Privacy Policy

Last updated: July 5, 2026

1. Introduction

PageSpace is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect information in our cloud-based workspace platform, and describes your rights under the General Data Protection Regulation (GDPR) and similar data protection laws.

2. Who We Are (Data Controller)

PageSpace is operated by Jonathan Woodall, as a sole proprietorship, who is the data controller responsible for your personal data under this Privacy Policy.

TODO: legal entity name (if different from the above) and registered/postal address for the data controller.

Data Protection Officer (DPO): our recommended-default position is that a DPO is not required — GDPR Art 37 only mandates one where core activities involve large-scale, regular, and systematic monitoring of data subjects, or large-scale processing of special-category data, which is unlikely to describe PageSpace at its current size.

TODO: confirm current headcount and processing scale still support the "no DPO required" conclusion above; revisit as the company grows.

EU representative: PageSpace is operated from the United States and has no establishment in the EU. If we offer services to EU-based data subjects on more than an occasional basis, Art 27 GDPR likely requires us to appoint an EU representative (unless a recognized exemption applies, e.g. only occasional, low-risk processing).

TODO: confirm whether Art 27 applies given our actual EU user base, and if so, name an appointed EU representative — or document the exemption rationale if it does not apply.

3. Cloud-Based Privacy Approach

PageSpace is designed with privacy and security as core principles:

  • Secure Cloud Storage: Your data is stored in our cloud infrastructure with access controls and security logging
  • Authentication Security: Passwordless authentication via passkeys and magic links, with sessions managed using opaque tokens
  • Data Protection: Sensitive secrets like OAuth tokens for connected integrations are encrypted using AES-256-GCM encryption. Note that document content and chat messages are stored as plain text to enable search functionality
  • Transparency: Clear information about how we handle your data and what security measures we implement

4. Information We Collect

4.1 Account and Content Data

Information we collect and store includes:

  • User account information (username, email)
  • Pages, documents, and content you create (stored as plain text in our database)
  • File organization and workspace structure
  • Application settings and preferences
  • Chat messages and AI conversation history (stored as plain text in our database)
  • Usage analytics and subscription billing information (via Stripe)
  • OAuth tokens for connected integrations such as Google Calendar and Google Drive (encrypted using AES-256-GCM)

4.2 Technical Information

We collect technical information to maintain and improve the service:

  • IP addresses and device information
  • Browser type and version
  • Error logs for troubleshooting
  • Performance metrics for optimization
  • Feature usage statistics

5. Lawful Basis for Processing

Under GDPR Art 6, we rely on the following lawful bases for each purpose we process personal data for. This is our recommended-default mapping:

  • Account provision (creating and operating your account, storing your content) — Contract (Art 6(1)(b)): necessary to provide the service you signed up for
  • Billing and subscriptionsContract (Art 6(1)(b)): necessary to perform our agreement with you
  • Security and audit logsLegitimate interest (Art 6(1)(f)): protecting the service, our users, and detecting abuse
  • Marketing emailsConsent (Art 6(1)(a)): only sent if you opt in, and withdrawable at any time
  • AI processing (sending your prompts/content to AI providers) — Consent / Contract: providing AI features is part of the service you signed up for; where required, we also seek explicit consent
TODO: legal review of the legitimate-interest balancing test for security/audit logging, to confirm this mapping holds up to scrutiny.

6. Third-Party AI Services

When you use AI features, we work with external AI providers, each subject to that provider's own privacy policy. Provider routing is managed by PageSpace at the deployment level — you no longer supply or store provider API keys yourself. Supported providers include:

  • Model providers: your prompts and the relevant context are sent to AI model providers — including Anthropic (Claude), OpenAI (GPT), Google (Gemini), xAI (Grok), and, via the OpenRouter routing provider, additional third-party models — to generate responses. AI usage is metered against your plan's monthly credit allowance; Free plans use a curated set of models, and paid plans unlock the full catalogue.
  • Ollama (on-premises/local option): for self-hosted deployments, PageSpace supports Ollama, which runs models locally — your prompts and content never leave your own infrastructure when using this option.

Important: When using AI services, we send your prompts and relevant context to AI providers to generate responses. We do not share your personal information or unrelated workspace data with AI providers.

7. Data Processing and Storage

7.1 Cloud Processing

Data processing occurs on our secure cloud infrastructure, including:

  • Content creation and editing
  • Search and indexing
  • File organization
  • Real-time collaboration
  • AI model inference through third-party providers

7.2 Database Storage

Your data is stored in our cloud database infrastructure with security measures appropriate for a service of this type, including:

  • Access Controls: Database access is restricted to authorized services and personnel, with all operations logged for security analysis
  • Authentication Security: Passwordless authentication via passkeys and magic links
  • Secret Encryption: OAuth tokens for connected integrations and other application secrets are encrypted using AES-256-GCM
  • Connection Security: Database connections use secure protocols
  • Content Storage: Document content and chat messages are stored as plain text in our database to enable full-text search and collaboration features. This means content is not encrypted at rest in the database

Note: Our logging infrastructure captures database operations, errors, and security events for troubleshooting and security analysis, but does not constitute real-time monitoring or intrusion detection.

8. Data Sharing

PageSpace does not sell or rent your personal data. We may share your data only in these situations:

  • With AI service providers when you use AI features
  • When you explicitly share or collaborate with other users
  • With service providers who help us operate the platform (under strict confidentiality agreements) — see our Subprocessors page for the full list
  • When required by law or to protect our legal rights
  • In connection with a business transfer (merger, acquisition, etc.)

9. Data Security

We implement security measures appropriate for a cloud-based workspace service, including:

  • Data in Transit: Secure HTTPS connections for all web traffic
  • Authentication Security: Passwordless authentication eliminates credential-based attack vectors
  • Session Management: Opaque session tokens with proper expiration and validation
  • Secret Protection: AES-256-GCM encryption for OAuth tokens and stored integration credentials
  • Database Access: Restricted access controls with comprehensive logging of operations, errors, and security events
  • Input Validation: Comprehensive sanitization and validation of user inputs
  • Rate Limiting: Protection against abuse and excessive API usage
  • CSRF Protection: Built-in protection against cross-site request forgery

While we implement commercially reasonable security measures, no system is 100% secure. We encourage users to register passkeys on their devices, use secure email accounts, and follow good security practices. You are responsible for maintaining backups of critical data.

10. Your Rights and Control

Under GDPR and similar laws, you have the following rights over your personal data:

  • Access: All your data is accessible through the application interface
  • Modification (Rectification): Edit or update any content at any time
  • Deletion (Erasure): Delete individual items or your entire workspace
  • Export (Data Portability): Data export available by request - contact us for assistance
  • Restriction (Art 18): Request that we limit processing of your data in certain circumstances (e.g. while a dispute about accuracy is resolved)
  • Objection (Art 21): Object to processing based on legitimate interest, including for direct marketing purposes
  • Withdraw Consent (Art 7(3)): Where processing is based on consent (e.g. marketing emails), withdraw it at any time without affecting the lawfulness of processing before withdrawal
  • Complain to a supervisory authority (Art 13(2)(d)): You have the right to lodge a complaint with a data protection supervisory authority
TODO: name your supervisory authority if PageSpace is EU-established; otherwise state that this right applies to lodging a complaint with any EU Data Protection Authority (DPA), typically the one in the data subject's member state.

11. Automated Decision-Making

We do not make solely-automated decisions that produce legal effects concerning you or similarly significantly affect you (GDPR Art 22).

TODO: confirm no such use case currently exists in the product (e.g. automatic billing-suspension or account-lockout logic that acts without human review) — revisit this statement if one is introduced.

12. Children's Privacy

PageSpace is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, please contact us.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

14. Data Retention

We retain different categories of data for different lengths of time, depending on why we hold it:

  • Account and content data: retained while your account is active. Upon a deletion request, we complete erasure within 30 days (our internal Art 12(3) service-level target), except where we are required to retain specific records by law
  • Security and monitoring logs: retention varies by log type — API metrics, error logs, and AI-usage logs are kept for 90 days by default; system logs for 30 days; general user-activity logs for 180 days. Our tamper-evident security audit log and activity log are retained indefinitely because deleting entries would break the cryptographic hash chain that proves they haven't been altered — this is justified under GDPR Art 17(3)(b) as necessary for compliance with a legal obligation
  • Backups: retained separately from primary storage for disaster-recovery purposes
TODO: pull the exact backup retention day-count once it's documented — it is not currently codified alongside the other retention policies.

15. International Users and Data Processing

PageSpace is operated from the United States. If you are accessing our services from outside the United States, including from the European Economic Area (EEA) or United Kingdom, your information will be transferred to, stored, and processed in the United States.

Where we transfer personal data from the EEA or UK to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) as our transfer mechanism, rather than relying on your consent alone. Our subprocessors are listed on our Subprocessors page.

TODO: confirm which SCC Module is used for each vendor relationship, and confirm whether any transfers can instead rely on an adequacy decision (e.g. the UK's adequacy regulations) rather than SCCs.

16. Payment and Billing Information

When you purchase a subscription, payment processing is handled by Stripe, Inc. We do not store your credit card information on our servers. Stripe's privacy policy governs the collection and use of payment information.

We receive and store information about your subscription status, billing history, and usage metrics necessary for providing our services and managing your account.

17. Data Security Incidents

In the event of a personal data breach, we follow GDPR's two-part notification model:

  • We notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Art 33), unless the breach is unlikely to result in a risk to your rights and freedoms.
  • Where a breach is likely to result in a high risk to your rights and freedoms, we also communicate it to you directly, without undue delay, in clear and plain language (Art 34). This notification has no fixed hour deadline, but we aim to act as quickly as the circumstances allow.

Notifications will include information about the nature of the incident, the data affected, and the steps we are taking to address it.

18. Records of Processing Activities

A full Records of Processing Activities (RoPA) register is maintained internally per GDPR Art 30. GDPR does not require us to publish this register, so it is not reproduced here.

19. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at:

  • Email: hello@pagespace.ai
  • Support: Available through the in-app help system
  • Community: AI Agent Hub

For data protection requests (access, deletion, portability), please use the subject line "Data Protection Request" in your email.

Search

Search docs, blog posts, and more.