Security and your data
What Pensova reads, what it keeps, what it never touches, and how to delete everything.
Updated 9 September 2026
The short version: two Google permissions, both for Calendar; your calendar events are read live when planning and never copied into the database; the card never touches Pensova at all. The full account, table by table, is on the Security and data page.
What is stored
- Your tasks, the blocks placed for them, and drafts waiting for a decision.
- Working hours, the first day of the week, and which calendars count.
- Google tokens, so the background job can act on your calendar between visits. No signed-in user can read them, including you.
- A fingerprint of your busy pattern, so the job knows whether anything changed. It cannot be turned back into events.
- A mirror of your Stripe subscription: plan, status, interval and dates. Never the card.
- For notes by email: your private address token and a log of what arrived (service, hash, draft count), never the email.
Deleting the account
Email privacy@pensova.com from the address you signed up with. Deletion is permanent and covers everything above. It is done within 30 days, usually much sooner. Events on your Google Calendar and Stripe’s own records of past payments are not Pensova’s to delete. A button in the app for this is in development.