The Panel Privacy Policy
Effective date: 7 October 2026
Last updated: October 2026
Policy version: 2026-10-07
Summary (plain language, not a substitute for the full policy)
- The Panel asks several AI providers your question (or an AI answer you paste in for a Second Opinion), and shows you where they agree, disagree, and what a synthesized Panel Verdict says.
- Nothing you write is sent to AI providers, or to our safety check, until you give affirmative permission on the in-app permission screen. Skipping onboarding is never treated as that permission.
- Your content travels through Cloudflare (our network edge) to our server, and from there to OpenRouter (a routing service) and, through it, to OpenAI, Google, Anthropic, and xAI, the companies behind the AI panelists. Some of these companies also see other panelists' answers, because comparing AI answers requires at least one model to see them together. Full detail is in "Who receives your content" below.
- We do not sell or share your personal information for advertising, and the app carries no ad network or ad tracking. We do not use your information to train AI models.
- We do not promise that AI providers retain nothing, train nothing, or process anything anonymously. Those are not guarantees we can make on their behalf. We summarise what each company's own published terms say, and link nothing we can't stand behind.
- Model Consensus (how much the AI panelists agree) is not a measure of accuracy or truth, and Panel outputs can be wrong or incomplete. Do not rely on The Panel for medical, legal, financial, or other professional decisions.
- An automated safety check, run for us by OpenAI, reviews your question before Panelists see it and reviews each answer and the Panel Verdict before we save or show them. Some content is blocked or withheld to prevent harm. See "Who receives your content" and our Usage Policy for detail.
- Your Panel Checks are saved to your History unless you turn Save Run History off. You can turn it off, set History to auto-delete, export your data, and delete your account at any time from Account → Data & privacy.
- If your account is closed under our Usage Policy, you can still export your data or delete your account. Appeals and reports are handled by email, reviewed by a person.
- This summary is an aid to reading the policy, not a substitute for it. If anything here conflicts with the full text below, the full text controls.
1. Who we are
The Panel is operated by an individual developer based in the Philippines, who publishes it through an Apple Developer Program individual account. The developer's legal name is the Seller shown on The Panel's App Store page.
support@appsbynikki.com
We are the controller (or the equivalent term where you live) of the personal information described in this policy. The companies in §6 process it for us, under our instructions, except where this policy says otherwise: Apple handles App Store payments and Sign in with Apple as an independent company; OpenRouter and the AI companies decide for themselves how long to keep the limited copies their own terms allow (§6); and Cloudflare uses traffic information for its own network security under its privacy policy.
Data Protection Officer (Singapore; also Privacy Officer for Canada and New Zealand; for Québec, the person in charge of the protection of personal information): the operator of The Panel, support@appsbynikki.com.
2. Scope
This policy covers The Panel iOS app. It applies to users in the countries where The Panel is offered: United States, Canada, Australia, New Zealand, and Singapore. We are not offered in mainland China and have no storefronts there.
Regional sections in §12 apply as noted.
Minimum age: you must be at least 18 years old to use The Panel (Terms of Use §2). We do not knowingly collect personal information from anyone under this age; if we learn we have, we will delete it.
3. Information we collect
Identity, via Sign in with Apple and Supabase
When you sign in, we receive your Apple-issued identity: the Apple user ID for The Panel, and nothing else. The app does not ask Apple for your name or email address, so we do not receive or store either. Sign-in and sessions are handled for us by Supabase, our authentication provider, which holds that Apple user ID, your session tokens, and the network address and device details of each sign-in while that session exists, and keeps its sign-in event logs for 7 days; The Panel's own database stores the resulting account record. There is no profile or display name.
Age range from Apple
Where a law requires it (currently Texas; Utah, Louisiana and California from 2027), the app asks Apple for your age range (for example "18 or over") when you sign in. We use it only to keep The Panel for adults and to comply with those laws. We don't keep the age range once the check is done, and we never receive your date of birth.
What you submit
- The question you ask, or the AI answer you paste in for a Second Opinion, and any optional context you add.
- Anything you type directly into those fields is part of the request, including if you type something sensitive. Please avoid including personal or sensitive information you don't need to.
- Your question, submitted answer, or context may include health or other sensitive information if you choose to include it, for example a medical question. We don't ask for it. We process it only with the permission you give on the permission screen (§5), to produce your result, keep it in History under your settings, run the safety check described in "Who receives your content" below, and enforce our Usage Policy.
What we generate
- Panelists' independent answers ("Original Responses"), extracted claims, stance comparisons, dissent and Minority View analysis, and the synthesized Panel Verdict.
History
- Save Run History is on for new accounts, because keeping your own results in your History is part of the service. You can turn it off at any time in Account → Data & privacy. Turning it back on also keeps any earlier Panel Check whose content we haven't yet removed.
- If Save Run History is on, completed runs are saved to your account History, subject to any auto-delete period you set.
- If Save Run History is off, a run's content is still processed to produce your result, but is removed from The Panel within 24 hours of the run finishing (see "Retention" below), and it is never listed in History.
Usage, allowance, and subscription status
- Your Panel Check allowance and purchased credits, and your subscription status (Free trial or Pro, and its renewal state), as read from Apple's App Store systems. We do not receive or store your card number or other payment credentials: Apple handles payment.
Device and diagnostic data
- Standard technical data needed to operate the service (for example, app version, device/OS version where needed for compatibility, and error/status codes).
- Share Diagnostics is a setting in Data & privacy, off unless you turn it on. While it is on, the app sends a crash report to Sentry, our crash-reporting service (§6), when the app crashes or freezes. After your first completed Panel Check the app asks you once whether to turn it on; either answer is remembered, and you can change it at any time. A crash report holds what is needed to find the fault: the stack trace of the crash or freeze, the device model, the iOS and app versions, and when it happened. It never includes your questions, submitted answers, AI responses, or results, and we do not attach your name, email address, account ID, or a device identifier to it. Turning the setting off stops reports straight away. Signing out turns crash reporting off on that device until you sign in again and your setting is read from your account.
- The app does not collect product analytics or usage tracking of any kind, and there is no setting for it.
Logs
Our operational logs do not contain your prompt or response text. They are built to be content-free by construction: fields are limited to identifiers, status, timing, error categories, provider names, and similar operational metadata. A database error is logged as an error class and code only, never the text of the failed request.
The logs do include your network (IP) address. Every request line records the address the request came from, together with the route requested (never the text of a History search). An IP address is personal information. These logs live in our hosting provider Fly.io's log stream, which keeps them for 7 days; we do not copy them anywhere else. Cloudflare, which stands in front of our server (§6), also sees your network address on every request. Separately, Philippine law requires us to keep a short record of each Panel Check you start, described in §7.
On your device
See "On your device" below.
4. How and why we use your information, and our legal bases
| Purpose |
What it uses |
Legal basis (GDPR-style; regional sections in §12 add local detail) |
| Create and operate your account |
Sign-in identity |
Performance of a contract with you |
| Check your age range where a law requires it |
Age range from Apple |
Legal obligation |
| Run a Panel Check / Second Opinion and show you the result |
Submitted question/answer/context, generated results |
Performance of a contract with you, and your affirmative provider-sharing permission for the content sent to AI providers (§5) |
| Process health or other sensitive information you choose to include |
The parts of your question, submitted answer or context that contain it |
Your consent, given on the provider-sharing permission screen, which tells you questions can include health information and that we check them for safety |
| Maintain your History (unless you turn it off) |
Saved runs |
Performance of a contract with you |
| Track your allowance and subscription |
Usage counters, Apple subscription status |
Performance of a contract with you |
| Prevent abuse of the free trial and enforce spend/rate limits |
Keyed identity fingerprints, rate/spend counters |
Legitimate interests (protecting the service and other users from abuse) |
| Operate, secure, and debug the service |
Operational logs, security events |
Legitimate interests |
| Keep the record of Panel Check requests that Philippine law requires (§7) |
Internal account number, network address, time |
Legal obligation |
| Crash reports (Share Diagnostics, a setting you turn on; off by default) |
Crash and freeze reports: stack traces, device model, iOS and app versions |
Consent (you opt in; default off) |
| Run the safety check on your questions, answers, and the Panel Verdict, and withhold harmful content |
Submitted content, generated results |
Legitimate interests (preventing harm and misuse), within the permission you gave (§5) |
| Enforce our Usage Policy (recording a strike, a child-safety event, or closing an account) |
Keyed identity fingerprints, strike/event records, and, for 90 days, the full question you wrote, when it earned a strike |
Legitimate interests (protecting the service and other users), and legal obligation where reporting to an authority is required |
| Comply with law, respond to lawful requests |
As applicable |
Legal obligation |
5. Provider-sharing permission
Before your question, submitted answer, or context is sent to any AI provider, you must give affirmative permission on an in-app permission screen. This is required for every standard Panel Check or Second Opinion the first time, and again whenever the disclosure content or the set of providers changes (see "Changes to this policy" below). There is no "minor edit" exception.
Skipping onboarding is never treated as consent to provider sharing. Only the explicit "Enable permission" action on the permission screen grants it, and what you agree to is the exact disclosure text shown to you at that moment: if that text changes, you are asked again before the next Panel Check.
What the permission covers:
- sending your content to OpenRouter and the AI providers named on the screen, and to OpenAI's safety check (§6);
- processing health or other sensitive information you choose to include, as described in §3;
- overseas handling. The AI providers and OpenRouter are overseas companies that handle your content under their own terms, which we don't control. If you're in Australia: by allowing provider sharing, you agree that we won't be required to make sure they handle your content in line with the Australian Privacy Principles (Australian Privacy Principle 8.1 won't apply to this sharing), so if one of them mishandles your content we won't be accountable for that under Australia's Privacy Act and you won't be able to seek redress under it. If you're in New Zealand: they may not be required to protect your content in a way that, overall, provides comparable safeguards to those in New Zealand's Privacy Act 2020.
You can review your current permission status and revoke it at any time in Account → Data & privacy. Revoking:
- blocks new Panel Checks and Second Opinions until you allow again,
- does not delete your existing History or results,
- does not cancel your subscription.
The safety check described in "Who receives your content" below is part of what you allow on the permission screen. Because nothing you write is accepted or sent anywhere until you have given permission, the safety check only ever runs on content you submitted after giving it, and on the answers and Panel Verdict produced from it. It can't be switched off on its own, because it is how we stop harmful content from reaching you or being saved. If you withdraw permission, no new question is accepted, so the safety check stops too.
6. Who receives your content
We do not sell your personal information. We share the content described below only as needed to run the service, subject to your provider-sharing permission (§5).
AI providers and the routing intermediary
Every Panel Check or Second Opinion sends content through OpenRouter, a routing service, which passes it to the AI company behind each panelist:
| Company |
Consumer-facing panelist |
What it receives |
| OpenAI |
"ChatGPT" panelist |
Your question, or the AI answer you submitted, and any context, as the OpenAI panelist's own task. For analysis: the question plus the claims extracted across all panelists' answers, each panelist's stance on them, and a short rationale, not the full text of every panelist's answer. |
| Google |
"Gemini" panelist |
Your question/submitted answer/context, as the Gemini panelist's own task. For analysis: every panelist's full answer to your question, because Google's model performs claim extraction and stance classification across the whole panel. |
| Anthropic |
"Claude" panelist |
Your question, or the AI answer you submitted, and any context, as the Claude panelist's own task. |
| xAI (also trading as SpaceXAI) |
"Grok" panelist |
Your question, or the AI answer you submitted, and any context, as the Grok panelist's own task. |
Every request to these companies passes through OpenRouter, which receives the same content before routing it onward and acts as our service provider under its data processing agreement. OpenRouter's published terms say it does not store the text of prompts or responses unless the customer turns on logging, which we have not; it keeps request details such as token counts and timing, and may sample prompts for anonymous topic statistics. We ask OpenRouter to send each request only to the model maker's own service (never a reseller or another cloud, with no fallback) and only to services OpenRouter records as not training on the data. This is a routing setting and the providers' own published terms, not a guarantee we can make. We do not claim zero retention, zero training, or anonymous processing anywhere in this policy.
AI training. We do not use or sell your personal information to train large language models or any other AI model, and The Panel does not train or fine-tune AI models of its own.
A safety identifier, not your identity. Every request we send through OpenRouter also carries a keyed code derived from your account (a one-way cryptographic function of your identity, not your raw account ID) so that misuse can be attributed to one user if it needs to be. This code is pseudonymous: we, and only we, can turn it back into an account, using a secret we hold. We do not call it anonymous, because it isn't. It is never your name, email address, or internal Panel account ID, and it stays the same even if you delete your account and sign up again. OpenRouter's documentation says it does not pass this code on as it is: it turns it into a further one-way identifier that it sends to the AI company, so each AI company can tell one user's requests from another's for abuse monitoring.
OpenAI's safety check. Separately from its role as a Panelist, OpenAI operates an automated safety check that we call directly, not through OpenRouter, on your question before any Panelist sees it, and on each Panelist's answer and the Panel Verdict before we save or show them. This sends the checked text directly to OpenAI. OpenAI's published documentation says content sent to this safety service is not used for training and is not kept in its abuse-monitoring logs; we rely on OpenAI's terms for that and cannot verify it ourselves.
What the AI companies say they keep
| Company |
Uses your content to train its models? (its published terms) |
How long it keeps a copy (its published terms) |
| OpenRouter |
No |
Doesn't store prompts or responses unless logging is on (it is off for us); keeps request details |
| OpenAI (panelist and analysis) |
No |
Up to 30 days in abuse-monitoring logs, longer if the law requires it or to prevent harm |
| OpenAI (safety check) |
No |
Not kept in abuse-monitoring logs, per OpenAI's documentation |
| Google (Google Cloud) |
No |
Depends on Google's abuse-monitoring settings for OpenRouter's account, which we can't see; OpenRouter lists the Google Cloud service we use as not keeping prompts |
| Anthropic |
No |
Deleted within 30 days; up to 2 years if flagged for breaking Anthropic's usage policy |
| xAI (SpaceXAI) |
No |
30 days, for investigating suspected abuse |
These summaries describe each company's published terms as of the "Last updated" date above. The companies can change them, and we cannot verify or enforce them; we do not claim that any company keeps nothing or trains on nothing. Their privacy policies: OpenRouter (https://openrouter.ai/privacy), OpenAI (https://openai.com/policies/privacy-policy), Google Cloud (https://cloud.google.com/terms/cloud-privacy-notice), Anthropic (https://www.anthropic.com/legal/privacy), xAI (https://x.ai/legal/privacy-policy). We review these terms before adding or changing a provider; a change in who receives your content is a change to the permission screen, which asks you again (§5).
Not sent to any AI provider or to OpenRouter, as a matter of how requests are built: your account email, display name, subscription status, or your internal The Panel account ID.
No evidence or web-search provider receives your content. If a feature that checks claims against outside sources is added later, the companies it would send content to will be added to the permission screen first, and you will be asked again before it applies to you.
Other processors
| Who |
What they receive |
Why |
| Cloudflare (network edge) |
Every request between the app and our server passes through Cloudflare, which ends the encrypted connection from your device and opens a new one to our server. In transit it handles the request as a whole: your network address, headers (including your session token), and the request and response bodies (your question, submitted answer and results). We have given it no access to our database. Cloudflare also uses traffic information, such as your network address, for its own network security under its privacy policy. |
Protecting the one server behind it from floods and attacks, and hiding its direct address. |
| Supabase (Supabase Pte. Ltd.; authentication) |
Your Apple user ID for The Panel, session tokens, and the network address and device details of each sign-in. Its sign-in event logs are kept for 7 days. Not received: your name or email (the app never asks Apple for them), your questions, answers, or results. |
Runs sign-in and sessions. |
| Supabase (Supabase Pte. Ltd.; database) |
All data The Panel stores: account records, History, results, permission history, cost/operational metadata. The database is Supabase's Postgres, in Ireland. Supabase keeps daily backups of it available for 7 days, so a record you delete can persist in a backup for up to 7 days afterwards; backups are never read except to recover from a failure. |
Running the service. |
| Fly.io (hosting) |
The Panel's server runs on Fly.io, in London. Everything you submit and every result passes through it, and its log stream keeps our operational logs, which include your IP address, for 7 days (§3, "Logs"). |
Running the service. |
| Sentry (Functional Software, Inc.; crash reporting) |
Only while Share Diagnostics is on: crash, freeze and app-hang reports: stack traces, device model, iOS and app versions. Never your questions, answers, or results, and no name, email address, or account ID. Reports are stored in Sentry's EU data region (Germany) for up to 90 days. Like any server, Sentry sees the network address a report is sent from; we have set it not to store IP addresses. |
Finding and fixing crashes. |
| Apple (Sign in with Apple) |
A token-revocation request at account deletion. |
Required by Apple to revoke sign-in tokens when you delete your account. |
| Apple (App Store) |
Nothing new from The Panel: Apple already holds your purchase relationship; we read Apple-signed transaction and notification data it sends us. |
Verifying purchases and subscription status. Apple, not us, holds your payment details; we never receive your card number. |
We use no separate logging, analytics or monitoring company for the server; operational logs stay in Fly.io's log stream.
Our contracts with these companies. Each company in the tables above that handles your information for us does so under a written data processing agreement with us that limits it to providing its service, requires it to keep your information confidential and to protect it to at least the standard this policy describes, and allows it to pass your information only to sub-processors bound the same way: Cloudflare, Fly.io, Supabase and Sentry under their data processing agreements; OpenRouter under its data processing agreement; and OpenAI's safety check under OpenAI's data processing addendum. We have no direct contract with the AI companies that answer through OpenRouter (OpenAI, Google, Anthropic and xAI): OpenRouter contracts with them, and each company's own API terms, summarised in "What the AI companies say they keep" above, govern any copy it keeps. We route only to the services those terms cover (each company's own API, not a reseller), and those terms do not allow the company to train on your content and limit how long it keeps a copy. Apple handles sign-in and App Store purchases as an independent company under its own privacy policy.
7. Retention
- History off: a run's content (your question/submitted answer, context, Original Responses, claims, stances, dissent, verdict) is removed from The Panel within about a day (24 hours after the run finishes; a background job runs every 15 minutes, so removal typically completes within about 24 hours 15 minutes at the outside). Content-free records (status, timestamps, allowance/cost metadata) are kept, except the words of a question that counts against your account under our Usage Policy, which we keep for as long as described in "Records related to safety and misuse enforcement" below.
- History on, no auto-delete period set: saved runs are kept until you delete them or delete your account.
- History on, with an auto-delete period set (30, 90 or 365 days): a saved run's content is removed once it is older than that period, counted from when the run was created or from when you chose the period, whichever is later. Choosing a period never deletes anything at once.
- Delete now: you can delete an individual finished run's content immediately from its result screen, along with the labels we record about why a run was declined; the Panel Check itself is not refunded, because the work was already performed. It does not remove the strike record's copy of a question, described in the table below.
- Database backups are kept for 7 days by our database provider (§6), independent of the above, so deleted content can persist in a backup for up to 7 days.
- This does not describe or control how long an AI provider itself retains a copy once it has received content under §6. That is governed by the provider's own terms, summarised in §6 ("What the AI companies say they keep").
- Account deletion removes account data as described in §9 below.
- Operational and security logs, none of which contain prompt or response text, are kept by Fly.io for 7 days (§3). Per-run cost records (what each Panel Check cost us, with no content) are kept with the run's record and deleted with your account. Anonymous daily totals (how many Panel Checks were started across all users on a day, and what they cost) are kept indefinitely and are never linked to an account, a run, or a fingerprint.
Records we keep because the law requires it
| Record |
Contains your words? |
Kept for |
Survives account deletion |
| Panel Check request record (your internal account number, the network address the request came from, and when), required by Philippine law (Republic Act No. 11930) |
No |
6 months from each request |
Yes, until those 6 months end |
| A report made to the US National Center for Missing & Exploited Children, and what it contained |
Possibly (only material we already held, or that someone sent us) |
1 year after the report, as US law requires |
Yes |
Preservation orders. If an authority orders us to preserve specific information, we keep it for the period the order requires (under Philippine law, up to one year, which can be extended), even if you delete it or your account.
Records related to safety and misuse enforcement
Enforcing our Usage Policy (strikes, child-safety stops, and account closures) creates some additional records, described below. We built this to keep as little as possible, and to keep it content-free wherever we can.
| Record |
Contains your words? |
Kept for |
Survives account deletion |
| Strike record (that a strike was recorded, and why) |
No |
90 days |
Yes, keyed to a fingerprint, not your account |
| The full question you wrote when it earned a strike, kept as submitted (not an excerpt) |
Yes |
90 days, the same as the strike record. Delete now, turning History off and auto-delete do not remove it earlier |
No, deleted when you delete your account |
| Severe child-safety event record |
No |
12 months |
Yes |
| Answer-side child-safety stop record |
No |
30 days |
No, deleted with your account |
| Closure record (a keyed fingerprint and keyed purchase-ID hashes, so a closed account can't simply re-sign up) |
No |
3 years, or 6 years after a child-safety closure |
Yes |
| Enforcement decision log (that a decision was made, and its category) |
No |
6 years |
Yes |
| The self-harm signal used to show you support resources (a yes/no on the run it came from, so a reopened run still shows support), and the recorded reason a run was declined |
No |
Cleared with that run's content: when History is off, at your auto-delete period, on Delete now, or when you delete your account |
No |
| Refund record (a keyed hash of the ID of a refunded top-up pack, or of a refunded subscription that no account held, so it can't be claimed afterwards; no account link) |
No |
400 days |
Yes |
| Subscription usage record (a keyed hash of your App Store subscription's ID, how many of this month's Pro Panel Checks you had used, and your reset date; no account link) |
No |
Until that monthly allowance period ends (at most about a month) |
Yes |
We do not keep the text of a question or answer that our safety check stopped, beyond what these tables describe. If you appeal a decision or report an answer by emailing support@appsbynikki.com, we keep that correspondence only as long as needed to handle it.
Reporting to authorities
We don't scan or read stopped content looking for crimes, and we don't keep the text of stopped questions or answers. Where the law requires a report:
- Philippines. The Panel is operated from the Philippines, whose law against online sexual abuse and exploitation of children (Republic Act No. 11930) applies to online services that carry content created by others. If you or an authority tells us an answer or Panel Verdict contains sexual content involving a minor, we remove it at once, and in any case within 24 hours, and report the removal to the Philippine Department of Justice within 3 days. If our safety check is highly confident that someone's own words sought sexual content involving a minor, a person reviews the flag; if it stands, we report it to the Philippine Department of Justice within 3 days. These reports give the date and time, what kind of content was blocked, and the request record described above. They never contain question or answer text, because we don't keep it.
- United States. If we obtain actual knowledge of facts or circumstances indicating apparent child sexual exploitation that US law (18 U.S.C. §2258A) requires providers to report (for example, from material someone sends us in an appeal or a report), we report it to the CyberTipline of the National Center for Missing & Exploited Children (NCMEC). A report contains only what we hold at that point, such as the account's reference, the keyed code described in §6, dates and times, the network address in our records if it is still there, and any material sent to us. US law requires us to preserve what we report for one year after we report it; we keep it for that year, securely and for no other purpose, even if the account is deleted.
- Other countries. We may also report to the authorities in other countries where their law requires it, for example Canada's Cybertip.ca (run by the Canadian Centre for Child Protection) or the RCMP's National Child Exploitation Crime Centre, or Australia's eSafety Commissioner or Federal Police. If anyone gives us the address of a place online where child sexual abuse material is available, we report that address to the authorities.
We do not tell you when a report is made.
Requests from authorities
We disclose your information to a government authority only when the law requires it, for example under a subpoena, warrant or court order. We tell you about such a request unless the law or the authority forbids it, or telling you could harm an investigation into the sexual abuse or exploitation of a child; in those cases we may delay telling you, or not tell you.
8. On your device
The Panel does not keep a cache of your results on your device: results and History are fetched from our servers each time you open them. What the app does keep on your device:
- Your sign-in session, in the iOS Keychain, marked so that it stays on the device it was created on (it is not carried into a backup restored onto another device, so a new phone means signing in again). It is removed when you sign out.
- Small display preferences (for example, light or dark appearance). No content.
- Your crash-report choice: a copy of your Share Diagnostics setting, so it applies from the moment the app opens (cleared when you sign out), and whether the app has already asked you about it. If the app crashes while Share Diagnostics is on, the report waits in the app's storage until it is sent, the next time the app opens with the setting on.
- A file of your data, only if you export it. When you use Export My Data, the file (a zip holding a readable page and a data file) is written to the app's temporary storage, protected by your device's encryption, and replaced if you export again. It is deleted when you sign out or delete your account. Until then it holds the exported data in that file, and iOS may also clear temporary storage on its own. If you share or save the file elsewhere, that copy is yours and we cannot remove it.
None of this leaves your device on its own; it does not change what this policy says about what we receive or store.
9. Account deletion: what is removed and what survives
You can delete your account and most of your Panel-stored data at any time from Account → Data & privacy, except the limited records described below and in §7 that we keep for safety, security, or legal reasons, for set periods. Deletion requires you to re-authenticate with Sign in with Apple immediately beforehand, so that a stolen session token alone cannot delete your account.
Deleting your account, in one operation:
- deletes your History and results, Original Responses, analysis, run events, settings, permission history, allowance records, App Store purchase links, and internal cost records tied to your account;
- is refused while a Panel Check is actively running for your account (try again once it finishes);
- asks Apple to revoke your Sign in with Apple tokens (one attempt; if Apple can't be reached, the tokens expire on their own) and deletes your Supabase identity record, retrying until that succeeds;
- does not automatically cancel an Apple subscription: cancel separately in App Store subscription settings if you don't want it to renew;
- does not reach copies an AI provider or OpenRouter already holds under its own retention terms (§6): we cannot delete data held by a company we don't control.
What survives deletion, and why, none of it your account content and none of it usable to reconstruct your activity:
- a keyed fingerprint of your sign-in identity (a one-way cryptographic hash, not your raw Apple ID), recording how much of the one-time free trial you used: this exists solely so that deleting and re-creating an account cannot be used to reset the free trial; it is kept, with no link to any account, for as long as The Panel operates, because the trial is a once-per-person offer with no expiry;
- a keyed fingerprint marking your deleted sign-in identity, so a session token issued before deletion cannot be used to recreate the account; kept on the same basis;
- while a pending deletion with Supabase is still being confirmed, your raw Supabase identifier is held temporarily until Supabase confirms deletion, normally within minutes; if Supabase is unreachable the deletion is retried, at least daily, until it succeeds, and the identifier is removed as soon as it does;
- the enforcement records in §7 that survive deletion also keep an internal account number that no longer points to any account (it lets a record re-attach to you if you sign up again with the same Apple ID, as the Usage Policy describes), never your Apple ID, email, or content;
- the Panel Check request record that Philippine law requires us to keep for 6 months (§7), and anything an authority has ordered us to preserve, for the period of that order;
- anonymous, day-level aggregate statistics (for example, total Panel Checks started across all users on a given day, or total AI provider spend that day) that are never linked to your account, a specific run, or any fingerprint, and cannot be traced back to you;
- one anonymous spending figure: the AI spend of your account over its last 24 hours, and whether it had ever paid, with no account, run or fingerprint attached, kept for 48 hours so that deleting an account cannot reset our daily spending limits;
- a subscription usage record: if you had an active Pro subscription, a keyed hash of its App Store purchase ID with how many of the current month's Pro Panel Checks you had used and your reset date (no account link), kept until that monthly allowance period ends, so restoring the same subscription on a new account that month continues from where you were rather than starting a fresh allowance;
- refund records: if Apple refunds a top-up pack, or a subscription that no account holds any more (for example after you deleted your account), a keyed hash of that purchase's ID (no account link) is kept for 400 days, so the refunded purchase can't be claimed again;
- the other records described in §7 that survive deletion, where they apply to you.
Beyond the keyed hashes listed above, we keep no per-user financial history after deletion. Apple and OpenRouter's own invoices remain the source of truth for purchase and cost records independent of what The Panel stores.
10. Security
We use technical and organizational measures appropriate to the sensitivity of the data involved, including: server-side-only storage of provider and infrastructure credentials with least-privilege access; encrypted network transport (HTTPS/TLS); device-level file protection for the exported data file (§8) and a Keychain-held session that stays on the device; server-side authorization checks on every user-owned resource; rate limiting and spend controls to reduce abuse; and security event logging that never contains prompt or response content. Inside The Panel, only the operator and the one developer who maintains The Panel for her can access personal information, and only to run, secure and support the service.
No system is perfectly secure, and we do not claim end-to-end encryption, a specific security certification, "military-grade" encryption, or a zero-knowledge architecture, because our current architecture does not implement those things. If that changes, we will update this policy to match, not before.
If something goes wrong. We keep a record of every breach of our safeguards. If a breach affecting your personal information is likely to cause serious harm, we assess it promptly and notify the regulator where the law requires it (for example Singapore's Personal Data Protection Commission within 3 calendar days of deciding a breach must be notified, the Office of the Privacy Commissioner of Canada (and, for people in Québec, the Commission d'accès à l'information), Australia's OAIC, New Zealand's Privacy Commissioner, or a US state attorney general) and tell the people affected so they can protect themselves. Because we don't have your email address, we tell you in the app and on our website.
11. International data transfers
The Panel is run from the Philippines, and the companies that process your information for us are in other countries. Using The Panel transfers your information to, and processes it in:
- the United States: OpenRouter, and the AI companies behind the panelists (OpenAI, Google, Anthropic, xAI), including OpenAI's safety check, and other countries where those companies run their systems;
- the United Kingdom: our server (Fly.io, London);
- Ireland: our database and sign-in service (Supabase);
- Germany: crash reports, only if you turn on Share Diagnostics (Sentry);
- the Philippines: where The Panel is operated from;
- Cloudflare's network, which handles each request at one of its data centres, usually one near you, before passing it to our server.
The laws of these countries may differ from yours, and courts, law-enforcement and national-security authorities there may be able to require access to information under their own laws. If you are in Canada, this means your information is processed outside Canada, and if you are in Québec, outside Québec. We stay responsible for your information when these companies process it for us, and we protect each transfer by contract:
| Company |
Contract we rely on |
Transfer terms in it |
| OpenRouter |
OpenRouter's Terms of Service and Data Processing Agreement |
EU Standard Contractual Clauses (controller-to-processor) and UK Addendum |
| OpenAI (safety check) |
OpenAI Services Agreement and Data Processing Addendum |
EU Standard Contractual Clauses and UK Addendum |
| OpenAI, Google, Anthropic, xAI (panelists, through OpenRouter) |
OpenRouter's own agreements with each company; we have no direct contract |
As agreed between OpenRouter and each company |
| Supabase |
Supabase Terms of Service and Data Processing Addendum |
EU Standard Contractual Clauses and UK Addendum |
| Fly.io |
Fly.io Data Processing Agreement |
Fly.io is certified under the EU-U.S. Data Privacy Framework and its UK Extension |
| Cloudflare |
Cloudflare Self-Serve Subscription Agreement and Data Processing Addendum |
EU Standard Contractual Clauses, UK Addendum, Data Privacy Framework; certified under the Global CBPR and PRP systems |
| Sentry |
Sentry Data Processing Addendum |
EU Standard Contractual Clauses, UK Addendum, Data Privacy Framework |
| Apple |
None (independent company) |
Apple's own privacy policy |
For Singapore, see "Singapore" in §12.
12. Your rights
The rights available to you depend on where you live; the sections below set them out by country. You can always exercise them by emailing support@appsbynikki.com. Because you sign in only with Apple, we may ask you to make or confirm a request from inside the app, so we know it is your account; we never ask you to create a new account to use these rights. Requests are free, and we won't treat you differently for making one.
Automated decisions. We use computer programs, working on information about your account and what you submit, to make or help make some decisions about you.
- Made by a program alone: whether a question goes to the Panelists or is stopped by our safety check; whether a Panelist's answer or the Panel Verdict is withheld; whether a question counts against your account as a strike or a child-safety record (Usage Policy sections 5 and 6); pausing new Panel Checks for up to a day under the fair-use or child-safety limits (Terms of Use §9, Usage Policy section 6); and whether a run uses a Panel Check (Terms of Use §8).
- Flagged by a program, decided by a person: closing an account (Usage Policy section 7).
The information these programs use is: the text of your question, context and any submitted answer; the Panelists' answers and the Panel Verdict; our safety check's results; your account's strike and child-safety records; and your recent usage and what it cost. When a question counts against your account, the app tells you whether the decision was automatic. If you ask, we'll tell you what personal information was used, the reasons and the main factors that led to the decision, and that you can have that information corrected. You can ask a person to review any of these decisions, give your point of view and contest it by appealing as our Usage Policy describes (email support@appsbynikki.com with the reference code); a person who can change the decision reviews every appeal.
United States
The rights in this section apply to everyone in the United States, whichever state you live in. Some state laws, such as Connecticut's Data Privacy Act, require them; we give them to all US users.
What we collect and why. §3 lists what we collect, §4 why, and §6 who receives it. In the categories US privacy laws use: identifiers (your Apple user ID for The Panel, our internal account ID, the keyed code described in §6, and your network (IP) address); commercial information (your plan, allowance, and App Store purchase and subscription status); internet or electronic activity (our server logs, the request record in §7, and crash reports only if you turn on Share Diagnostics); and the content you submit and the results generated from it. We do not collect your name, email address, date of birth, precise location or biometric data.
Sensitive information. We don't ask for it, but a question may reveal sensitive information if you choose to include it, for example a health condition, religious beliefs, sexual orientation, immigration status, or that you were a victim of a crime. We process it only to give you the result you asked for, to keep it in your History under your settings, to run the safety check, and to enforce our Usage Policy. We do this with the consent you give on the AI provider sharing permission screen before any question is sent (§5). You can withdraw that consent at any time in Account → Data & privacy; from then on, no new question is accepted or sent. We never sell it, use it for advertising, or use it to train AI models. If you live in Washington, Nevada or Connecticut, also see our Consumer Health Data Privacy Policy (https://www.appsbynikki.com/the-panel/health-data).
No selling, no targeted advertising, no AI training by us. We do not sell your personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects. We do not use or sell your personal information to train large language models or other AI models.
Your rights. You can:
- confirm whether we process your personal information and get a copy of it: Export My Data (Account → Data & privacy) does this straight away;
- correct inaccurate information: most of what we hold is text you wrote, so you can delete a run and ask again, or email us;
- delete it: delete a run from its result screen, or your whole account in Account → Data & privacy (§9 explains the few records that remain, and why);
- get it in a portable, machine-readable format: the export includes a JSON file;
- withdraw a consent you gave (provider-sharing permission, §5; Share Diagnostics, §3).
We answer within 45 days. If we need up to 45 more days, we will tell you why within the first 45.
Appeals. If we turn down a request, we'll tell you why. You can appeal by emailing support@appsbynikki.com with "Appeal" in the subject line. A person will decide within 60 days and tell you the outcome and the reasons in writing. If we still turn it down, you can complain to your state attorney general: for example, in Connecticut, https://portal.ct.gov/ag; in Washington, https://www.atg.wa.gov/file-complaint.
Do Not Track and Global Privacy Control. We don't track you across other companies' apps or websites, and we don't let other companies do so through The Panel. A "Do Not Track" or Global Privacy Control signal therefore has nothing to switch off, and we don't change anything in response to one.
Canada
Canada's federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), applies to how we handle the personal information of people in Canada. If you live in Québec, Québec's Act respecting the protection of personal information in the private sector also applies: see "Québec" below for what it adds.
Privacy Officer. Our Privacy Officer (and, for Québec, the person in charge of the protection of personal information) is the operator of The Panel, support@appsbynikki.com.
Your rights. You can ask us whether we hold personal information about you, for access to it and a copy, and to correct it if it is wrong or incomplete. Export My Data (Account → Data & privacy) gives you a copy at any time, as a readable page and a machine-readable file. You can also withdraw your consent (for example, by revoking provider-sharing permission or turning off Share Diagnostics), subject to legal and contractual limits; we'll tell you what withdrawing means for the service before we act on it. We reply in writing within 30 days, and access is free.
Your information is processed outside Canada. We don't store your information in Canada. It is handled in the countries listed in §11. While it is in another country, it is subject to that country's laws and may be accessed by its courts, law-enforcement and national-security authorities.
Privacy breaches. If a breach of our safeguards creates a real risk of significant harm to you (in Québec, a risk of serious injury), we will report it to the Office of the Privacy Commissioner of Canada (and, for people in Québec, to the Commission d'accès à l'information) and tell you as §10 describes. We keep a record of every breach.
Complaints. Please contact us first. We'll look into it and reply in writing within 30 days with what we found and what we did. If you're not satisfied, you can complain to the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) or, in Québec, the Commission d'accès à l'information du Québec (https://www.cai.gouv.qc.ca).
Québec: what Québec law adds
- Who can see your information. Inside The Panel, only the operator and the one developer who maintains The Panel for her can access personal information, and only to run, secure and support the service. Everyone else who receives it is a company listed in §6.
- Outside Québec. All of your information is communicated outside Québec (§11). Before doing so we assessed the privacy risks for each company in §6, and we rely on written agreements with them.
- Sensitive information. Health information you include in a question is sensitive. We send it to AI providers and our safety check only after you give express permission on the provider-sharing screen (§5). You can always leave it out.
- Default settings. Share Diagnostics is off until you turn it on, and AI providers receive nothing until you allow provider sharing. Save Run History is on because keeping your own results in your own History is the service itself; nothing in it is shared with anyone, and you can turn it off at any time.
- How we assess your use. Our safety check assesses what you submit for categories of harm, and our strike rules keep track of flagged questions on your account; a keyed code derived from your account goes with each AI request so misuse can be traced to one account. These are part of keeping The Panel safe and can't be switched off. We use them for nothing else (no advertising, no recommendations), and The Panel never uses your location.
- Decisions made automatically. See "Automated decisions" at the start of this section.
- Keeping and destroying information. We keep information only as long as §7 and §9 describe, then destroy it or make it anonymous.
- Complaints. Send privacy complaints to support@appsbynikki.com. The person in charge of the protection of personal information reviews each one and replies in writing within 30 days. You can also complain to the Commission d'accès à l'information du Québec.
Australia
We handle personal information about people in Australia in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988.
- Access and correction. Export My Data (§15) gives you a copy of what we store about your account. To ask for anything else, or to correct something, email support@appsbynikki.com. We'll respond within 30 days and won't charge you.
- Not identifying yourself. We know you only by the Apple user ID for The Panel. We never ask for your name or email address.
- Health and other sensitive information. We don't ask for it. If you include health information in a question, a submitted answer or context, you consent, on the provider-sharing permission screen, to us collecting it to produce your result and run our safety check, and to sending it to the AI providers named in §6. You can delete a run's content at any time (§7).
- Sending your information overseas. Most of the companies that handle your information for us are outside Australia; §11 lists them by country. See §5 for what you agree to when you allow provider sharing.
- Complaints. If you think we've breached the APPs, email support@appsbynikki.com and tell us what happened. A person will look into it and reply within 30 days with what we found and what we'll do about it. If you're not satisfied, or you haven't heard back within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC): https://www.oaic.gov.au.
New Zealand
New Zealand's Privacy Act 2020 applies to how we handle personal information about people in New Zealand.
- Privacy officer: the operator of The Panel, support@appsbynikki.com.
- Access and correction. Export My Data (§15) gives you a copy of what we store about your account. To ask for anything else, or to correct something, email us. We'll respond as soon as we reasonably can, and within 20 working days.
- Sending your information overseas. The companies that handle your information are overseas (§6, §11). Our hosting, database, network and crash-reporting companies hold it only on our behalf. The AI providers and OpenRouter also handle it under their own terms; see §5 for what you agree to when you allow provider sharing.
- Information about other people. If you mention someone else in a question, we use it only to answer your question, and it is deleted with that run (§7). We don't contact them.
- Privacy breaches. If a privacy breach is likely to cause anyone serious harm, we'll tell the Privacy Commissioner and the people affected as soon as practicable.
- Complaints. Please raise it with us first. If you're not satisfied, you can complain to the Office of the Privacy Commissioner: https://www.privacy.org.nz.
Singapore
If Singapore's Personal Data Protection Act 2012 (PDPA) applies to you, you have the right to ask for access to your personal data and for information about how it has been used or disclosed in the past year, to ask us to correct an error or omission in it, and to withdraw your consent to our collecting, using, or disclosing it: for example, by turning off Share Diagnostics or revoking provider-sharing permission (§5). Withdrawing consent may mean we can no longer provide some or all of the service, and we will tell you what it means for you before acting on it. We respond as soon as we reasonably can; if we need more than 30 days, we will tell you within those 30 days when we will respond. If you have a complaint about how we handle your data, email our Data Protection Officer and we will reply in writing. If you are not satisfied with our response, you can complain to the Personal Data Protection Commission (PDPC), https://www.pdpc.gov.sg.
Transfers out of Singapore. Using The Panel transfers your personal data out of Singapore, to the countries listed in §11. These transfers are necessary to provide the service you signed up for: we cannot answer your question without sending it to the AI providers, or keep your account without our hosting and database providers. Singapore's Personal Data Protection Regulations 2021 permit transfers on that basis. The companies that process your data for us are also bound by the contracts listed in §11 to protect it and use it only to provide The Panel; Sentry's agreement keeps crash reports in its EU region.
Legitimate interests. We rely on the legitimate interests exception in Singapore's PDPA, after assessing that our interests outweigh any adverse effect on you, to run the safety check, enforce our Usage Policy, prevent free-trial abuse and keep our operational and security logs. Ask our Data Protection Officer if you would like more information about these assessments.
Data Protection Officer: support@appsbynikki.com.
Philippines
The Panel is operated from the Philippines but is not offered there. The Philippine Data Privacy Act of 2012 does not apply to personal information collected from residents of other countries in accordance with their own laws (section 4), which is all the personal information The Panel holds; your rights are the ones described for your country above. Philippine law does still govern how we handle child-safety reports (§7).
United Kingdom
The Panel isn't offered in the UK. If UK GDPR nonetheless applies to you, you have the right to: access your personal information; rectify inaccurate information; erase it (see §9 for how account deletion works in practice); restrict or object to certain processing; data portability (see Export My Data, below); not to be subject to a decision based solely on automated processing without the safeguards described under "Automated decisions" above; and to withdraw consent at any time where processing relies on consent (for example, Share Diagnostics, or provider-sharing permission: see §5). You also have the right to complain to the UK Information Commissioner's Office (ICO), https://ico.org.uk. We have not appointed a UK GDPR Article 27 representative, because we do not offer The Panel in the UK; we will appoint one before we do.
European Economic Area
The Panel isn't offered in the EEA. If EU GDPR nonetheless applies to you, you have the same rights described in the UK section above and the right to complain to your local supervisory authority. We have not appointed an EU GDPR Article 27 representative, because we do not offer The Panel in the EU; we will appoint one before we do.
13. No selling, no ad tracking
We do not sell your personal information. We do not share it with third parties for their own advertising or marketing purposes. The Panel has no advertising network, ad SDK, or ad-tracking technology of any kind. The only sharing that occurs is the provider-sharing described in §5–6, which exists to run the product feature you asked for, and the processors in §6 needed to operate the service.
14. Children
The Panel is not directed to children and our minimum age is 18 (see §2). We do not knowingly collect personal information from anyone below that age. If you believe someone under 18 is using The Panel, email support@appsbynikki.com and we will close the account and delete its information, except what the law requires us to keep.
15. Data export
You can request a copy of the data we store about your account from Account → Data & privacy, once a day. It includes:
- your account details (account ID and when the account was created);
- your plan, your Panel Check allowance periods, and any extra credits you bought, with how many are left and whether a purchase was refunded;
- your privacy settings, and your provider-sharing permission with its history of grants and withdrawals;
- your newest 1,000 Panel Checks whose content we still store, saved to History or not (email us if you need older ones): your question or submitted answer, the Original Responses, claims, Panelist Positions, dissent, the Panel Verdict, and the labels we keep with a run (for example, whether it was declined and why, or that crisis support was shown);
- any restrictions on your account under our Usage Policy, and the records behind them: strikes, safety events, and an account closure, with the full question you wrote for a strike while we still keep it (see "Records related to safety and misuse enforcement" above).
It is built on request; the only things we store as a result are the time of your last export (to apply the once-a-day limit) and a content-free log line. The app gives it to you as a single file you can save or share: a readable page to open first, with the complete data beside it in a machine-readable (JSON) file. It does not include records an AI provider or Apple holds independently of what we store, Panel Checks whose content has already been deleted, or our own operating and security records, such as per-request cost records, the request record in §7, keyed fingerprints and security logs, which this policy describes above. You can ask for those by email.
16. AI outputs may be wrong
The Panel Verdict, Model Consensus, and every other analysis output are generated by AI systems and can be inaccurate, incomplete, or misleading. Model Consensus describes agreement between AI systems, not a measure of factual accuracy. Strong agreement among AI panelists is not proof that an answer is correct, and a Minority View is not automatically wrong. Do not use The Panel as a substitute for professional medical, legal, financial, or other regulated advice. See the Terms of Use for the full disclaimer.
17. Changes to this policy
If we change what data we collect, who we share it with, or why, we will update this policy, change its version identifier and the "Last updated" date at the top, and tell you in the app before a material change takes effect. Changes to what is sent to AI providers also change the in-app permission screen, which asks for your permission again before the next Panel Check (§5). We will ask for your consent before collecting new kinds of sensitive information or using it for a new purpose.
18. Contact
Questions about this policy, or to exercise any right described above: support@appsbynikki.com.
Data Protection Officer (Singapore); Privacy Officer (Canada, New Zealand); person in charge of the protection of personal information (Québec): the operator of The Panel, support@appsbynikki.com.
To appeal a decision, or report an answer, under our Usage Policy: support@appsbynikki.com. Every finished result also has Report a response in its menu, which starts that email with the run's reference and the app version filled in, and a line asking what was wrong, none of what you wrote.