Serper.dev (Google Search)
What we collect: Public web snippets, news headlines, scholar citations, knowledge-graph metadata.
Legal basis: Public web; per Serper.dev Terms of Service.
Retention: Raw snippets: 180 days (rolling). Synthesized payloads: indefinite.
LinkedIn (via public Serper indexing)
What we collect: Publicly-indexed profile titles + snippets. Pano never authenticates to LinkedIn or scrapes the site directly.
Legal basis: hiQ v. LinkedIn precedent (public web); we honor LinkedIn's user-export rights.
Retention: Snippets: 180 days. Org-chart layered facts: indefinite.
SEC EDGAR (sec.gov)
What we collect: Filings, 8-Ks, S-1/S-4s referenced in M&A signal extraction.
Legal basis: Public-domain government filings.
Retention: Indefinite.
Issuer press releases / IR pages
What we collect: Press releases linked from /news endpoint and IR-team pages used for leadership-page extraction.
Legal basis: Public domain; press releases are explicitly distributed.
Retention: Indefinite for derived signals; 180 days for raw text.
Crunchbase (planned, Wedge 3+)
What we collect: Investor relationships, funding rounds, board seats. Used as a fallback when Serper snippets lack structured data.
Legal basis: Crunchbase Enterprise API license (per-tenant).
Retention: Per Crunchbase contractual terms.
User-supplied watchlists
What we collect: Customer-defined cohorts (slugs only). NEVER PHI/PII.
Legal basis: Customer ownership; processed under DPA.
Retention: Until customer deletes the watchlist.