we never see your card number. If you choose to connect a calendar, we read it in your browser only, never store it on our servers, and never write to it. The optional AI features send your draft, and for a résumé the personal details you chose to enter and the text of an existing résumé if you uploaded one, to Anthropic when you press the button, and never otherwise. Searching for jobs sends a summary of what you have tracked, and your latest résumé or review if you have one, so the results can be ordered usefully; your client names are never included. If you are signed in, the résumés and reviews you generate, the details you entered for them, and the text of any résumé you uploaded are saved to your account so you can reach them from your other devices; as a guest they stay in your browser. An uploaded résumé file itself never leaves your device: only the text inside it is read and saved. Ask Panda searches your board in your browser and sends only the handful of cards needed to answer each question, and the conversation stays in your browser. We don't sell your data, we don't use it for advertising, and we never touch your Gmail, Drive, or contacts.
What we collect
- Your account details, if you sign in with Google. We receive your name, email address, profile picture, and a Google account identifier. We use Google Sign-In only to identify your account. Signing in requests no access to your Google Drive, Gmail, Calendar, contacts, or any other Google data; calendar access is a separate, optional step described below, and only happens if you ask for it. We store your Google account identifier, email address, and name on our servers so we can save your work, sign you in, and, if you ask us to, find and delete your account.
- The content you create in the app, such as your boards, cards, notes, tags, time entries, and the résumés and reviews you generate along with the details behind them. If you are signed in, this is stored on our servers so it can sync across your devices. If you use Panda's Recap as a guest, without signing in, this content stays in your own web browser and is never sent to us.
- Anonymous counts of how far people get, and which features get used. So we can tell whether the app is actually being used, we count how many people reach a few basic milestones, and how often each part of the app is opened: the board, the calendar, reports, Ask Panda, settings, the timer, search, importing a spreadsheet, and the AI features. Milestones are counted at most once per browser, ever; feature use is counted each time. Either way it is stored only as a plain daily total, such as "41 people added a card on 12 August". No account, no identifier, no IP address and none of your content is stored alongside it, and there is no way to trace a count back to you or to link the counts together.
- Calendar files you choose to import. If you export your calendar and import the file (.ics or .csv), it is read in your browser only and is never uploaded to our servers. Only the events you choose to import become tasks, and after that they are ordinary tasks, no different from ones you typed yourself. We do not connect to, read, or change your actual calendar account.
- Your calendar events, only if you connect a calendar. Connecting Google Calendar is entirely optional and read-only. Your browser reads the events directly from Google using a short-lived token. The first import is shown to you for review. After that, while Panda's Recap is open in your browser, it re-reads your calendar every few minutes so new meetings arrive as tasks on their own; each automatic batch is announced with an Undo, and meetings you remove or skip are not re-added. Your calendar data is never sent to, or stored on, our servers. Imported meetings become ordinary tasks, no different from ones you typed yourself. We never create, change, or delete anything in your calendar, and we cannot read it while the app is closed: we never receive or store a refresh token. You can turn sync off in Settings, or disconnect at any time from your Google Account permissions page.
- Résumé details, if you choose to enter them. The Generate Résumé feature has a form for the things your board can't know: your name, job title, employer, location, email address, phone number, a link such as LinkedIn, your education, and any earlier roles you type in. Every one of these is optional and you can use the feature without entering any of them. If you are signed in, they are saved to your account so a résumé generated on your phone and one generated on your laptop are written from the same details. As a guest they are stored in your own web browser only and never reach us. Clearing the fields in the form removes them everywhere, including from your account. They are sent to Anthropic, together with your tracked work, only at the moment you press Generate Résumé.
- An existing résumé, if you choose to upload one. Generate Résumé lets you upload a résumé you already have, as a PDF, a Word document, or a text file, so that Panda can carry forward the history it can't know: your earlier jobs, your education, your qualifications. The file is never uploaded to us. It is opened and read into text inside your own web browser, and the file itself never leaves your device. The text it contains is stored alongside the résumé details above, so that you don't have to upload it again next time. If you are signed in, that text is saved to your account, so you don't have to upload it again on a different device either. As a guest it stays in that browser only and never reaches us. It is sent to Anthropic, with the rest of your résumé details and your tracked work, only at the moment you press Generate Résumé. You can remove it at any time with the Remove button next to the file name. Please note that a résumé usually contains more personal information than anything else in this app, such as a home address, a phone number and your employment history, so upload one only if you're comfortable with it being sent to Anthropic when you generate.
- Subscription and billing information, if you subscribe to Pro. Our payment provider, Stripe, collects and processes the payment details you enter to bill you. We never see or store your full card number. On our own servers we store only your subscription status and the Stripe identifiers needed to manage it, such as whether your subscription is active and when the current period ends.
How we use it
- To sign you in and keep you signed in.
- To save your work and sync it across the devices where you sign in.
- To provide the Pro subscription and process its payments (through Stripe).
- To operate, maintain, and improve the service.
- To generate your year-end review. If you choose to use the optional AI Polish feature, the text of your review draft is sent to Anthropic to rewrite it into a finished write-up. This only happens when you click Polish.
- To write a résumé, if you choose to use the optional Generate Résumé feature. When you press the button, the résumé details you entered, the text of an existing résumé if you uploaded one, and a summary of your completed work are sent to Anthropic to be written into a résumé. This only happens when you press Generate Résumé, and if you never use it, none of this is sent anywhere.
We do not sell your personal data, share it with data brokers, or use it for advertising or profiling.
Who we share it with
We don't share your data with third parties except the infrastructure providers that run the service on our behalf:
- Google provides sign-in, and Google Calendar if you connect it. Calendar events are requested by your browser directly from Google and are not routed through our servers. See the Google Privacy Policy.
- Cloudflare hosts the app and the database that stores your saved content. See the Cloudflare Privacy Policy.
- Stripe processes subscription payments for Pro. When you subscribe, the billing and payment details you enter are handled by Stripe, not stored by us. See the Stripe Privacy Policy. If you never subscribe, none of your data is sent to Stripe.
- Anthropic powers the optional AI features: AI Polish, Generate Résumé and Ask Panda. When you use AI Polish, your review draft is sent to Anthropic's Claude models to produce the polished version. When you use Generate Résumé, the résumé details you entered (which may include your name, contact details, employer and education) are sent along with a summary of your completed work, and the text of an existing résumé if you chose to upload one. Your client names are left out by default, and are sent only if you tick the box in Your details asking for them by name. Anthropic does not use data submitted through its API to train its models. See the Anthropic Privacy Policy. When you use Ask Panda, your question is sent along with only the cards needed to answer it, rather than your whole board: the app searches your board in your own browser and sends just the matching rows, which is usually a handful. Without Pro, no cards are sent at all, because Ask Panda then answers questions about the app rather than about your work. The conversation itself is kept in that browser only, never on our servers, and you can clear it at any time with the Clear button in Ask Panda. Jobs sends nothing about your board. Only the words you type into the search boxes go out, they go to the job boards rather than to Anthropic, and the listings that come back carry nothing about you. All of these features are entirely optional and only run when you use them. If you never use them, none of your data is sent to Anthropic.
Google user data
Panda's Recap's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. In plain terms:
- We request the minimum access we need: your basic profile (name, email address, profile picture) to sign you in, and read-only calendar access only if you choose to connect a calendar. We request no access to Gmail, Drive, or contacts.
- We use your profile for one purpose: identifying your account so we can save your work and honor deletion requests.
- We use calendar data for one purpose: showing you your own events so you can turn them into tasks on your own board.
- Calendar data is read in your browser and is never stored on our servers.
- We do not transfer Google user data to anyone, and we do not sell it.
- We do not use Google user data for advertising, and we do not use it to train AI models.
- We do not allow humans to read your Google user data.
Cookies
We use a single cookie to keep you signed in after you log in with Google. We do not use advertising or third-party tracking cookies. If you use the app as a guest, no sign-in cookie is set.
Where your data lives, and keeping it secure
Signed-in data is stored on Cloudflare's infrastructure. Connections use HTTPS, and your sign-in session is protected with a signed, secure cookie. No system is perfectly secure, but we take reasonable steps to protect your information.
Keeping or deleting your data
- Guest data lives only in your browser. Clearing your browser's site data removes it. You can also export a backup any time from Settings.
- Account data: to delete your account and the data associated with it, email us (below) and we'll remove it. Note that Stripe may retain records of your payments as required for legal, tax, and accounting purposes, even after your account is deleted.
- Résumé details are saved to your account if you are signed in, and sit only in the browser you typed them into if you are a guest. Clear the fields in the form and they are gone from both. Deleting your account deletes them with it.
- An uploaded résumé file never leaves your device. The text read out of it is saved to your account if you are signed in, and stays in that browser if you are a guest. Press Remove next to the file name, or use Clear details, and it's gone from both.
- Generated reviews and résumés are kept in a History (the last twenty of each), so you can go back to an earlier version. If you are signed in they are saved to your account and available on your other devices; as a guest they stay in your browser and never reach us. Delete any version, or all of them, from the History panel, and the deletion applies to your account too. "Reset everything" in Settings and clearing site data also remove them from that browser.
Children
Panda's Recap is a general-audience productivity tool and is not directed to children under 13. We do not knowingly collect data from children under 13.
Changes to this policy
We may update this policy from time to time. When we do, we'll change the “Last updated” date above.
Contact
Questions, or want your data deleted? Email [email protected].