Pamo Privacy Policy
Last updated: September 10, 2026
Pamo is provided by Hedirun, based in Georgia, United States ("Hedirun", "we", "us", or "our"). This Privacy Policy explains how information is handled when you use Pamo's mobile app, account, document storage, and related support services (together, "Pamo" or the "Service"). For privacy questions or requests, contact support@hedirun.com.
This policy covers Pamo. Hedirun's website and other apps have separate privacy notices. Please also read Pamo's Terms of Service, available in the app and at https://hedirun.com/pamo/terms. This notice describes our practices; it does not replace any separate consent required by law.
1. The essentials
- Pamo encrypts document files and sensitive document metadata on your device before uploading them. Its normal storage and organization functions do not require Hedirun to read your documents.
- Onna, Pamo's document assistant, performs text recognition, classification, and search processing on your device. Pamo does not send your document content to an external AI service.
- Account and operational information, such as your email, sign-in records, file sizes, and folder associations, is not protected by the same document encryption.
- Pamo currently has no advertising, cross-app tracking, third-party analytics SDK, or third-party crash-reporting SDK. We do not sell personal information or share it for targeted advertising.
- You can export documents and request account deletion in the app. Protect your recovery phrase and keep separate copies of irreplaceable documents.
2. Important terms
- Personal information means information that identifies you or can reasonably be linked to you, including your account and related technical records.
- Document content means the files you add and the text or other information within them.
- Document metadata means information describing a document, such as its title, type, tags, description, and extracted text.
- Vault key means the encryption key generated on your device to protect your documents. Encrypted, or "wrapped", copies of this key are stored with your account for unlocking and recovery.
- Recovery phrase means the 12-word secret used to recover access to your vault. It is different from an account sign-in code or a two-factor backup code.
- Service providers means organizations that supply functions such as authentication, hosting, storage, or email delivery for Pamo.
3. Information you provide
Account and sign-in information. We process your email address, the name you provide, your account identifier, and your chosen sign-in method. If you use Apple or Google sign-in, we receive the identity information and sign-in tokens the provider makes available, such as a name, email or private relay address, and provider identifier. We do not request access to your social posts or contacts.
For email/password sign-in, your password is transmitted to our authentication provider over an encrypted connection for account creation, verification, or password changes. The provider stores a password hash rather than a readable password. Pamo also uses your password locally to protect the wrapped vault key in password-based accounts. A separate vault passphrase used with social sign-in, and your recovery phrase, are used locally for vault encryption and recovery. They are not submitted as document content. Do not send passwords, vault passphrases, recovery phrases, or sign-in codes to support.
If you enable two-factor authentication, our authentication systems process enrollment and verification information. Pamo's server stores hashes of two-factor backup codes and whether they have been used. We also store wrapped vault-key copies and related account security settings.
Documents. You choose the scans, photographs, or files to add. These may contain information about you or other people, including sensitive information such as identification, financial, health, or school records. Please add only information you are entitled to store.
Support communications. If you email us, we receive your email address, message, and any attachments or diagnostic details you choose to send. A document or screenshot attached to a support email is outside the encrypted vault and can be read by the recipients. Share only what is needed to resolve your request.
4. Document encryption and its limits
Pamo uses AES-256-GCM encryption on the device for uploaded document files and sensitive metadata, including titles, file types, extracted text, AI-generated descriptions and tags, and search embeddings. Custom folder names are encrypted too. Our servers store these fields as ciphertext. The vault key is not uploaded in readable form; its wrapped copies require the corresponding unlocking secret.
Encryption does not conceal every fact about an account. Account identifiers, document and folder identifiers, file sizes, timestamps, document counts, storage usage, folder associations, and system-defined folder information remain available to operate the Service. A default folder or its association with a document may reveal a broad category even though the document is encrypted.
Pamo's document encryption is not a promise of absolute security or anonymity. Password authentication, account records, device security, and support messages have separate roles and protections. Someone who obtains an unlocking secret or access to an unlocked device may be able to read documents. An exported or shared copy is no longer protected by Pamo's vault controls.
5. Information processed automatically
Pamo and its hosting, authentication, and delivery providers process technical information needed to deliver and protect the Service. This can include IP addresses, request times, sign-in events, response or error information, and client information supplied with network requests. IP addresses can indicate a general location; Pamo does not request precise device location.
We also maintain operational records such as account creation dates, member numbers, storage usage, and document or folder counts. These support account management, quotas, troubleshooting, and abuse prevention. They are distinct from advertising profiles or behavioral analytics.
Pamo currently has no payment or subscription system and does not collect payment-card numbers or billing addresses. Apple handles any separate App Store account information under its own policies.
6. Device permissions, local storage, and exports
- Camera and selected media or files. Camera access enables scanning. System photo and file pickers let you choose what to import. Pamo does not upload your entire photo library. You can manage permissions in device settings, although denying a permission can prevent the related feature from working.
- Biometric authentication. Where supported, the operating system can authenticate you for Pamo's app lock. Pamo receives the authentication result, not your Face ID or fingerprint template.
- Local storage. Pamo keeps sign-in session information, preferences, locally stored vault-key material, downloaded AI models, and encrypted offline document caches on the device. Readable information may be held in memory or temporary files while you scan, preview, process, copy, or export it.
- Sign-out and removal. Signing out initiates clearing of Pamo's account key and offline document cache. Downloaded AI models may remain for reuse. Uninstalling the app does not delete your server account, and some operating-system secure storage, backups, or exported files may persist separately.
- Sharing and copying. Files, ZIP exports, or copied text that you send to another app, person, cloud drive, or clipboard are handled under that destination's controls and policies. Deleting an item in Pamo does not recall those copies.
The native app uses local storage and session tokens to provide its functions, rather than advertising cookies. Apple, Google, or other websites opened during sign-in or from a link may use their own cookies under their policies.
7. How Onna works
Onna processes document text on your device to help classify, name, describe, and find files. Model files are downloaded from our Cloudflare-hosted distribution service and reused locally; a download exposes ordinary network details to the delivery provider, not the contents of your vault.
Document content is not uploaded to train an external AI model. Classification and search results can be inaccurate, and you can review or correct them. Pamo does not use these document-organizing features to make decisions about your eligibility for credit, employment, insurance, or other similarly significant matters.
8. Why we use information
- To create and authenticate your account, deliver encrypted files, synchronize your vault, and provide document organization and search on your device.
- To maintain account security, verify two-factor codes, enforce storage limits, prevent abuse, and diagnose service problems.
- To send necessary account messages, including verification, recovery, security, and material service or policy notices.
- To answer support and privacy requests and keep an appropriate record of their resolution.
- To comply with applicable legal obligations and establish, exercise, or defend legal claims.
Providing basic account information is necessary to use a cloud vault. Optional permissions and support attachments are your choice. We do not use your documents or account information for advertising, and Pamo does not currently send a marketing newsletter.
9. Service providers and other disclosures
Our current supporting services include:
- Supabase: account authentication, database services, and encrypted file storage. It processes account and sign-in information, operational records, and encrypted vault data.
- Render: hosting for Pamo's backend, which handles authorized requests, account operations, technical records, and encrypted data in transit to storage.
- Resend: delivery of account emails through the configured authentication email service. Email delivery involves the recipient address and message contents, including applicable account links or codes.
- Cloudflare: distribution of public on-device AI model files. It receives download-related technical information.
- Apple: App Store distribution and version lookup, and Sign in with Apple if you choose it. Network requests to Apple expose ordinary request information; sign-in also involves your selected Apple identity.
- Google: Sign in with Google if you choose it, involving the identity and authorization information needed for that sign-in.
We use service providers for their relevant functions. Document storage providers receive encrypted vault data, while account, network, and email providers receive the readable information necessary for those functions. Apple and Google also process information independently when you use their services.
We may disclose information in response to a binding legal requirement, to address fraud or threats to security or safety, or to protect legal rights. Such a disclosure can include account or technical information and encrypted data we hold; it does not itself decrypt document files.
Information may transfer with a merger, acquisition, reorganization, or sale involving Pamo. A successor would receive it subject to applicable law and the privacy commitments that apply to it. We will give notice of material changes where required. We may also disclose information when you specifically direct us to do so, such as sending an exported file.
10. International processing
Pamo's primary backend, database, and storage infrastructure is hosted in the United States. Service providers may process account, support, and technical information in other countries as part of their services. Those countries may have different data protection laws from where you live. Document files are encrypted before upload regardless of your location.
Contact support@hedirun.com for information about the processing locations and transfer arrangements relevant to your account, including any applicable safeguards. You retain the rights provided by the laws that apply to you.
11. Retention and account deletion
We keep account records and encrypted vault data while your account is active and they are needed to provide the Service. You can delete individual documents or use Account > Account details > Delete account. Account deletion removes the account and associated database records and requests removal of stored document files. Export anything you want to keep before deleting it.
Removal of every stored copy is not instantaneous or guaranteed by the deletion confirmation. Storage deletion can fail, and residual encrypted files or backup copies may remain after active account records are removed. Contact us if you need help with a deletion request or have concerns about retained information.
Security logs, support correspondence, records of privacy requests, or information subject to a legal preservation obligation may be retained separately. We determine retention based on the purpose of the record, whether the issue remains unresolved, security and recovery needs, provider backup cycles, and applicable legal obligations. Retained information is used for those limited purposes, not to restore your account for ordinary use or to market to you. There is no single fixed retention period for every category.
Deleting Pamo from your device does not close your account. Deleting your account cannot remove copies you exported, shared, backed up independently, or sent in correspondence to others.
12. Your choices and privacy requests
You can view and export documents, correct document titles or folders, update supported profile information, manage device permissions, and request deletion through the app. If you cannot sign in, or need account information beyond the built-in tools, email support@hedirun.com with the account email and the request you want to make.
Depending on the law that applies, you may have rights to access, correct, delete, or receive a portable copy of personal information; restrict processing; object to certain uses; withdraw consent where processing relies on it; or appeal a decision on a request. These rights can have exceptions. Withdrawing consent does not undo lawful processing that occurred before withdrawal.
We may need to verify your identity or an authorized agent's authority before acting. We request verification appropriate to the sensitivity of the request; we do not need your recovery phrase or vault key. We respond within applicable legal time limits and explain any permitted extension, refusal, or limitation. You may reply to our response to request reconsideration or an appeal where available, and you may contact the relevant privacy regulator. We do not discriminate against you for exercising applicable privacy rights.
Because documents are encrypted, we may be unable to supply a readable copy if you have lost access to your vault. That does not prevent you from requesting account information or deletion, subject to appropriate verification.
13. Additional information for US residents
Where applicable state privacy law provides these rights, you may request the categories or specific information held about you, its sources, purposes, and recipients, as well as correction, deletion, portability, and an appeal. Sections 3 through 9 describe the information categories, sources, uses, and recipients. Sensitive documents you choose to store are processed to provide your vault, not for advertising or to infer personal characteristics for marketing.
California residents: where the California Consumer Privacy Act applies, its rights may include knowing, accessing, correcting, and deleting information, and limiting certain uses of sensitive information. We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive information for purposes requiring a separate limitation option under that law. Submit requests or authorized-agent requests using the contact method above.
Pamo does not track you across other companies' apps or websites for advertising. The native app has no separate response to browser Do Not Track or Global Privacy Control signals because it does not perform the sale, sharing, or targeted advertising those controls are intended to limit. This does not limit any privacy choice that applicable law gives you.
14. Additional information for the EEA, UK, and Switzerland
Where the relevant data protection laws apply, Hedirun is responsible for the account and service processing described here. The bases for that processing include delivering the service you request, legitimate interests in securing and supporting it and addressing legal claims, complying with legal obligations, and consent where separately required. The basis depends on the specific processing and applicable law.
You may object to processing based on legitimate interests, subject to the applicable legal conditions. You may also exercise applicable access, correction, erasure, restriction, portability, and consent-withdrawal rights using the contact method above. You can complain to your local supervisory authority without first contacting us. Onna's on-device filing and search do not constitute a decision determining your legal rights or eligibility for services.
15. Children
Pamo is not directed to children under 13 or a higher minimum age required by applicable law, and we do not knowingly collect personal information from children below that age. If you believe a child has provided such information, contact us so we can investigate and take appropriate steps, including deletion. Older minors must meet the consent and permission requirements in the Terms of Service.
16. Security and recovery
Pamo uses document encryption, encrypted network connections, account authentication, access controls, and available device security features to protect information. No system can guarantee that information will never be lost, accessed improperly, or affected by a security incident. Where notification of an incident is required, we will provide it as required by applicable law.
Keep your device, account credentials, vault passphrase, and recovery phrase secure. If you lose all means of unlocking the vault, including the recovery phrase, Hedirun cannot recreate the missing secret to recover your documents. An account password reset alone does not necessarily restore vault access.
17. Changes and contact
We may update this policy as Pamo or its information practices change. We will update the date above and communicate material changes through the app or email before they take effect, and obtain additional consent where required. A future change does not automatically authorize a materially different use of previously collected information.
Hedirun
Privacy questions, requests, and complaints: support@hedirun.com.