Privacy Policy

Effective date: July 15, 2026 

This Privacy Notice explains how Panel Labs s.r.o. collects and uses personal data in connection with the Panel website, Application, public projects, embeds, AI Features, support, and related services.


1. Who is responsible for your data 

The controller for Panel's own purposes is:

Panel Labs s.r.o.

Company ID (IČO): 24106682

Registered office: Příčná 1892/4, Nové Město, 110 00 Praha 1, Czech Republic

Registered in the Commercial Register maintained by the Municipal Court in Prague, file C 437858

Email: hello@panel.design

Contact form: https://www.panel.design/contact

In this Notice, “Panel,” “we,” “us,” and “our” mean Panel Labs s.r.o.

Panel has not appointed a data protection officer at launch. You may direct every privacy question or request to the contact details above.

 

2. Scope of this Notice

This Notice applies when you:

  • visit panel.design;

  • create or use an Account at app.panel.design;

  • create, upload, edit, generate, publish, or embed content;

  • view a Public Project or Embed;

  • purchase or manage a Subscription;

  • contact support or submit a report;

  • request Account deletion; or

  • otherwise interact with Panel.

It does not govern an independent third-party website that embeds a Panel Project, Polar's processing as Merchant of Record, or another provider's processing for its own purposes. Those parties may provide their own privacy information.

 

3. Personal data we process

The exact data depends on how you use Panel.


3.1 Account and identity data 

This can include:

  • name;

  • email address;

  • Account and authentication-provider identifiers;

  • profile information;

  • organization or business name, if supplied;

  • Account status and Plan; and

  • records of acceptance of our Terms and policies.

 

3.2 Authentication and session data

This can include:

  • login and session identifiers;

  • authentication events;

  • security and device information;

  • approximate location derived from network information;

  • IP address in provider or security logs; and

  • essential cookies or similar storage used to keep you signed in and protect the Service.

Authentication is provided using WorkOS/AuthKit.

 

3.3 Subscription and billing data

This can include:

  • Polar customer, order, product, and subscription identifiers;

  • Plan, price, billing currency, tax status, renewal date, and subscription status;

  • payment success, failure, refund, cancellation, or chargeback status;

  • receipt and invoice metadata; and

  • limited customer contact and business-tax information.

Panel does not need to receive full payment-card details. Polar acts as Merchant of Record and payment processor and provides its own privacy information for its transaction processing.

 

3.4 User Content and Project data

This can include:

  • Project names, structures, editor state, text, dialogue, and settings;

  • uploaded images and videos;

  • reference images and profile labels;

  • prompts, generation parameters, and model settings;

  • generated images and associated metadata;

  • publication status, slugs, public links, and embed settings; and

  • storage and file metadata.

Content can contain personal data about you or other people. You are responsible for having the rights, permissions, consent, or other lawful basis needed to submit and use it.

 

3.5 AI Feature data

When you use an AI Feature, we may process and send to our AI provider chain:

  • prompts and instructions;

  • reference images or other selected assets;

  • aspect ratio, resolution, quantity, and generation settings;

  • Account, Project, request, and usage identifiers;

  • generated Outputs; and

  • technical response, moderation, and error metadata.

At launch, Panel routes image-generation requests through Vercel AI Gateway to the downstream model made available as bytedance/seedream-4.5.

The current downstream route does not provide Panel with a confirmed zero-data-retention guarantee. Do not submit passwords, trade secrets, highly sensitive personal data, or other information that you cannot lawfully and safely share with an AI provider.

 

3.6 Character and Style Profile data

Character and Style Profiles are simple reference-image and metadata workflows intended to guide visual consistency. Panel may store the selected reference asset, a label or role, and related Project or generation metadata.

At launch, Panel does not intentionally use these workflows to:

  • recognize a face;

  • match a person to an identity database;

  • create a biometric identity template; or

  • infer sensitive personal traits.

You must not use an identifiable real minor as AI Reference Material at launch.

 

3.7 Public-project and viewer data 

When someone views a Public Project or Embed, Panel and its infrastructure providers may process:

  • the requested page or asset;

  • date, time, and basic request information;

  • IP address and browser/device information in ordinary server, CDN, or security logs;

  • a bounded session or deduplication identifier;

  • publication and performance events; and

  • information the viewer voluntarily sends through a contact or report flow.

Panel's intended product analytics do not include raw prompts, Project text, asset filenames, or full public URLs as analytics properties.

 

3.8 Support, rights, deletion, and report data

This can include:

  • contact details;

  • Account email;

  • the content of the message;

  • public URLs or content identifiers;

  • identity or authority verification;

  • evidence attached to a complaint or rights notice;

  • our investigation notes and outcome;

  • correspondence; and

  • billing, security, legal, or moderation records relevant to the request.

Please send only the information reasonably necessary for us to handle the matter.

 

3.9 Usage, credit, technical, and security data

This can include:

  • AI Credit grants, reservations, deductions, releases, expiry, and adjustments;

  • feature-use and bounded product events;

  • upload and generation rate-limit records;

  • server and application logs;

  • errors, stack traces, and scrubbed runtime metadata;

  • deployment, webhook, and billing-event records;

  • suspected abuse, fraud, or security signals; and

  • records needed to protect Accounts and infrastructure.

Sentry is configured for error monitoring with default PII collection disabled and without Session Replay in the intended launch configuration. Sensitive fields are intended to be removed before transmission.

 

4. How we receive personal data

We receive data:

  • directly from you;

  • from the person or organization that creates or manages an Account for you;

  • automatically from your browser, device, and use of the Service;

  • from WorkOS/AuthKit;

  • from Polar;

  • from a person who publishes, embeds, reports, or refers to content;

  • from our hosting, storage, security, analytics, and AI providers; and

  • from competent authorities or other parties where relevant to a legal, safety, fraud, or rights matter.

 

5. Why we process personal data and our legal bases

The legal basis depends on the purpose and the law that applies.

Where we rely on legitimate interests, we consider the necessity of the processing, its impact on people, reasonable expectations, and available safeguards. You may object as explained below.

We do not treat the Privacy Notice or general use of the Service as consent for processing that legally requires a specific consent.

 

6. AI data use and training

Panel does not use private prompts, Reference Material, Projects, or Outputs to train its own AI models at launch.

For the current AI route, Panel uses the available provider setting to disallow prompt training. This setting is not the same as zero data retention. Downstream AI providers may still process or retain Inputs and Outputs for service delivery, safety, abuse prevention, legal compliance, or another purpose described in their applicable terms. Panel does not promise zero retention for the current Seedream route.

Before submitting an Input, consider whether:

  • you have the right to share it;

  • it contains personal data about another person;

  • the depicted person has given any consent required by law;

  • it includes confidential or sensitive information; and

  • the intended Output and use are lawful.

We may change models or providers. If a change materially affects privacy, we will update this Notice or provide another appropriate notice.

 

7. Public Projects, unlisted links, and embeds

7.1 Public content

A Public Project can be viewed by anyone with its URL and may be indexed by search engines. Published Content may include personal data that the creator chose to make public.

An unlisted Project may use a noindex instruction, but anyone who obtains the URL can still access it. “Unlisted” is not the same as private, confidential, or access-controlled.

 

7.2 Third-party copies

Viewers, search engines, archives, and third-party websites may copy, cache, screenshot, record, or embed Published Content. Unpublishing or deletion from Panel does not necessarily remove copies controlled by others.

 

7.3 Embeds

A third-party website that embeds Panel content may collect data under its own policies and may combine the Embed with other scripts. Panel does not control that site's independent processing.

 

8. Cookies, local storage, and analytics

8.1 Necessary technology

Panel uses or may use necessary cookies and similar storage for:

  • authentication and session continuity;

  • security and fraud prevention;

  • remembering essential settings;

  • preventing duplicate events; and

  • maintaining basic Application operation.

The Application may use localStorage or sessionStorage for bounded operational purposes such as session deduplication or a daily event throttle.


8.2 Framer Analytics 

The public website uses Framer and its built-in aggregate analytics. In the launch configuration, Framer Analytics is cookieless and does not use persistent identifiers for cross-site behavioral advertising.

 

8.3 PostHog

Panel uses PostHog for limited product analytics in the Application. We collect only a small allowlist of operational product events, such as app sessions, project creation, completed AI generation, credit usage, publishing and limited reader activity. Autocapture, automatic pageview tracking, session replay, surveys, feature flags and PostHog error tracking are disabled. We do not send raw prompts, Project text, uploaded media, asset filenames, Project titles, slugs, full URLs, signed URLs or editor payloads to PostHog. PostHog data is hosted in its EU environment.

 

8.4 Marketing and newsletter

The marketing website offers an optional newsletter signup. If you subscribe, we use your email address to send occasional Panel news and product updates based on your consent. You can withdraw your consent at any time using the unsubscribe link in each message or by contacting hello@panel.design. The newsletter signup and delivery provider processes the address on our behalf as described in this Notice.

 

9. Who receives personal data

We share personal data only as reasonably necessary for the purposes in this Notice.

 

9.1 Core providers

Current or intended launch providers include:

  • WorkOS/AuthKit — Account authentication, identity, and sessions.

  • Polar Software, Inc. — Merchant of Record, checkout, payment transaction, tax handling, receipts/invoices, subscriptions, refunds, chargebacks, and Customer Portal.

  • Vercel — website/Application hosting, serverless runtime, technical operation, observability, and AI Gateway.

  • Convex — application database, backend functions, usage and credit logic, and related storage.

  • Cloudflare R2 — storage and delivery of uploaded, generated, and Published Content.

  • Sentry — scrubbed error monitoring.

  • Framer — marketing, legal, and contact pages and aggregate website analytics.

  • PostHog — limited product analytics only where enabled and lawfully configured.

  • The downstream AI model provider made available through Vercel AI Gateway for bytedance/seedream-4.5.

  • Email and infrastructure providers used to receive and respond to messages.

 

These providers process different data for different roles. Many act as processors or service providers for Panel. Polar also acts as an independent controller for significant payment, tax, fraud, and legal functions as Merchant of Record.

 

9.2 Other recipients

We may also disclose data:

  • to professional advisers, insurers, auditors, or transaction advisers under confidentiality;

  • to a buyer, investor, successor, or affiliate in a genuine corporate transaction, subject to appropriate safeguards;

  • to a rights holder or reporter where necessary to resolve a notice, while minimizing disclosure;

  • to a competent court, regulator, law-enforcement body, or other authority where required or lawfully necessary;

  • to protect a person from serious harm; or

  • with your direction or consent.


We do not sell personal data or share it for third-party cross-context behavioral advertising.

 

10. International transfers

Panel is established in the Czech Republic, but some providers are based in or process data from countries outside the European Economic Area.

Where EU data-protection law applies and a transfer requires safeguards, we seek to rely on an applicable mechanism such as:

  • an adequacy decision;

  • the EU-US Data Privacy Framework where a recipient is eligible;

  • Standard Contractual Clauses;

  • another lawful transfer safeguard; or

  • a limited statutory derogation where appropriate.

The exact location of downstream AI processing may depend on provider routing. Panel does not promise EU-only processing for AI Features.

You may contact us for more information about the safeguards relevant to your data. Some provider contractual details may be confidential, but we will provide the information required by law.

 

11. How long we keep data

We keep personal data only for as long as reasonably necessary for the stated purpose, the Account relationship, security, disputes, and legal obligations.

The following are the launch rules and targets

Provider-level records may follow provider settings where Panel cannot delete one person's entry separately. We will periodically review and refine these periods as the service matures.

 

12. Account deletion 

12.1 How to request deletion

There is no instant self-service Account deletion function at launch.

Submit a request through https://www.panel.design/contact or email hello@panel.design from your Account email and state “Account deletion.”

We may ask you to: 

  • confirm access to the Account email;

  • sign in or provide Account identifiers;

  • verify authority where the Account belongs to an organization; and

  • resolve a billing, ownership, security, or legal issue before deletion.

 

12.2 Timing and effect 

We aim to:

  • acknowledge a request within 7 calendar days;

  • answer a data-protection request within the period required by law, normally one month under GDPR; and

  • remove data from active primary systems within 30 days after verification and resolution of outstanding issues.

These are operational targets, not a promise of immediate deletion from every system.

When closure is executed, we will ordinarily:

  • end Account access;

  • unpublish Public Projects;

  • expire unused AI Credits;

  • delete or schedule deletion of Account and Project data in active systems; and

  • confirm completion or explain what remains and why.

     

12.3 Active Subscriptions

Account deletion is not a reliable substitute for canceling a Subscription until Panel or Polar confirms cancellation. You should cancel future renewal through the authenticated Polar Customer Portal.

We will assist after verification. Deletion may end remaining paid access without an automatic refund, subject to mandatory consumer law and case-by-case review.

Polar may retain payment, tax, fraud, dispute, and transaction records under its independent legal obligations.

 

12.4 Retention exceptions and backups 

We may retain limited data where necessary for:

  • tax or accounting law;

  • fraud, security, or abuse prevention;

  • legal claims and disputes;

  • chargebacks and payment ownership;

  • moderation evidence;

  • lawful requests; or

  • a legal hold.


Protected backups may not permit deletion of one item or Account. Data may remain until ordinary backup rotation or expiry. It is not used for ordinary operations. If a backup is restored, deleted Accounts should be re-deleted or suppressed through the restoration procedure.

 

13. Your rights

Depending on the law that applies, you may have the right to:

  • obtain information about processing;

  • access your personal data;

  • correct inaccurate or incomplete data;

  • request deletion;

  • restrict processing;

  • receive certain data in a portable format;

  • object to processing based on legitimate interests;

  • withdraw consent at any time where processing relies on consent;

  • object to direct marketing; and

  • lodge a complaint with a supervisory authority.

A withdrawal of consent does not affect earlier lawful processing.

To exercise a right, use https://www.panel.design/contact or hello@panel.design. We may verify identity and authority. We normally respond within one month under GDPR, but may extend the period by up to two additional months where legally permitted because of complexity or volume, in which case we will tell you.

Rights are subject to legal conditions and exceptions. For example, deletion does not require us to erase a record that we must retain by law or reasonably need for a legal claim.

 

14. Complaints

You may contact the supervisory authority in the country where you live, work, or believe an infringement occurred.

Panel's lead Czech authority is: 

Úřad pro ochranu osobních údajů

Pplk. Sochora 27

170 00 Praha 7

Czech Republic

https://uoou.gov.cz

 

We encourage you to contact us first so that we can try to resolve the issue, but this is not a requirement for filing a complaint.

 

15. Automated decisions

Panel does not make solely automated decisions that produce legal effects or similarly significant effects about users at launch.

AI generation is automated content creation at the user's request, not a decision about the user's legal rights. Automated security or provider signals may help flag activity, but material Account or content action is subject to human review where required and reasonably possible.

 

16. Security 

We use reasonable technical and organizational measures appropriate to an early-stage SaaS service, including HTTPS/TLS in transit, authentication controls, ownership checks, provider access controls, rate limits, and minimization or scrubbing of selected monitoring data.

No online service is completely secure. We do not claim:

  • absolute security;

  • end-to-end encryption;

  • a security certification;

  • guaranteed uptime;

  • automatic daily backups;

  • a tested disaster-recovery program; or

  • instant deletion from every backup.

Please protect your Account and contact us promptly if you suspect unauthorized access or a security issue.

 

17. Children

A person must be 18 or older to create or control an Account. Panel does not knowingly offer Accounts to children and does not support parental-consent or school-account workflows at launch.

If you believe a child has created an Account or provided personal data contrary to this rule, contact us. We will review and take appropriate steps, which may include restricting the Account and deleting data subject to verification and legal retention.

Creators must not submit an identifiable real minor's image as AI Reference Material at launch.

 

18. Business users and third-party personal data

A Business User may upload content that contains personal data about clients, collaborators, performers, employees, or other people. The Business User is responsible for determining its own lawful basis and notices.

Panel does not offer a standard Data Processing Agreement at launch. Unless Panel separately agrees in writing, do not use the Service for processing on behalf of an organization where a DPA is legally required.

This restriction does not change the legal classification that applies to a particular activity; it limits the supported launch use of the Service.

 

19. Changes to this Notice 

We may update this Notice as the Service, providers, processing, or law changes.

For a material change, we will use an appropriate notice, such as an Account email, an in-app message, or a prominent website notice. The “Effective date” identifies the current version.

A change to this Notice does not reduce rights granted by applicable law and does not turn a new purpose requiring consent into consent merely through continued use.

 

20. Contact

For privacy questions, access requests, Account deletion, objections, complaints, or other data-protection matters:

  • https://www.panel.design/contact

  • hello@panel.design

Please use the Account email where possible and include enough information for us to identify the request without sending unnecessary sensitive data.