Privacy Policy
Version 1.0 · Effective 18 August 2026
What Panorithm reads, what it keeps, where it sits, who can reach it, and how to get rid of all of it.
Panorithm reads a company's email so it can answer questions about it. That is an unusually broad thing to let software do, so this page is specific about what it reads, what it keeps, where that is, and who can see it. It describes what the software actually does, not what it might one day do.
Panorithm is operated by MAMMARELLA (PTY) LTD (2021/684969/07), 6 Calders Road, Bedfordview, Johannesburg, Gauteng, 2008, South Africa. For anything in this policy, write to obakengm@mammrlla.com.
1. What Panorithm is allowed to do with your mailbox
You connect your own mailbox through Google's consent screen. Google, not us, decides what we may do, and it grants exactly these permissions:
- Read your mail
gmail.readonly
So it can find the contract, quote, site list or invoice you asked about, and read what is inside the attachment. - Prepare a draft
gmail.compose
So it can leave a reply in your drafts with the right document attached. It cannot send. - Save a file you ask it to
drive.file
Only files Panorithm itself creates. It cannot see the rest of your Drive, and never opens a file it did not make. - Your email address
userinfo.email
So the account is yours, and so what each question costs is attributable to a person. - Your name and picture
userinfo.profile
Shown beside your mailbox so colleagues can tell whose is whose. - Confirm it is you
openid
The standard sign-in check. It carries no data of its own.
Panorithm cannot send email, delete anything, or change anything in your mailbox. Not because a setting forbids it, but because the permission that would allow it was never requested from Google. It can leave a draft. A person still has to press send.
You can withdraw the whole thing at any moment, from inside Panorithm or from your Google account at myaccount.google.com/permissions.
2. What is stored, and what is not
Panorithm does not keep copies of your attachments. When you open a document it is fetched from Gmail at that moment and passed to you. It is not held in our database.
What we do store:
- Your email address, name and profile picture from Google.
- Your organisation, your role in it, and who invited you.
- Access tokens for your mailbox, encrypted at rest.
- Facts about documents Panorithm has read, filename, sender, subject, date, and the fields it extracted, such as supplier, invoice number, dates and amounts. This index is what makes a second question fast. The document itself stays in Gmail.
- The questions asked, who asked them, when, and what each one cost. Your own questions are shown back to you as history. Nobody else in your company can read them, whatever their role.
- WhatsApp numbers. Your company's business number if you give us one, and each person's own work number if they give us theirs.
- Your acceptance of these terms: the address, the version, and when.
- A record of anything sent outside the company: who it went to, which documents, who approved it, when it expires, and whether it was opened.
- What you write on the contact form: your name, work email, company, industry and what you told us about your business. Kept so an enquiry is not lost if the email fails, and deleted on request.
- A counter, so nobody can use the sign-up form to send mail to strangers. It holds a number and a time. It does not hold your IP address: what identifies one caller from another is a one-way code derived from it, which cannot be turned back into an address.
3. Who can see it
Inside a company, the account holder decides. Two things are set per person:
- Which kinds of document they may open: invoices, payments, quotes, contracts, or anything Panorithm could not identify. A kind that is not granted is refused everywhere, including on a download link kept from last week.
- Which mailboxes they may look in. By default, only the ones they connected themselves.
Somebody can also be given an account that connects a mailbox and searches nothing, which is what most people at a company actually need. Everyone is emailed when their access changes, and Settings states it in a sentence.
The account holder can grant somebody access to every connected mailbox. That is their decision to make about their own company, and it is the one setting worth checking before you connect a mailbox that carries anything you would not want a colleague to read.
Between organisations there is no such sharing. Every record carries the organisation it belongs to and is refused to any other. No other client can see, search or reach your mail.
4. Documents that leave Panorithm
A company can send documents to somebody outside it, typically a bookkeeper, auditor or attorney. This is the only way anything reaches a person without an account, and it is deliberately narrow:
- The account holder approves the recipient first. Nothing can be sent to an address they have not approved.
- They also cap what that recipient may ever be sent. By default, invoices and payments only.
- A person inside the company then checks a specific bundle and sends it. Nothing leaves automatically, and nothing is created until somebody presses send.
- The recipient gets a link, not an account. It stops working after fourteen days and can be withdrawn before that.
- The documents are fetched from the mailbox when the recipient downloads them. We do not keep a copy for them either.
5. WhatsApp
Where a company uses WhatsApp with Panorithm, the number is theirs, not ours. Mammrlla registers it with Meta as a Tech Provider and runs the software on it. Two consequences worth stating plainly:
- Meta processes those messages. Anything sent to that number passes through Meta's WhatsApp Business Platform under Meta's own terms, in addition to this policy.
- A registered number stops working as ordinary WhatsApp. Registering moves it onto the business platform, which is why a separate business SIM is usually the right number to give us.
Documents sent to that number are filed the same way as documents from email, and the same permissions decide who can open them. A personal work number, where somebody gives one, is used to tell which person sent something and to reach them on WhatsApp instead of by email. It is not shown outside their company and is never used for marketing.
If a company uploads a WhatsApp chat export, that file can contain messages from people who are not Panorithm users and have not agreed to anything. Whoever uploads it is responsible for being entitled to, and we keep only what is needed to file the documents in it.
6. Where it is, and who processes it
- Stored in Johannesburg. Google Cloud Firestore, region
africa-south1. - Read by Anthropic. To answer a question, the relevant email text and document contents are sent to Anthropic's API in the United States, under a workspace scoped to your organisation. Anthropic does not train models on data submitted through its API.
- Read by Google Gemini, in the United States, where a billing workflow runs for your company on a Google key you connected. Google does not train on data sent through the paid API.
- Written to Xero, only where you have connected your own Xero organisation, and only as drafts a person at your company approves.
- Email sent by SMTP2GO. Sign-in links and notices only.
- Hosted by Vercel. The application itself.
- Meta, only where a company uses WhatsApp with Panorithm, and only for messages sent to that company's own registered number.
The full list, with a country against each name and the standard a provider must meet, is the subprocessor list, which is the one kept current. We do not sell your data, share it with advertisers, or use it to build anything for anyone else.
7. When Mammrlla looks at your account
We hold no standing access. When we need to look, we ask your account holder, they approve or decline, the access expires on its own and can be withdrawn at any moment, and every time we look is logged and shown to you in Settings. By default we can see the shape of your documents (how many of each kind, how well the reading worked) and not their contents.
8. Signing in
There are no passwords. You ask for a link, it arrives by email, and it stops working fifteen minutes later. Your session is a signed cookie holding your email address and nothing else. it cannot be edited into somebody else's.
9. Keeping it and deleting it
Disconnecting a mailbox deletes its tokens and every document record drawn from it. That happens immediately, from Settings, without asking us.
Ask us to close your account and everything belonging to your organisation is deleted within thirty days. We keep only what the law requires us to keep, invoices and payment records.
10. Your rights under POPIA
The Protection of Personal Information Act gives you the right to know what we hold about you, to have it corrected, to have it deleted, to object to how it is processed, and to complain to the Information Regulator.
Write to obakengm@mammrlla.com and we will answer within thirty days. If we handle it badly, the Information Regulator of South Africa is at inforegulator.org.za.
11. Changes
If this policy changes in a way that affects what we do with your information, we email everyone with an account before it takes effect. Each version is numbered, and the version you accepted is recorded against your address.