Legal / Public Policy
Privacy Policy
Effective 7 September 2026
What Panoptik collects, who receives it, how long it is kept, and how to withdraw consent or delete everything.
Overview
Panoptik is operated by Trenton Ryu (“Panoptik,” “we,” “us,” or “our”). This Privacy Policy explains what information the Panoptik iOS app, this website, and related services (together, the “Services”) collect, how it is used, who receives it, how long it is kept, and how you can withdraw consent or delete your data.
Panoptik is a private group video app. A member creates an event and shares a six-character join code. During the event, Panoptik sends capture prompts to one member at a time; that member has two minutes to record a short clip. Clips go into the event vault, where they are unreadable to every member — including the person who recorded them — until the event ends. After it ends, each member can develop the clips into a film on their own device.
Panoptik has no public feed, no public profiles, no followers, no comments, no likes, and no in-app messaging. Events are private and are joined only by code.
Questions about this policy can be sent to support@panoptikapp.com.
1. Account Information
Member accounts. When you create an account, Panoptik stores your email address and a securely hashed password through Supabase Auth. Your email is used to sign you in and to send verification, password-reset, and service messages. Other members never see your email address: the app does not display it, and the database is configured so that one member cannot read another member’s email.
Guest passes. You can join a single event on a single device without creating a full account. In that case Panoptik creates a restricted anonymous identifier and stores the display name you choose and a one-event entitlement. It does not collect an email address for a guest pass. Joining more than one event requires converting the guest pass into an account.
Profile. After signup you choose a username and may add a profile photo. Your username and profile photo are visible to other members of events you join.
Age. Panoptik asks for your birthday once, to confirm you meet the minimum age of 13. The birthday is converted to a whole-year age on your device and is never transmitted. Neither the birthday nor the age is stored. Only the true-or-false result of the eligibility check is recorded against your account.
Account status. If an account is suspended for a violation, Panoptik stores the suspension, its reason, and any appeal you submit, so that the decision can be reviewed.
2. Camera, Microphone, and Photos
Panoptik requests camera and microphone access so you can record clips, camera access if you choose to take a profile photo, and add-only photo library access so a finished film can be saved to your library.
Add-only access means Panoptik can write a film you choose to save into your photo library but cannot read, browse, or index the photos and videos already there. Event clips are always recorded inside Panoptik and can never be uploaded from your camera roll.
These capabilities are used only at the moment you choose to capture or save. Panoptik does not record in the background.
3. Clips, Covers, and the Vault
Clips you record are uploaded to private storage where nobody can read them — not the other members, not the event creator, not Panoptik’s operator — until the event has ended. Access is enforced by server-side database and storage rules rather than by the app alone, so a modified client cannot read a locked clip.
Profile photos and event covers you submit are stored privately and are visible only to the members of the events you share them with.
Event records include the event name and settings, start and end times, the creator, the member list, the join code, capture-prompt settings, clip length and allowance settings, missed-prompt status, reveal status, and deletion status.
Panoptik performs the technical processing needed to run the service: upload, storage, compression, transcoding, thumbnail generation, playback, download, and film export. Panoptik does not use your clips for advertising, does not use them to train AI or machine-learning models, and does not run face recognition or build profiles of the people in them.
4. Notifications
If you enable notifications, Panoptik stores a device token so it can send capture prompts, reveal-ready alerts, and event reminders through the Apple Push Notification service.
Capture prompts are delivered as Time Sensitive notifications because they require a response within two minutes. Time Sensitive alerts may break through a Focus mode, but never through the Ring/Silent switch. When you allow it, a Live Activity shows the remaining capture time on your Lock Screen.
Notifications are optional. Turning them off in iOS Settings stops all of this, and Panoptik remains usable — you may simply miss prompts.
5. Analytics and Diagnostics — Off Unless You Turn Them On
Product analytics and crash diagnostics are optional and stay switched off until you enable Share Product Analytics in Settings. Nothing is sent to an analytics provider before you do.
Consent is recorded separately for each member account and each guest pass on a device. One identity’s choice never enables collection for another identity on the same device.
When you enable it, Panoptik uses PostHog to understand feature usage — for example how often clips are captured, and how the develop and reveal flow performs — and to collect crash reports. This is never used for advertising. Panoptik does not sell your data, does not share it with advertisers, and shows no ads.
You can withdraw consent at any time by turning Share Product Analytics off in Settings. Future collection stops immediately, and analytics data linked to your account is deleted when you delete your account.
6. Support, Reports, and Safety Records
If you contact support or report a clip or a member, Panoptik stores the reason you selected and any message you write, together with the account, event, or clip identifiers needed to investigate and respond.
When a moderator acts on a report, Panoptik records the decision, the reason for it, and who made it. These records are an audit trail so that enforcement can be reviewed and appealed, and they are kept separately from the reported content.
Panoptik does not collect device location and never requests location permission. IP address information may be processed for security, abuse prevention, rate limiting, IP blocking, and fraud prevention.
7. People Who Are Not Panoptik Users
Clips may capture the image or voice of people who do not use Panoptik. That footage is stored as part of the recording member’s clip and is handled under the same access, retention, and deletion rules as everything else in this policy. Panoptik does not use clips to identify non-users, run face recognition, or build profiles.
Members are responsible for recording lawfully and for obtaining any consent the law requires from people who appear in or can be heard in their clips.
If you are not a Panoptik user and believe you appear in a clip without your consent, email support@panoptikapp.com with enough detail to locate the event or content. Requests involving intimate imagery are handled on the priority timeline described in our Terms of Service.
8. Service Providers and Third Parties
Panoptik relies on a small set of providers, each receiving only the data needed for its function: Supabase for accounts, authentication, and application data; Cloudflare R2 and Supabase Storage for hosted clips, covers, avatars, and films; Resend for transactional and service email; an operational alerting service that notifies the on-call moderator when a report is filed; PostHog for product analytics and crash reports, and only if you have enabled them; Apple for push notification delivery and the Photos features you invoke; and Vercel for hosting this website.
Each of these providers is bound by its service terms to provide the same or equivalent protection of your data as this policy states and as Apple’s App Store guidelines require. They may process your data only to deliver their service to Panoptik, and are not permitted to use it for their own purposes.
Panoptik does not sell personal information, does not share personal information for cross-context behavioural advertising, and uses no advertising SDKs. If that ever changes, this policy will be updated before the change takes effect.
Panoptik may disclose information when reasonably necessary to comply with law, legal process, or a government request; to enforce our Terms; to protect the rights, safety, and security of members, Panoptik, or others; or to investigate fraud, abuse, a security incident, or illegal activity.
9. Who Can See Your Content
While an event is running, nobody can see the clips inside it. That includes the other members, the event creator, and Panoptik’s operator. The vault is held closed by server-side rules.
After an event ends, its members can see the clips recorded during it, together with your username, profile photo, participation, and missed-prompt status. Clips and films are available to that event’s members only, for the 14-day retention window.
Panoptik does not routinely watch member clips. A moderator can open a clip only after it has been reported, and only through a short-lived access link issued for that review. Every such access is written to the audit trail described in section 6.
Panoptik cannot control what another member does with a film once they have saved or exported it.
10. Retention
Clips, films, and their generated thumbnails are deleted 14 days after an event ends. An event creator can delete an entire event sooner, which deletes its clips and files for every member.
Account information is kept while your account exists. When you delete your account, deletion begins immediately — see the next section.
Diagnostic logs, analytics data if you enabled it, and IP-related security records are kept for limited periods appropriate to their purpose and are then deleted or de-identified. Moderation and enforcement records are kept for as long as they are needed to handle appeals and repeat violations.
Deleted information is removed from live systems immediately. Backup copies may persist briefly until they are overwritten in the ordinary backup cycle. A film that a member has explicitly saved into their own Photos library is under that member’s control and Apple’s, and is outside Panoptik’s reach.
11. Account Deletion
You can permanently delete your account at any time from Settings inside the app, without contacting support. Deletion is immediate and cannot be undone. There is no recovery window and no deactivated state.
Deleting your account removes your profile, your event memberships, your device tokens, your analytics data if you enabled analytics, and every clip you uploaded — including clips in events created by someone else. Because a film is assembled from the clips in an event, another member’s film may change after you delete your account.
If you created an event that still has other members, you choose a successor to take ownership before deletion completes. Events with no other members are deleted outright.
Guest passes can be deleted too. Delete Guest Data removes the guest identity, its event membership, its local Panoptik data, and any linked analytics. Clips a guest already contributed to a shared event remain in that event without attribution, so the group’s film is not broken. If you want those removed as well, contact support and we will remove them.
If a storage or analytics provider is temporarily unavailable, deletion of that provider’s copy is queued and retried until it succeeds. Copies a member explicitly saved to their own Photos library are outside Panoptik’s control.
If you cannot sign in to reach Settings, email support@panoptikapp.com from the address on the account and we will verify the request and delete it for you.
12. Your Choices and Rights
Inside the app you can change your username and profile photo, turn Share Product Analytics on or off, turn notifications on or off, block another member, leave an event, and delete your account or your guest data.
Depending on where you live, you may also have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. You can exercise any of these rights by emailing support@panoptikapp.com. We will respond within the period applicable law requires, and may need to verify your identity first.
California residents have the rights described above, including the right to know, delete, correct, and obtain a copy. Panoptik does not sell personal information and does not share it for cross-context behavioural advertising, so there is no opt-out to offer. We will not discriminate against you for exercising a privacy right.
Because there is no common industry standard for browser Do Not Track signals, this website does not currently respond to them.
13. Children
Panoptik is for people aged 13 and over. A neutral age screen runs before you can reach any app feature, and the check is repeated on the server so a modified app cannot bypass it. Anyone under 13 is refused an account.
If you are under 18, use Panoptik only with the permission of a parent or legal guardian.
Panoptik does not knowingly collect information from children under 13. If you believe a child under 13 has an account, email support@panoptikapp.com and we will delete the account and its associated information.
14. International Users
Panoptik is operated from the United States, and data is processed and stored there, where data-protection law may differ from the law where you live. By using Panoptik you understand that your information is processed in the United States.
If you are in the European Economic Area or the United Kingdom, our lawful bases are: performance of our contract with you, for running your account, events, clips, and films; your consent, for optional product analytics, which you may withdraw at any time; and our legitimate interests in keeping the service safe, for moderation, abuse prevention, and security records. You may lodge a complaint with your local supervisory authority, and you can reach us on any data-protection question at support@panoptikapp.com.
15. Website and Cookies
This website is static. It sets no advertising cookies, runs no advertising SDKs, and does not track you across other sites. The support form sends only what you type into it, together with your email address, so that we can reply.
The Panoptik app uses no advertising cookies and no advertising SDKs.
16. Security
Panoptik uses access controls, authenticated sessions, encryption in transit, row-level database rules that restrict every record to the people entitled to it, private storage with short-lived signed access, and narrowly scoped moderator roles with an immutable audit trail.
No system is completely secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed. If we become aware of a breach affecting personal information, we will notify affected people and regulators as applicable law requires.
17. Changes to This Policy
We may update this policy as the app changes. If a change is material we will notify members in the app, by email, or by another reasonable means before it takes effect where the law requires, and the app will ask you to accept the updated terms.
The updated policy takes effect when posted unless a later effective date is stated.
18. Contact
For privacy questions, data access or deletion requests, or safety concerns, contact support@panoptikapp.com.
Reports of objectionable content are acted on within 24 hours. To report non-consensual intimate imagery, email support@panoptikapp.com with “NCII Removal Request” in the subject line. Copyright concerns follow the procedure in our Terms of Service.