Privacy notice
HOW WE HANDLEYOUR DATA.
This notice covers the public part of the site: the home page and the contact form. It describes what the product does today. Where something does not exist yet, it says so — instead of a promise the code does not keep.
Updated on 16 August 2026
The contact form
The form asks for three things: name, email and message. We do not ask for phone, company, job title, any identity document or anything else, and there is no hidden field.
- Purpose
- To answer the contact you started and talk about the project described in the message.
- Legal basis
- Your consent, given when you fill in and submit the form. You can withdraw it at any time through the address at the end of this page.
- Today
- Automatic email delivery is not switched on, because the provider credential has not been configured yet. When you press send, the text travels to our server, is validated and discarded at the end of the request: it is not written to any database and not passed to anyone. Your own email app then opens with the message ready, and it only leaves when you send it, straight to the address at the end of this page.
- Planned
- Once automatic delivery is switched on, those same three fields will be transmitted over an encrypted connection to Resend (resend.com) — the email delivery provider already chosen and wired into the product's code. It is named here before the key even exists, deliberately: what is still undefined is how long Resend keeps the messages, and that period will appear on this page once it is settled.
The attempt limit
The form is the only address in this product that anyone can reach without an account. To keep it from becoming a target for automated submissions, we count how many submissions came from the same origin within a time window.
What gets stored is not your IP address: it is the output of a hash function (SHA-256) computed over it, together with a counter and the time the window started. The address itself never enters this product's database. It does appear, as on any website, in the hosting provider's technical access records — that is covered in section 04, and it is not the same thing as this counting. The same counting protects the login screen, and there the identifier is the email typed in — also kept only as a hash.
- Retention
- Each count is deleted once its window has been over for more than one day.
- Legal basis
- Legitimate interest in keeping the service available and protected from automated abuse.
What stays in your browser
There is no Google Analytics, social pixel, heat map, session recording or third-party tag on this surface — not in the code, not in the project dependencies. Nothing here measures audience.
We only keep your reading preferences, in your own browser's local storage:
slatecase:temalight or dark theme of the public siteslatecase:movimentonormal or reduced motionslatecase:backoffice:tematheme of the client areaThose values stay on your device, are never sent to us, and disappear when you clear the site data.
The only cookie in this product is the session cookie, created after someone signs in to the client area. Visiting the public site without signing in does not create it. We use no tracking or advertising cookies.
Who the data is shared with
We do not sell, rent or trade personal data. The list below is complete:
- Supabase — the product database. It holds the attempt-limit counts described above.
- Hosting provider — keeps the technical access records any web server operation produces. The provider is still being decided, and its name will appear here once it is contracted.
- Resend — the email delivery provider, already chosen and wired into the code. It receives nothing yet: it will start receiving the form's name, email and message once the delivery credential is configured, and not before.
No other third party receives data from this surface.
How long we keep it
Periods measured in the code and in the database, not estimated:
| Data | Retention | Status |
|---|---|---|
| Name, email and message from the form | Not stored — discarded at the end of the request | In force |
| The same three fields, once automatic delivery is on | To be defined with Resend | Pending |
| Hash of the submission origin, with a counter | One day after the window ends | In force |
| Hash of the email used at login, with a counter | One day after the window ends | In force |
| Authorization states for the client area integrations | Seven days after expiring or being consumed | In force |
| Theme and motion preferences | In your browser, until you clear them | In force |
Your rights
Brazil's General Data Protection Law (LGPD) grants you, over your own data:
- confirmation that processing exists, and access to what exists;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data;
- portability to another provider;
- deletion of data processed on the basis of your consent;
- information about who we share it with;
- withdrawal of consent, at any time.
To exercise any of them, write to the address below saying what you want. We reply by the same email.
What is still pending
This list is published on purpose. Each item leaves this page the day it is resolved:
- Data protection officer not appointed yet.
- How long Resend keeps the form messages is not defined yet — the provider is chosen, the retention period is not.
- Hosting provider not yet named on this page.
- Response time for requests not yet committed to publicly.
- The client area behind the login has its own processing and is not covered by this notice yet.
Talking about your data
Questions about this notice, or a request about your data:
hello@panoramacase.comUntil a data protection officer is appointed, requests arrive at that address and are handled by whoever answers for the studio.