oddrefresh

PennyOS fine print

Privacy policy

What this website, the PennyOS software, and the services the project operates do with your information. Effective 14 September 2026.

The short version

PennyOS is software you install on your own Beepy and, optionally, your own server. The project has no accounts, no analytics and no advertising, and it does not collect data from your device. What you write stays on your device and your server. A few features reach public services or small hubs the project runs, and this page says exactly what each one sees.

Who this covers

This policy covers three things: this website, the PennyOS software, and the hosted services the PennyOS project operates for the software's optional features. Questions go to the Contact me button on this page.

This website

  • The site is static files served by Cloudflare Workers. It sets no cookies and runs no analytics. Images are served from this domain.
  • The pages load the Schibsted Grotesk and Martian Mono typefaces from Google Fonts, so Google receives the requests for the stylesheet and font files, including your IP address, under the Google privacy policy. No other third party script or stylesheet is loaded.
  • Cloudflare processes each request to deliver it, which involves your IP address and browser details, under the Cloudflare privacy policy. The site's Worker has Workers Logs turned on, so those request details are also kept for a limited time in the Cloudflare account that runs it. The project does not use those logs to identify visitors.
  • The Contact me button opens your own email program. What you choose to send is used only to reply and grant access.

The software on your device and server

  • Notes, journal entries, the vault mirror, caches, saved places and settings are stored on your device, inside an encrypted volume once you set one up. They are not sent to the project.
  • Sync copies your notes and journal to your server over SSH. The project never receives them.
  • Service credentials, including mail tokens and search API keys, are stored on your server, never on the device and never with the project. The device holds its own SSH key, inside the encrypted volume, random pairing ids for Link and News, and, if you set one up, a boot key that can fetch only the card's second key.
  • PennyOS contains no telemetry, crash reporting or update check.

Services the project operates

By default, three features talk to small Cloudflare Workers run by the PennyOS project. You can point PennyOS at your own copies with link_url and news_url in the configuration.

ServiceUsed byWhat it receives and keeps
Link hubLink, and the Penny glasses appA random pairing channel id. While the monitor is on, the text you are typing, held in memory and gone after ten minutes. The last Ask or Chat answer for a day, the glasses' location for six hours, your saved places until replaced, marks for seven days if unclaimed, and headlines saved for the device for thirty days. The /where route returns the approximate city Cloudflare associates with your IP address and stores nothing. Text passes in plaintext over HTTPS; the channel id is the credential. Cloudflare request logs are turned on for the hub and kept for a limited time. They include request paths, and a path includes the channel id.
News APINewsA random reader id, the feeds you subscribe to, and which articles you have read and when, so read state can be shared with a paired reader. The same service can also store a summary API key, in plain text, for a reader that sets one. PennyOS News does not send one. None of this has a deletion schedule: it stays until you ask for it to be removed.
Property lookupStoreYour location (latitude and longitude) for Store near you, partial addresses as you type them, and the addresses, business names and owner names you look up, to answer them from San Francisco public records. It keeps no database, but its questions to the city's data portal stay in Cloudflare's edge cache for six hours to a week, and its request logs are turned on and kept for a limited time.

None of these services asks for your name or email. The project does not sell, rent or share what they receive, and does not use it for advertising or profiling.

Third-party services the software contacts

Some apps fetch public data directly from other providers. Each receives your IP address and the request itself, such as coordinates for a forecast, and each has its own privacy policy.

  • Weather and Field: Open-Meteo, OpenStreetMap's Overpass API and Nominatim, Photon by Komoot, and Wikipedia. Searching for a place sends the name you type to Open-Meteo's geocoding API. Field also downloads public data from USGS (earthquakes) and Where the ISS at (the station's position); neither receives your coordinates.
  • Locate: BeaconDB receives the Wi-Fi access points your device can hear, to estimate a position.
  • Ask, Store dig and Search web pass: your server sends your question to Anthropic through Claude Code, under your own Anthropic account and terms.
  • Search: your server queries public sources such as crt.sh, RDAP, the Internet Archive, Shodan InternetDB, ipwho.is, Gravatar and GitHub, and any keyed services you configure.
  • Mail: your server connects to your mail provider over IMAP.

Google user data

The Mail app can read a Gmail mailbox over IMAP using Google OAuth with the scope https://mail.google.com/. When it does:

  • What is accessed: message headers (sender, subject, date) and message text from the inbox of the account that granted access.
  • How it is used: only to display that account owner's own messages on their own device. Nothing is sent, deleted, labelled or moved. Opening a message marks it as read, which is the one change it makes.
  • Where it is stored: the OAuth token is stored in a file readable only by the account owner's user on the account owner's own server. A copy of recent headers and message text is cached on the account owner's own device so the inbox can be read offline. No Google user data is stored on any server operated by the PennyOS project, and none is transmitted to the project.
  • Sharing: Google user data is not shared with, sold to or transferred to anyone.

PennyOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the mail reading feature to the user who granted access, is never used for advertising, and is never transferred to others except as necessary to provide that feature, to comply with law, or with the user's explicit consent.

Access can be revoked at any time at myaccount.google.com/permissions. Cached messages are removed from the device with Settings > Device > Clear cache, or by erasing the card.

Retention and deletion

Everything on your device and server is yours to delete. Clear cache removes fetched data; notes and journal entries are removed by deleting them. For the Link hub, pressing u in Link retires your channel; the remaining documents expire on the schedule above. To ask for News or Link data tied to a reader or channel id to be deleted sooner, send the id through the Contact me button on this page.

Children

PennyOS and this site are not directed at children under 13 and do not knowingly collect information from them.

Changes

This policy changes when the software does. The effective date at the top is the date of the current version. Material changes are noted in the release notes.