Privacy Policy

Last updated: August 2026

1. Data Controller

The data controller within the meaning of the GDPR is:

Jan Ole Schmidt
Kellersweg 7
35764 Sinn
Germany

E-Mail: hello@usepalim.com

2. What Data We Process

When using Palim, the following data is processed:

  • Account data: Email address and a salted password hash processed by Supabase Auth for authentication. Palim does not store the plaintext password.
  • Session content: The AI conversations, summaries, and notes you explicitly save with the Palim MCP server.
  • Metadata: Timestamps, tags, and other metadata you assign to your sessions.

Storing your choice (marketing site): We set a cookie `palim_cookie_consent` (one-year lifetime, path “/”, SameSite=Lax) to remember your decision on optional statistics — so we can honor a refusal persistently. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in transparent, compliant cookie handling).

Optional analytics (marketing site): If you consent, we load Vercel Web Analytics and Vercel Speed Insights (provider: Vercel Inc.). Aggregated usage data and Web Vitals (performance) are processed; Vercel may use first-party cookies or similar technologies for this. We do not run ad tracking. Legal basis when you consent: Art. 6(1)(a) GDPR. You may withdraw consent by deleting this cookie and visiting the site again.

3. Legal Basis

Your data is processed for the performance of the contract (Art. 6(1)(b) GDPR). Storage is at your explicit request — Palim only stores what you actively save with the MCP tools.

4. Data Storage & Processing

Your data is stored on servers operated by Supabase.

The infrastructure (API server) is provided via Render.com, Frankfurt region (EU).

For sending email (e.g. the weekly digest) we use Resend, Inc. Your email address and the content of that message are processed in the United States.

Disclosure to the AI tools you connect: Palim delivers stored content, decrypted, to whichever AI client requests it — ChatGPT, Claude, Cursor, or any other MCP-capable client. You trigger that disclosure yourself by connecting a client and initiating a retrieval there. Those providers are not processors of Palim: we do not engage them, we hold no processing agreement with them, and we cannot influence what they do with the retrieved data. From the moment of delivery, their own privacy and processing terms apply, and you are in a direct contractual relationship with them. Before connecting a client, check whether that provider's terms are appropriate for the data you keep in Palim.

Consolidation of oversized knowledge topics: Palim can have a topic document that exceeds its size limit rewritten by a language model. Doing so transmits that one topic's decrypted content to Anthropic PBC (United States), where it is processed solely to rewrite that document. The United States is a third country without an adequacy decision covering this provider; before the feature is enabled we put Standard Contractual Clauses under Art. 46(2)(c) GDPR in place and state that fact here. The legal basis for the transfer would be Art. 6(1)(b) GDPR (performance of the contract). The feature is currently switched off: while it is off, no such transfer takes place. It is enabled only through an explicit server setting; a stored API key alone is not enough. The active state is publicly visible at api.usepalim.com/health under „brain_consolidation“; a value of „none“ means no such transfer takes place. No recipient other than the one named here can be enabled — the server refuses to start while a provider is missing from this privacy policy.

5. Encryption

Supported stored content fields are encrypted server-side at rest with AES-256-GCM. A separate key is derived for each user via scrypt from a Palim-managed master key. This is not end-to-end or zero-knowledge encryption: Palim can decrypt content to provide the service. Account data and operational metadata are processed separately. Transfers use HTTPS/TLS.

6. Retention

Your data is stored for as long as your account exists. You can delete individual sessions at any time. For account-deletion requests or privacy-rights requests, contact privacy@usepalim.com; self-service account deletion is not currently available.

7. Your Rights

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR): What data we hold about you.
  • Rectification (Art. 16 GDPR): Correction of inaccurate data.
  • Erasure (Art. 17 GDPR): Removal of your data ("right to be forgotten").
  • Restriction (Art. 18 GDPR): Restricted processing of your data.
  • Data portability (Art. 20 GDPR): Export of your data in a standard format.
  • Objection (Art. 21 GDPR): Object to processing.

To exercise these rights, contact: privacy@usepalim.com

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. The competent authority is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), P.O. Box 3163, 65021 Wiesbaden, Germany.

9. Beta Notice

Palim is currently in public beta. Although we take great care with the security of your data, we cannot guarantee full data availability during the beta phase. For critical data, we recommend additional backups via the export function.

© 2026 Palim — Imprint