Legal
Privacy
Pharos handles two very different kinds of personal data, and almost everything below follows from telling them apart: the data about you as a Pharos user, and the data about your subscribers that you upload and manage.
Last updated 25 August 2026
Draft. The facts here — where data is hosted, how long it is kept, what is deleted when — have been checked against the running system. What is still missing is the company's registered details, the governing law, and a lawyer's review; anything in square brackets is one of those. This is not legal advice, and counsel should review it before Pharos accepts customers.
Two roles, two sets of rules
For your account data — your name, email address, workspace and the way you use the product — Pharos is the controller. We decide what is collected and why, and this policy is our account of it.
For the contact data you put into Pharos — your subscribers' email addresses, names, tags, language and engagement history — you are the controller and Pharos is a processor. It is your list. We store and process it on your instructions, we do not decide what goes in it, and we do not use it for our own purposes. Concretely, that means we never mine it, never sell it, never use it to train models, and never mail your subscribers on our own initiative.
Because you are the controller of that data, you are the one who owes your subscribers a privacy notice, a lawful basis for contacting them, and a working way to unsubscribe. Pharos gives you the machinery — one-click unsubscribe headers, per-list subscription status, automatic suppression on hard bounces and spam complaints — but the obligation is yours.
Your sending account is yours
Pharos does not send email on its own credentials. You connect your own Resend or Amazon SES account, and campaigns go out through it. This is a deliberate architectural choice with a direct privacy consequence: your subscribers' addresses are handed to your email provider under your contract with them, not pooled into an account we control. Your domain reputation, your suppression list and your relationship with your provider stay yours, and remain yours if you stop using Pharos.
The credentials you give us for that account are encrypted with AES-256-GCM before they are stored, and are never displayed again after you save them.
What we collect about you
- Account
- Name, email address, and a hash of your password. We never store your password itself.
- Workspace
- Your organization, your role in it, who invited you, and which projects it contains.
- Session
- A session token, its expiry, and the IP address and user agent it was created from.
- Security audit
- Which credential performed which API request — method, path, scope and outcome — so you and we can answer what a key did. Never the key itself.
- Operational logs
- Errors and diagnostics needed to keep the service running.
- Payment
- None today. Billing is not live; no card details are collected or stored by Pharos, and when billing launches card data will be handled by a payment processor, not by us.
We do not run advertising trackers, we do not sell personal data, and we do not share it with anyone beyond the subprocessors listed below.
What you put into Pharos
Contact records (email address, first and last name, tags, language, source), the lists they belong to, the campaigns and automations you build, and the resulting delivery events — sent, delivered, opened, clicked, bounced, complained, unsubscribed. Also anything you connect on purpose: app store and revenue integrations, social accounts, mention monitoring.
Every row is scoped to a project, and every project to an organization. A credential issued for one project cannot read another: the scope is fixed in the credential itself, checked on the server for every request, and covered by tests that specifically try to reach across the boundary. The database enforces the structural half — foreign keys make a row that belongs to no project, or to another tenant's project, unrepresentable.
Artificial intelligence
AI drafting is off unless you switch it on per project. When it is on, the prompt sent to the model contains the campaign brief and the brand voice you configured — not your contact list. Product facts such as recipient counts, rankings and revenue figures are computed deterministically and never generated by a model.
Every generation is recorded with its capability and prompt version so you can audit what was asked for. Our model provider does not use this data to train its models.
Where it lives, and for how long
- Location
- The database is hosted by Neon on AWS in US East (N. Virginia), and the application's server functions run in the same region on Vercel. Requests reach it through Vercel's global edge network, so a request may transit a location nearer to you. Subprocessors may process data elsewhere; see the subprocessor list.
- Contact data
- Kept until you delete it or delete the project. Deleting a project deletes its contacts, lists, campaigns and delivery history, enforced by database cascade.
- Account data
- Kept while your account exists. Closing your account deletes it immediately rather than scheduling it — the rows are gone when the request returns, not thirty days later.
- Audit and logs
- Operational logs are retained for 30 days and then age out automatically. Security audit rows live in the database and are removed with the workspace they belong to.
- Backups
- The database keeps a six-hour point-in-time restore window. Deleted data can therefore persist in restorable history for up to six hours before ageing out; there are no longer-lived backup copies behind it.
Your rights
Depending on where you live you may have the right to access, correct, export, delete or restrict processing of your personal data, and to object to it or complain to a supervisory authority. For your own account data, write to hello@d2vsolutions.com and we will respond within 30 days.
If you are a subscriber of one of our customers and want your data removed, contact that company directly — they control the list and can delete you from it immediately. We will help them do it, but we cannot act on their data without their instruction. Every marketing email sent through Pharos carries an unsubscribe link that works without contacting anyone.
You can export your contacts to CSV at any time, and read everything an API key is scoped for through the API. Leaving does not require our cooperation.
Security
Passwords are hashed. Sending, store and social credentials are encrypted at rest with AES-256-GCM. API keys are stored only as SHA-256 hashes — we cannot show you a key again after it is created, because we do not have it. Keys carry explicit scopes, can be given an expiry, are rate limited, and can be revoked immediately. Inbound webhooks are signature-verified with a replay window.
No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and, where required, the relevant authority, without undue delay.
Cookies
Pharos sets only strictly necessary cookies — your sign-in session, and whatever the authentication layer needs to keep that sign-in secure. There are no advertising or analytics cookies on the application, and signing out clears your session.
Changes and contact
If we change this policy materially we will say so here and, for changes that affect how we handle your data, tell account owners by email before it takes effect.
Pharos is operated by D2V Solutions, [registered address]. hello@d2vsolutions.com. See also our terms and subprocessor list.