Privacy Policy

Last updated: September 17, 2026

1. Introduction

PageSpace is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect information in our cloud-based workspace platform, and describes your rights under the General Data Protection Regulation (GDPR), the UK GDPR, and similar data protection laws.

2. Who We Are (Data Controller)

PageSpace is operated by Jonathan Woodall, trading as PageSpace, a sole proprietorship established in the United States. Jonathan Woodall is the data controller responsible for your personal data under this Privacy Policy. You can reach the controller directly at hello@pagespace.ai.

Data Protection Officer (DPO): PageSpace has not appointed a DPO. GDPR Art 37 only requires one where core activities involve large-scale, regular, and systematic monitoring of data subjects, or large-scale processing of special-category data. PageSpace is a single-operator business that does neither. Privacy questions and requests are handled personally by the controller at the email address above, and we will appoint a DPO if the scale of our processing ever meets the Art 37 threshold.

EU / UK representative: PageSpace is operated from the United States and has no establishment in the EU or UK. We have not appointed an Art 27 representative because our processing of EU and UK personal data is occasional, does not include large-scale processing of special categories of data or criminal-conviction data, and is unlikely to result in a risk to the rights and freedoms of data subjects (the exemption in GDPR Art 27(2)(a)). We review this position as our user base changes and will appoint a representative if the exemption ceases to apply. In the meantime, EU and UK data subjects and supervisory authorities can contact the controller directly at hello@pagespace.ai.

3. Cloud-Based Privacy Approach

PageSpace is designed with privacy and security as core principles:

  • Secure Cloud Storage: Your data is stored in our cloud infrastructure with access controls and security logging
  • Authentication Security: Passwordless authentication via passkeys and magic links, with sessions managed using opaque tokens
  • Data Protection: Sensitive secrets like OAuth tokens for connected integrations are encrypted using AES-256-GCM encryption. Note that document content and chat messages are stored as plain text to enable search functionality
  • Transparency: Clear information about how we handle your data and what security measures we implement

4. Information We Collect

4.1 Account and Content Data

Information we collect and store includes:

  • User account information (username, email)
  • Pages, documents, and content you create (stored as plain text in our database)
  • Files you upload (stored in object storage)
  • File organization and workspace structure
  • Application settings and preferences
  • Chat messages and AI conversation history (stored as plain text in our database)
  • Usage analytics and subscription billing information (via Stripe)
  • OAuth tokens for connected integrations such as Google Calendar, Google Drive, and GitHub (encrypted using AES-256-GCM)

4.2 Technical Information

We collect technical information to maintain and improve the service:

  • IP addresses and device information
  • Browser type and version
  • Error logs for troubleshooting
  • Performance metrics for optimization
  • Feature usage statistics (first-party, only with your analytics consent — see our Cookie Policy)

5. Lawful Basis for Processing

Under GDPR Art 6, we rely on the following lawful bases for each purpose we process personal data for:

  • Account provision (creating and operating your account, storing your content) — Contract (Art 6(1)(b)): necessary to provide the service you signed up for
  • Billing and subscriptionsContract (Art 6(1)(b)): necessary to perform our agreement with you
  • Security and audit logsLegitimate interest (Art 6(1)(f)): protecting the service, our users, and detecting abuse. Our balancing test: this logging is limited to what is needed to secure accounts and investigate incidents, users reasonably expect a workspace service to keep security records, the data is access-restricted and not used for any other purpose, and the impact on users is minimal compared with the harm an unsecured service would expose them to
  • Product analyticsConsent (Art 6(1)(a)): our first-party usage tracker only runs after you opt in, and you can withdraw at any time
  • Marketing emailsConsent (Art 6(1)(a)): only sent if you opt in, and withdrawable at any time
  • AI processing (sending your prompts and the content you choose to include to AI providers) — Contract (Art 6(1)(b)): AI features are part of the service you signed up for, and are only triggered by your own explicit actions

6. Third-Party AI Services

When you use AI features, we work with external AI providers, each subject to that provider's own privacy policy. Provider routing is managed by PageSpace at the deployment level — you do not supply or store provider API keys yourself. Every cloud model PageSpace offers is reached through OpenRouter, a routing provider: your request goes to OpenRouter, which forwards it to the provider of the model you selected. The parties involved are:

  • OpenRouter (routing): OpenRouter receives your prompt and the context you include on every cloud AI request, and forwards it to the provider of the model you selected.
  • Model providers: the provider of the model you choose generates the response. The catalogue includes Anthropic (Claude), OpenAI (GPT), Google (Gemini), xAI (Grok), Z.ai, DeepSeek, Mistral, Meta, Qwen, Moonshot AI, Cohere and others; the model selected by default for a new account is Z.ai's GLM-5.3 Flash. AI usage is metered against your credits (a one-time starter grant on Free, a monthly allowance on paid plans); Free plans use a curated set of models, and paid plans unlock the full catalogue.
  • Ollama (on-premises/local option): for self-hosted deployments, PageSpace supports Ollama, which runs models locally — your prompts and content never leave your own infrastructure when using this option.

Important: When using AI services, we send your prompts and relevant context through OpenRouter to the provider of the model you selected, to generate a response. We do not share your personal information or unrelated workspace data with AI providers. Anthropic, OpenAI, Google and xAI state that inputs sent through their APIs are not used to train their models. For every model, retention and training are governed by the upstream provider's own policy, which OpenRouter publishes per model — check the model's entry on OpenRouter if this matters for your data.

7. Data Processing and Storage

7.1 Cloud Processing

Data processing occurs on our secure cloud infrastructure, hosted by Fly.io in the United States (Ashburn, Virginia), including:

  • Content creation and editing
  • Search and indexing
  • File organization
  • Real-time collaboration
  • AI model inference through third-party providers

7.2 Database Storage

Your data is stored in our cloud database infrastructure with security measures appropriate for a service of this type, including:

  • Access Controls: Database access is restricted to authorized services and personnel, with all operations logged for security analysis
  • Authentication Security: Passwordless authentication via passkeys and magic links
  • Secret Encryption: OAuth tokens for connected integrations and other application secrets are encrypted using AES-256-GCM
  • Connection Security: Database connections use secure protocols
  • Disk Encryption: The volume holding our database is encrypted at rest by our hosting provider
  • Content Storage: Document content and chat messages are stored as plain text in our database to enable full-text search and collaboration features. This means content is not application-level encrypted in the database

Note: Our logging infrastructure captures database operations, errors, and security events for troubleshooting and security analysis, but does not constitute real-time monitoring or intrusion detection.

8. Data Sharing

PageSpace does not sell or rent your personal data. We may share your data only in these situations:

  • With AI service providers when you use AI features
  • When you explicitly share or collaborate with other users
  • With service providers who help us operate the platform (under data processing agreements) — see our Subprocessors page for the full list
  • When required by law or to protect our legal rights
  • In connection with a business transfer (merger, acquisition, etc.)

9. Data Security

We implement security measures appropriate for a cloud-based workspace service, including:

  • Data in Transit: Secure HTTPS connections for all web traffic
  • Authentication Security: Passwordless authentication eliminates credential-based attack vectors
  • Session Management: Opaque session tokens with proper expiration and validation
  • Secret Protection: AES-256-GCM encryption for OAuth tokens and stored integration credentials
  • Database Access: Restricted access controls with comprehensive logging of operations, errors, and security events
  • Input Validation: Comprehensive sanitization and validation of user inputs
  • Rate Limiting: Protection against abuse and excessive API usage
  • CSRF Protection: Built-in protection against cross-site request forgery
  • Encrypted Backups: Database backups are encrypted (AES-256) before they leave the database host

While we implement commercially reasonable security measures, no system is 100% secure. We encourage users to register passkeys on their devices, use secure email accounts, and follow good security practices. You are responsible for maintaining backups of critical data.

10. Your Rights and Control

Under GDPR and similar laws, you have the following rights over your personal data:

  • Access: All your data is accessible through the application interface
  • Modification (Rectification): Edit or update any content at any time
  • Deletion (Erasure): Delete individual items or your entire workspace
  • Export (Data Portability): Data export available by request - contact us for assistance
  • Restriction (Art 18): Request that we limit processing of your data in certain circumstances (e.g. while a dispute about accuracy is resolved)
  • Objection (Art 21): Object to processing based on legitimate interest, including for direct marketing purposes
  • Withdraw Consent (Art 7(3)): Where processing is based on consent (e.g. analytics or marketing emails), withdraw it at any time without affecting the lawfulness of processing before withdrawal
  • Complain to a supervisory authority (Art 13(2)(d)): You have the right to lodge a complaint with a data protection supervisory authority. Because PageSpace is not established in the EU, you may complain to the Data Protection Authority of the EU member state where you live or work, or where you believe an infringement occurred. UK residents may complain to the Information Commissioner's Office (ICO)

We respond to rights requests within one month of receipt (GDPR Art 12(3)). We would appreciate the chance to address any concern directly before you contact a supervisory authority.

11. Automated Decision-Making

We do not make solely-automated decisions that produce legal effects concerning you or similarly significantly affect you (GDPR Art 22). Two automated safeguards do exist, and neither has such an effect: an account is temporarily locked for 15 minutes after 10 consecutive failed sign-in attempts, and a subscription whose payment ultimately fails (after Stripe's retry period) is returned to the Free plan without deleting any of your content. Both are reversible, and you can contact us at any time to have a person review either outcome.

12. Children's Privacy

PageSpace is not intended for anyone under 16, and you must be at least 16 to create an account. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has provided personal information, please contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

14. Data Retention

We retain different categories of data for different lengths of time, depending on why we hold it:

  • Account and content data: retained while your account is active. Upon a deletion request, we complete erasure within 30 days (our internal Art 12(3) service-level target), except where we are required to retain specific records by law
  • Deleted chats and page versions: deleted chat records and superseded page versions are kept for 30 days so they can be restored, then permanently removed
  • Security and monitoring logs: retention varies by log type — API metrics, error logs, and AI-usage logs are kept for 90 days by default; system logs for 30 days; general user-activity logs (including consented product analytics) for 180 days. Our tamper-evident security audit log and activity log are retained indefinitely because deleting entries would break the cryptographic hash chain that proves they haven't been altered — this is justified under GDPR Art 17(3)(b) as necessary for compliance with a legal obligation
  • Backups: an encrypted logical backup of the database is taken daily and retained for 30 days; our hosting provider's automatic disk snapshots are retained for 5 days. Content you delete therefore disappears from all backups within 30 days of deletion

15. International Users and Data Processing

PageSpace is operated from the United States. If you are accessing our services from outside the United States, including from the European Economic Area (EEA) or United Kingdom, your information will be transferred to, stored, and processed in the United States.

Where we transfer personal data from the EEA to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs, Module 2: controller-to-processor) incorporated into the data processing agreement of each subprocessor, rather than relying on your consent alone. For UK personal data we rely on the same SCCs together with the ICO's International Data Transfer Addendum. Where a subprocessor is certified under the EU-U.S. Data Privacy Framework (and its UK Extension), we may rely on that adequacy decision instead. Our subprocessors, and the mechanism used for each, are listed on our Subprocessors page.

16. Payment and Billing Information

When you purchase a subscription, payment processing is handled by Stripe, Inc. We do not store your credit card information on our servers. Stripe's privacy policy governs the collection and use of payment information.

We receive and store information about your subscription status, billing history, and usage metrics necessary for providing our services and managing your account.

17. Data Security Incidents

In the event of a personal data breach, we follow GDPR's two-part notification model:

  • We notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Art 33), unless the breach is unlikely to result in a risk to your rights and freedoms.
  • Where a breach is likely to result in a high risk to your rights and freedoms, we also communicate it to you directly, without undue delay, in clear and plain language (Art 34). This notification has no fixed hour deadline, but we aim to act as quickly as the circumstances allow.

Notifications will include information about the nature of the incident, the data affected, and the steps we are taking to address it.

18. Records of Processing Activities

A full Records of Processing Activities (RoPA) register is maintained internally per GDPR Art 30. GDPR does not require us to publish this register, so it is not reproduced here.

19. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at:

  • Email: hello@pagespace.ai
  • Support: Available through the in-app help system
  • Community: AI Agent Hub

For data protection requests (access, deletion, portability), please use the subject line "Data Protection Request" in your email.

Search

Search docs, blog posts, and more.