Privacy policy

Your curiosity belongs to you.

Last updated: September 13, 2026

You can read stories and reveal explanations without an account. A free account saves your activity and lets you participate. We will never sell your personal data or harvest it for resale.

What this policy covers

This policy explains how Panori handles information about visitors and account holders. It also covers questions, source suggestions and feedback sent to us. Linked publishers have their own privacy policies.

What we collect and why

  • Account details: your email, name, optional profile picture and account settings. We use these to manage your account, contact you about it and show your preferences.
  • Sign-in information: password hashes, sign-in tokens, confirmation records and any passkeys or two-factor authentication details you set up. We use these to check who is signing in and protect your account. Panori does not receive your device's fingerprint or face scan when you use a passkey.
  • Saved reader activity: answers, revealed explanations, reading progress, story visits, followed stories and saved questions. These let you return to your activity and see what changed since your last visit.
  • Optional participation: reactions, forecasts, questions and source suggestions, including their dates and review status. We use these to show your responses, produce community summaries and help editors review contributions.
  • Messages and preferences: feedback, notification settings and records of notifications sent or read. These help us respond to problems and respect your communication choices.
  • Technical and security information: sign-in IP addresses and times, requests, errors and account activity logs. These help us run the site, investigate faults and prevent misuse. Browsing without an account still sends technical information to the server.

Your answers and reactions may reveal personal opinions, including political views. Participation is optional. Avoid putting sensitive personal details or other people's private information in questions, feedback or source suggestions.

What other readers can see

Your individual answer history, saved reading activity and email address are not shown to other readers. Community response summaries appear only after at least five readers have responded. They show combined results without account identities and describe participating readers, not the public as a whole. A minimum group size does not eliminate every possibility of someone inferring a response.

Questions and source suggestions go to an editorial review queue. They do not publish automatically. Editors may use a submitted question or source to develop coverage. Do not include information you would not want considered for that purpose.

Cookies and browser storage

Panori uses cookies to keep sessions working, protect sign-in and remember your language. If you select “Remember me”, its sign-in cookie lasts up to 60 days; signing out removes it. The language cookie lasts up to one year. Your browser may keep a session cookie when restoring a previous session.

Display preferences, such as light or dark mode, may be saved in your browser until you clear them. Temporary story selections also help the current visit work. These are separate from the reading activity saved to a signed-in account.

The reader app does not include advertising trackers. When enabled, browser diagnostics use an identifier held only in page memory, without analytics cookies or persistent browser storage. Browser diagnostics respect Do Not Track and Global Privacy Control. You can clear cookies and site storage in your browser. Blocking essential cookies may prevent sign-in or other features from working.

Providers and editorial AI

Panori uses outside services to help operate the platform. Providers receive the information needed for their part of the service:

  • Hosting: hosting and backup providers process stored account data and technical information to keep the service running and support recovery.
  • Email: email providers process your email address and message content to deliver account messages and news updates. When Resend is used for contact management, it receives your email, name and subscription preference, including an unsubscribed status.
  • Product analytics and error monitoring: when configured, PostHog receives server-side counts of account registration, onboarding, feedback submission, story opens and follows, explanation reveals, answer submission and editorial contribution submission. Usage events include a pseudonymous account ID or an anonymous identifier lasting for the current reader connection and, where relevant, story, edition or exercise IDs. They exclude names, emails, answer choices and outcomes, reactions, message text and sign-in credentials. Error events include the error type, module, function and line number; error messages, request details and source content are removed. When browser diagnostics are enabled, PostHog also receives scrubbed JavaScript error types and stack locations, page visits recorded as route templates, navigation timing, loading, interaction and layout-shift measurements, browser and operating-system categories, and screen dimensions. Random session, window and page-view identifiers group events within the current page lifetime; full reloads and new tabs start new identities. Route templates replace story slugs, account identifiers and sign-in tokens with placeholders. Page addresses contain the site origin and route template. These events exclude page text, original page addresses, query strings, referring addresses and form values. Browser diagnostic identities are separate from account IDs. All events include the application environment and release label. PostHog receives connection information needed to accept browser requests; geographic enrichment is disabled. When operational logging is enabled, PostHog also receives fixed diagnostic summaries with route templates, status codes, timing, background job worker names and outcomes, and code locations. Web operation events also count requests and page interactions using route templates, fixed action categories, response status and timing. When tracing is enabled, diagnostic records include request, page-operation and database timing linked by random trace identifiers. These records exclude raw messages, request content, database queries, job arguments and account identifiers. PostHog data is processed in its US region. This integration does not record browser sessions or create person profiles. Provider-held event data requires separate deletion or expiry.
  • News discovery: NewsAPI.ai supplies reporting and source information for editorial research. The ingestion process sends news search requests, not reader answer histories.
  • AI drafting: OpenAI receives selected source material and editorial instructions to help prepare drafts. The current drafting workflow does not attach reader account profiles or answer histories. Material supplied by editors can contain names, quotations or other information about people in a story. Human review is required before publication.

External sources and images can cause your browser to contact their hosts, which receive normal connection information such as your IP address.

Service providers may process information outside your country, where different laws and lawful government-access rules may apply. Panori remains responsible for its choices about providers and the information shared with them.

We may disclose information when required by law or when lawfully necessary to investigate abuse or protect people's rights and safety. We limit disclosure to what the situation requires.

Email choices

You can choose whether to receive Panori news and updates in notification settings and unsubscribe from those emails. These choices are separate from messages needed to confirm an account, sign in or notify you of a password change. Changelog notifications have their own settings.

How long we keep information

Account details and saved activity are kept while your account remains active, unless you remove them through an available control or request deletion. There is currently no automatic expiry for inactive accounts or saved reader activity.

Deleting an account schedules removal of its saved reader activity, contributions, notifications, sign-in tokens and passkeys, and removes the name, email and profile-picture reference from the account. The process is not instantaneous. Some account metadata and the password hash remain in a disabled account record.

Feedback text and some operational records can remain after their account links are removed. Text you entered may still identify you. Published story editions and source records are kept as an editorial history; deleting your account does not automatically remove information already incorporated into published coverage. Specific privacy concerns about retained text need individual review.

Deleting your account does not immediately erase every copy held in logs, backups, image storage or provider systems. Those copies require separate deletion or expiry.

Your choices and requests

You can update your profile and email, manage notifications, export account data and request account deletion in account settings. You can continue browsing public stories without an account after deletion.

For information not available through those controls, you may request access, a correction or deletion, ask how information was used, or raise a privacy concern. We may need to verify your identity. Some requests may be limited by applicable law or the rights of others; we will explain the reason and available next steps. You can also contact the privacy regulator responsible for your location.

Email [email protected] for privacy questions and requests. You can also use Feedback while signed in.

Age and account eligibility

Accounts are for people aged 18 or older. Public stories and explanations can be read without an account. Panori is not intended to collect account information from children. If an underage account is identified, we will review it and arrange its removal.

Security and policy changes

We restrict access to administrative tools, use account authentication and store password hashes rather than readable passwords. No online service can guarantee complete security.

We will date policy revisions and bring significant changes to readers' attention. If a new use of personal information requires consent, we will ask before making that use.

See also our Terms of service.