PageSpace is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect information in our cloud-based workspace platform, and describes your rights under the General Data Protection Regulation (GDPR) and similar data protection laws.
2. Who We Are (Data Controller)
PageSpace is operated by Jonathan Woodall, as a sole proprietorship, who is the data controller responsible for your personal data under this Privacy Policy.
TODO: legal entity name (if different from the above) and registered/postal address for the data controller.
Data Protection Officer (DPO): our recommended-default position is that a DPO is not required — GDPR Art 37 only mandates one where core activities involve large-scale, regular, and systematic monitoring of data subjects, or large-scale processing of special-category data, which is unlikely to describe PageSpace at its current size.
TODO: confirm current headcount and processing scale still support the "no DPO required" conclusion above; revisit as the company grows.
EU representative: PageSpace is operated from the United States and has no establishment in the EU. If we offer services to EU-based data subjects on more than an occasional basis, Art 27 GDPR likely requires us to appoint an EU representative (unless a recognized exemption applies, e.g. only occasional, low-risk processing).
TODO: confirm whether Art 27 applies given our actual EU user base, and if so, name an appointed EU representative — or document the exemption rationale if it does not apply.
3. Cloud-Based Privacy Approach
PageSpace is designed with privacy and security as core principles:
Secure Cloud Storage: Your data is stored in our cloud infrastructure with access controls and security logging
Authentication Security: Passwordless authentication via passkeys and magic links, with sessions managed using opaque tokens
Data Protection: Sensitive secrets like OAuth tokens for connected integrations are encrypted using AES-256-GCM encryption. Note that document content and chat messages are stored as plain text to enable search functionality
Transparency: Clear information about how we handle your data and what security measures we implement
4. Information We Collect
4.1 Account and Content Data
Information we collect and store includes:
User account information (username, email)
Pages, documents, and content you create (stored as plain text in our database)
File organization and workspace structure
Application settings and preferences
Chat messages and AI conversation history (stored as plain text in our database)
Usage analytics and subscription billing information (via Stripe)
OAuth tokens for connected integrations such as Google Calendar and Google Drive (encrypted using AES-256-GCM)
4.2 Technical Information
We collect technical information to maintain and improve the service:
IP addresses and device information
Browser type and version
Error logs for troubleshooting
Performance metrics for optimization
Feature usage statistics
5. Lawful Basis for Processing
Under GDPR Art 6, we rely on the following lawful bases for each purpose we process personal data for. This is our recommended-default mapping:
Account provision (creating and operating your account, storing your content) — Contract (Art 6(1)(b)): necessary to provide the service you signed up for
Billing and subscriptions — Contract (Art 6(1)(b)): necessary to perform our agreement with you
Security and audit logs — Legitimate interest (Art 6(1)(f)): protecting the service, our users, and detecting abuse
Marketing emails — Consent (Art 6(1)(a)): only sent if you opt in, and withdrawable at any time
AI processing (sending your prompts/content to AI providers) — Consent / Contract: providing AI features is part of the service you signed up for; where required, we also seek explicit consent
TODO: legal review of the legitimate-interest balancing test for security/audit logging, to confirm this mapping holds up to scrutiny.
6. Third-Party AI Services
When you use AI features, we work with external AI providers, each subject to that provider's own privacy policy. Provider routing is managed by PageSpace at the deployment level — you no longer supply or store provider API keys yourself. Supported providers include:
Model providers: your prompts and the relevant context are sent to AI model providers — including Anthropic (Claude), OpenAI (GPT), Google (Gemini), xAI (Grok), and, via the OpenRouter routing provider, additional third-party models — to generate responses. AI usage is metered against your plan's monthly credit allowance; Free plans use a curated set of models, and paid plans unlock the full catalogue.
Ollama (on-premises/local option): for self-hosted deployments, PageSpace supports Ollama, which runs models locally — your prompts and content never leave your own infrastructure when using this option.
Important: When using AI services, we send your prompts and relevant context to AI providers to generate responses. We do not share your personal information or unrelated workspace data with AI providers.
7. Data Processing and Storage
7.1 Cloud Processing
Data processing occurs on our secure cloud infrastructure, including:
Content creation and editing
Search and indexing
File organization
Real-time collaboration
AI model inference through third-party providers
7.2 Database Storage
Your data is stored in our cloud database infrastructure with security measures appropriate for a service of this type, including:
Access Controls: Database access is restricted to authorized services and personnel, with all operations logged for security analysis
Authentication Security: Passwordless authentication via passkeys and magic links
Secret Encryption: OAuth tokens for connected integrations and other application secrets are encrypted using AES-256-GCM
Connection Security: Database connections use secure protocols
Content Storage: Document content and chat messages are stored as plain text in our database to enable full-text search and collaboration features. This means content is not encrypted at rest in the database
Note: Our logging infrastructure captures database operations, errors, and security events for troubleshooting and security analysis, but does not constitute real-time monitoring or intrusion detection.
8. Data Sharing
PageSpace does not sell or rent your personal data. We may share your data only in these situations:
With AI service providers when you use AI features
When you explicitly share or collaborate with other users
With service providers who help us operate the platform (under strict confidentiality agreements) — see our Subprocessors page for the full list
When required by law or to protect our legal rights
In connection with a business transfer (merger, acquisition, etc.)
9. Data Security
We implement security measures appropriate for a cloud-based workspace service, including:
Data in Transit: Secure HTTPS connections for all web traffic
Session Management: Opaque session tokens with proper expiration and validation
Secret Protection: AES-256-GCM encryption for OAuth tokens and stored integration credentials
Database Access: Restricted access controls with comprehensive logging of operations, errors, and security events
Input Validation: Comprehensive sanitization and validation of user inputs
Rate Limiting: Protection against abuse and excessive API usage
CSRF Protection: Built-in protection against cross-site request forgery
While we implement commercially reasonable security measures, no system is 100% secure. We encourage users to register passkeys on their devices, use secure email accounts, and follow good security practices. You are responsible for maintaining backups of critical data.
10. Your Rights and Control
Under GDPR and similar laws, you have the following rights over your personal data:
Access: All your data is accessible through the application interface
Modification (Rectification): Edit or update any content at any time
Deletion (Erasure): Delete individual items or your entire workspace
Export (Data Portability): Data export available by request - contact us for assistance
Restriction (Art 18): Request that we limit processing of your data in certain circumstances (e.g. while a dispute about accuracy is resolved)
Objection (Art 21): Object to processing based on legitimate interest, including for direct marketing purposes
Withdraw Consent (Art 7(3)): Where processing is based on consent (e.g. marketing emails), withdraw it at any time without affecting the lawfulness of processing before withdrawal
Complain to a supervisory authority (Art 13(2)(d)): You have the right to lodge a complaint with a data protection supervisory authority
TODO: name your supervisory authority if PageSpace is EU-established; otherwise state that this right applies to lodging a complaint with any EU Data Protection Authority (DPA), typically the one in the data subject's member state.
11. Automated Decision-Making
We do not make solely-automated decisions that produce legal effects concerning you or similarly significantly affect you (GDPR Art 22).
TODO: confirm no such use case currently exists in the product (e.g. automatic billing-suspension or account-lockout logic that acts without human review) — revisit this statement if one is introduced.
12. Children's Privacy
PageSpace is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
14. Data Retention
We retain different categories of data for different lengths of time, depending on why we hold it:
Account and content data: retained while your account is active. Upon a deletion request, we complete erasure within 30 days (our internal Art 12(3) service-level target), except where we are required to retain specific records by law
Security and monitoring logs: retention varies by log type — API metrics, error logs, and AI-usage logs are kept for 90 days by default; system logs for 30 days; general user-activity logs for 180 days. Our tamper-evident security audit log and activity log are retained indefinitely because deleting entries would break the cryptographic hash chain that proves they haven't been altered — this is justified under GDPR Art 17(3)(b) as necessary for compliance with a legal obligation
Backups: retained separately from primary storage for disaster-recovery purposes
TODO: pull the exact backup retention day-count once it's documented — it is not currently codified alongside the other retention policies.
15. International Users and Data Processing
PageSpace is operated from the United States. If you are accessing our services from outside the United States, including from the European Economic Area (EEA) or United Kingdom, your information will be transferred to, stored, and processed in the United States.
Where we transfer personal data from the EEA or UK to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) as our transfer mechanism, rather than relying on your consent alone. Our subprocessors are listed on our Subprocessors page.
TODO: confirm which SCC Module is used for each vendor relationship, and confirm whether any transfers can instead rely on an adequacy decision (e.g. the UK's adequacy regulations) rather than SCCs.
16. Payment and Billing Information
When you purchase a subscription, payment processing is handled by Stripe, Inc. We do not store your credit card information on our servers. Stripe's privacy policy governs the collection and use of payment information.
We receive and store information about your subscription status, billing history, and usage metrics necessary for providing our services and managing your account.
17. Data Security Incidents
In the event of a personal data breach, we follow GDPR's two-part notification model:
We notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Art 33), unless the breach is unlikely to result in a risk to your rights and freedoms.
Where a breach is likely to result in a high risk to your rights and freedoms, we also communicate it to you directly, without undue delay, in clear and plain language (Art 34). This notification has no fixed hour deadline, but we aim to act as quickly as the circumstances allow.
Notifications will include information about the nature of the incident, the data affected, and the steps we are taking to address it.
18. Records of Processing Activities
A full Records of Processing Activities (RoPA) register is maintained internally per GDPR Art 30. GDPR does not require us to publish this register, so it is not reproduced here.
19. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us at: