Security, access and POPIA

Reading a company's mail is a serious thing to be allowed to do.

This page describes what the software actually does, not what it aspires to. It is updated whenever the product changes, and there are automated checks that fail our build if the two drift apart.

What Panorithm is allowed to do in your mail

Four permissions, and one of them is the important one.

Requested through Google's own consent screen, granted by each person for their own mailbox, and revocable by that person at any time without asking us.

Read your mailTo find the document you asked about and read what is inside it.
Prepare a draftTo leave a reply in your drafts with the right document attached.
Save a file it madeOnly files Panorithm itself creates. It never opens a file it did not make.
Not requestedSend, delete and modify. Because the permission was never asked for, it cannot be enabled later without a new consent screen you would see and approve.

Who at your company can see what

One person seeing every invoice is not the same as seeing every contract.

Most tools give you one dial: this person is an admin, or they are not. That is useless in a real company, where your bookkeeper needs every invoice and none of the contracts, and your salesperson needs everything in their own mailbox and nothing in anybody else's.

So there are two dials, set per person by the account holder. What kind of document they may open, and where they may open it. A document has to pass both, and if it fails either, it does not appear, is not counted, and cannot be downloaded from a link somebody kept from last week.

The five kinds above are the ones the software sorts documents into. Anything it could not identify lands in Unclassified, which almost nobody should be given, because nobody has checked what is in there yet.

New people start narrowAn invitee gets invoices, in their own mailbox only, until the account holder deliberately widens it. Nobody is accidentally given the company.
Most staff should search nothingA connect-only account contributes a mailbox so its documents can be found, and searches nothing at all. For the majority of a company this is the right answer, and it is one setting.
Your bookkeeper never gets an accountPeople outside the company cannot sign in and cannot search. They receive bundles somebody inside approved, at a link that expires after fourteen days and can be withdrawn before then.
One document, without widening anybodySomebody needs a single invoice they are not cleared for. Rather than granting them the category and forgetting to take it back, the account holder approves that one document, and it goes to them at a link pinned to it that expires. Their standing access does not move.
Only the account holder changes any of itInviting, removing, widening access and approving an outsider are all theirs. Nobody can quietly grant themselves more.
People are told, not left to discoverEveryone is emailed when their own access changes, and can read what they currently have in one sentence rather than inferring it from a grid of ticks.

When we look at your account

Nobody here can open your account because they feel like it.

We built it, so occasionally we need to look: to fix something, or to scope an agent for you. There is no standing access and no master login. Every look is a request your account holder either approves or does not.

We askNaming what we want to see, why, and for how long. Your account holder gets an email. Nothing happens until they approve it, and declining costs you nothing.
Shape, not contentsBy default we see how many documents of each kind you have and how well the reading worked. No filenames, senders, suppliers, amounts or contents. Opening actual documents is a separate level, asked for only when the work needs it.
It ends by itselfA week at the outside, counted from your approval, without anybody having to remember to close it.
You can stop it instantlyWithdraw in Settings and it stops on the next request, without telling us first.
Every look is on the recordEach access is logged and shown to you in Settings, whether or not you were watching at the time.

Your data and another client's

There is no shared pool. There never was one.

Every record carries the company it belongs to and is refused to any other. No client can see, search or reach another's mail, and nothing from your business is used to build, train or improve anything for anybody else.

Where your data sits

Mostly, it stays where it already was.

The important thing on this list is the first one: Panorithm does not make a second copy of your documents. They stay in the mailbox and are fetched when somebody opens one.

Documents are not copiedAttachment contents are fetched from the mailbox when somebody opens them. We keep an index of what was read, not the files.
Stored in JohannesburgGoogle Cloud Firestore, region africa-south1.
Read in the United StatesDocument contents are processed by Anthropic, which does not train models on data submitted through its API.
Disconnecting is immediateIt deletes the access and every record drawn from that mailbox, without asking us.
On terminationEverything belonging to your company is deleted within thirty days.

POPIA

Two obligations, and one of them is yours.

Your company is the responsible party for the personal information in its own mail. Mammrlla is an operator, processing it on your instruction and for no other purpose.

Two things worth doing on your side: tell staff whose mailboxes are connected that they are connected and what that means, and decide deliberately who may see whose mail before you invite anybody. The controls exist; the policy is yours.

Data processing agreement · Subprocessors · Privacy policy · Confidentiality

Questions this page should have answered.

Can we start with one department?Yes, and we would recommend it. Three mailboxes in one function is enough to find the pattern, and widening later costs nothing.
What happens when somebody leaves?Their mailbox is disconnected, which deletes the access and every record drawn from it. Removing the person from the account is a separate step the account holder takes in Settings.
Can you read a mailbox nobody connected?No. There is no administrative route into a Google Workspace mailbox here. Every mailbox is connected by the person who owns it, through Google's consent screen, and revoked the same way.
Does our data train anything?No. Not our models, because we have none, and not Anthropic's, which does not train on data submitted through its API. Nothing from one client builds anything for another.
What if we are audited?Every question, every document opened and every support access is logged with who and when, and the log is yours to read in Settings rather than something you request from us.

Read this before you connect anything.

It is the page we would want to have read, and it is the one most likely to contain your objection. If it does not answer it, ask and we will add the answer here.