Legal
Privacy policy
What Pemberley collects, why, and the control you keep over it.
Last updated: June 29, 2026
Pemberley (“Pemberley,” “we,” “us”) is positioning intelligence for people who trade on what they know: we read your writing and your field to keep you current, show you where your perspective sits in it, and help you promote your own work. This policy explains what personal data we collect, how we use it, who we share it with, and the rights you have. It applies to trypemberley.com and the Pemberley app.
Information we collect
We collect only what the service needs to work:
- Account & identity. Your email address, and (if you sign in with GitHub) your GitHub account identifier, name, and avatar. We authenticate with magic links (email) or GitHub; we never see or store a password.
- Your interests & reading. The interest tags, notes, and prose you provide; the blog URL you connect and the publicly available content we read from it; and your reading and feedback activity within Pemberley. Your preferences are kept as a Taste Profile you can view, edit, and delete.
- Connected social accounts (optional). If you connect X, Threads, LinkedIn, or Bluesky to schedule posts, we store the account handle and an access token. Tokens are encrypted at rest and used only as described in “Posting to your social accounts” below.
- Payment information. Subscriptions are handled by Stripe. We receive your subscription status and a Stripe customer identifier; we do not receive or store your full card number. Stripe does.
- Technical & usage data. Standard log and device data (IP address, browser type), and product-analytics and error events we use to keep the service working and improve it.
How we use your information
- To provide the service: curate your digest, build your Taste Profile, and power the writer tools.
- To generate and schedule promotional posts you create about your own work.
- To process your subscription and send transactional email (sign-in links, receipts, your weekly issue).
- To secure the service, prevent abuse, debug, and understand and improve how Pemberley is used.
We process your data to perform our contract with you, on the basis of your consent (which you can withdraw), and for our legitimate interest in running and improving the service. We do not sell your personal data, and we do not use the content of your work to train third-party models beyond what is necessary to provide these features.
Posting to your social accounts
This section governs the optional social connections. When you connect an account:
- We request only the permission needed to publish posts on your behalf.
- We publish only the specific posts you create and schedule, and only when you have approved them. We never post automatically without your action.
- We never read your timeline, followers, direct messages, or other private data, and we never post to anyone’s account but your own.
- One narrow exception, in your favor: where a platform allows it, we read the public metrics on posts you published through Pemberley (views, likes, replies) so you can see how they did. Only those posts, nothing else on your account, and never anyone else’s content.
- Your access token is encrypted at rest and is never shared with third parties or shown back to you.
- You can disconnect an account at any time from your settings; doing so deletes the stored token. You can also revoke access directly from the platform.
Service providers we share data with
We rely on a small set of vetted processors to operate Pemberley. They handle data only on our instructions:
- Cloudflare: hosting, storage, and our AI gateway.
- Stripe: payment processing.
- Cloudflare Email Service: transactional and digest email delivery.
- Google (Gemini) and Jina: language-model and embedding processing used to match and compose content.
- PostHog, Helicone, and Sentry: product analytics, model observability, and error monitoring.
- X, Threads (Meta), LinkedIn, and Bluesky: only when you connect them, to publish the posts you create.
Some of these providers operate in the United States; where required, transfers rely on appropriate safeguards. We may also disclose information if required by law or to protect the service and its users.
Cookies
We use a small number of cookies: a session cookie to keep you signed in, preference cookies (such as your theme), and analytics cookies to understand usage. You can clear cookies in your browser; doing so will sign you out.
Data retention
We keep your data while your account is active and for a limited period afterward as needed for legal, security, and operational reasons. When you delete your account we delete or anonymize your personal data, except where we must retain it (for example, billing records). Disconnecting a social account deletes its token immediately.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Within Pemberley you can view and edit your Taste Profile, disconnect social accounts, manage your subscription, and unsubscribe from non-essential email. To exercise any other right, email us at jamie@born2be.io.
Security
Data is encrypted in transit (HTTPS), and sensitive material such as social access tokens is encrypted at rest. No system is perfectly secure, but we work to protect your information and to limit who and what can access it.
Children
Pemberley is not directed to children and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes to this policy
We may update this policy as the service evolves. When we make material changes we will update the date above and, where appropriate, notify you.
Contact
Questions about this policy or your data? Email jamie@born2be.io.