Effective: 19 September 2026.
PENROUZ Commander processes data necessary to authenticate users, link authorized devices, route requested MCP operations, secure the service, and provide support.
We may process account email, OAuth client metadata, session and device identifiers, device name/platform, declared capabilities and local permission policy, timestamps, IP/network security logs, and operation status metadata.
When you ask an AI client to use a connected device, tool arguments and results can contain file paths, file content, commands, process output, or other data needed for that request. This data is relayed between the AI client and your selected device to perform the operation.
Cloud device credentials, account sessions, OAuth access tokens, refresh tokens, and authorization codes are stored as one-way hashes rather than plaintext values. The local agent credential is stored on the user's device.
Relay job arguments and results are scrubbed from the relay database after the result is delivered to the MCP caller. Relay audit metadata records the operation name, device, time, and outcome without preserving the job payload and is subject to bounded operational retention. Pairing codes expire after 10 minutes and are single-use. Access tokens are short-lived and refresh tokens rotate.
We do not sell user data and do not use it for advertising. Data is processed by PENROUZ infrastructure and hosting providers required to operate the service. Data returned through MCP is also provided to the AI service the user chose to invoke the tool.
Users can disconnect devices, revoke browser and OAuth sessions, generate one-time recovery codes, change their password, and permanently delete their account from Account security. Account deletion purges account-linked devices, queued jobs, sessions, recovery codes, and issued OAuth tokens. For privacy questions, contact support@penrouz.com.
Do not send passwords, API keys, MFA codes or other authentication secrets as ordinary tool arguments. For sensitive workloads, use narrow device permissions or an isolated OS account, container, VM, or dedicated machine.