Cookie and Browser Storage Notice
Last updated: 4 October 2026
PageJoy uses cookies for sign-in and free-use identity, browser storage for saved work, and Cloudflare Turnstile for bot checks. This notice explains the technologies, their purposes and your choices.
1. Who operates the service
PageJoy operates pagejoy.app. Contact support@pagejoy.app about this notice. Our Privacy Notice explains how personal information is handled.
2. Storage is wider than cookies
A cookie stores information on a device and may send it with later web requests. Local storage, session storage and browser databases can also keep information in your browser. Scripts can read device information without creating a cookie.
Cookie-free does not automatically mean consent-free. UK Privacy and Electronic Communications Regulations 2003, regulation 6, can apply to storing or accessing information on a device, whether or not it is personal information. UK GDPR also applies where personal information is processed. ICO storage and access guidance.
3. What is used
We have no advertising. Analytics runs only if you press Accept in the analytics banner: our third-party analytics providers then count visits, the pages you open and the downloads you finish. You can press Reject, or change your choice any time under Analytics settings at the bottom of every page. The rows below describe sign-in cookies, free-use storage, saved work, payment screens and third-party services.
| Purpose | Technology and exact keys or names | What is stored or accessed | Provider and who can read it | Duration | Consent or exception |
|---|---|---|---|---|---|
| Keep an account session | Cookie __Host-session on HTTPS; session on HTTP | Opaque session handle; account authentication tokens remain on the server | PageJoy account broker; HttpOnly, SameSite=Lax, Secure on HTTPS; root path; the host-prefixed cookie has no Domain | 30 days; a successful refresh rotates the handle and refreshes its cookie expiry; server revocation can end access sooner | Used to provide the signed-in service you request |
| Identify a browser for free-use counting and bind email-code or provider flows | Cookie browser | Random browser identity; count and code-binding records are server-side | PageJoy account broker; HttpOnly, SameSite=Lax, Secure on HTTPS | 365 days | Used for free-use counting and sign-in code binding |
| Bind an external sign-in return to the browser that started it | Cookie provider_flow | Opaque provider-flow reference | PageJoy account broker; HttpOnly, SameSite=Lax, Secure on HTTPS | 5 minutes; removed on successful callback | Used for the provider sign-in you request |
| Display the website free allowance | localStorage account-use:pdf, account-use:templates and account-use:photo; the browser identity cookie is listed separately | UTC month and remaining allowance, with no file contents | the site script and people with access to the browser profile; the server checks the actual quota separately | until overwritten by a later count or cleared by you or your browser | used to display the free allowance you request |
| Keep Personal Templates details and saved browser work while you are not signed in | IndexedDB database document-templates-v1, object store state, key workspace | business details, logo, clients, saved items, designs, documents, revisions, counters and preferences | the Templates application on this site and anyone with access to the same browser profile; a backup is shared only when you export it | until you or your browser clear the saved data; no automatic expiry is set | storage for the saved work you request |
| Cloudflare Turnstile bot checks | External script and challenge frame at challenges.cloudflare.com; actual device access and cookies: Cloudflare challenge script and frame. Cloudflare's storage notice describes any additional device storage | Browser and network signals, site context and verification result | Cloudflare and PageJoy verification endpoint | Turnstile verification token: up to 5 minutes and one validation; signal, device-storage and any cookie lifetimes: verification tokens last five minutes; Cloudflare's notice describes its separate device storage and retention | bot protection; Cloudflare's notice explains its separate purposes and choices |
| Count use, only after you press Accept | localStorage pagejoy-analytics-id; a visit-counting script that uses no cookies or browser storage | a random analytics ID; sent: that ID, the page address, the event (page opened or download finished), the referring site, browser, device type and country; never file contents, file names, signed links or account secrets | our third-party analytics providers; our own event counts go through our server with no network address and no location lookup | the ID stays until you press Reject, clear your browser storage or change your choice | consent: nothing runs until you press Accept |
| Remember your analytics choice | localStorage pagejoy-analytics-consent | yes or no, so the banner does not come back; marketing choices and their recorded date stay with the account | the site script and people with access to the browser profile | until you change your choice or clear your browser storage | needed to remember the choice you made |
| Stripe checkout and Link | no Stripe or Link storage is used by this website. Storage on a hosted payment screen follows the notice shown there | no Stripe or Link storage is used by this website. Storage on a hosted payment screen follows the notice shown there | Stripe and no Stripe or Link storage is used by this website. Storage on a hosted payment screen follows the notice shown there | no Stripe or Link storage is used by this website. Storage on a hosted payment screen follows the notice shown there | no Stripe or Link storage is used by this website. Storage on a hosted payment screen follows the notice shown there |
| Google or Apple sign-in, when selected | our provider_flow callback cookie. Each sign-in provider controls storage on its own domain | an opaque callback reference on our site; provider credentials stay with the provider and server-held tokens stay on the broker | Google or Apple and our account broker for its callback cookie; each sign-in provider controls its own domain storage | our callback cookie lasts five minutes and is removed on successful sign-in. Provider-domain storage follows the provider's notice | our callback cookie serves the sign-in you request; storage on a provider's domain follows its separate notice |
| Other hosting, email or error service device access, if present | none; hosting, email and error services do not add device storage on our website | none; hosting, email and error services do not add device storage on our website | none; hosting, email and error services do not add device storage on our website | none; hosting, email and error services do not add device storage on our website | none; hosting, email and error services do not add device storage on our website |
Cookie lifetimes describe browser persistence. They do not set how long the associated server record, count, security event or provider data is retained. The Privacy Notice sets out the separate retention schedule. The session broker checks the server session on protected requests, so a revoked session must stop working even if its old cookie is still in the browser.
The sign-in implementation does not put account authentication tokens, email codes, authenticator seeds, backup codes or file names into localStorage, sessionStorage or IndexedDB. Values needed by a screen stay in page memory; sensitive retained server state is encrypted. Supabase PKCE state is held in a server-side map within that encrypted state. Saved Templates work uses the separate browser storage described above.
Turnstile is a third-party bot check, not a data-free operation. Its verification token lasts up to 5 minutes and works once. Cloudflare token validation. Turnstile pre-clearance can add a cf_clearance cookie; it is disabled by default and its lifetime depends on the selected configuration. Cloudflare's notice explains its separate handling of device information. Cloudflare clearance documentation.
4. Essential storage and optional purposes
Some storage may be essential to deliver the service you request. For example, maintaining an authenticated session may qualify. Each use must satisfy the legal test. A use is not essential simply because it helps our business.
The free-use limit is a commercial rule. Its browser identity cookie and any other storage mechanism need an individual assessment. Saved work also needs an assessment of whether you requested that storage and how long it persists. Turnstile device access must be assessed against the actual deployment and local law, including the provider's separate purposes. When invisible mode is enabled, Cloudflare requires a reference to its Turnstile Privacy Addendum in our Privacy Notice. Cloudflare widget documentation.
For UK users, PECR as amended by the Data (Use and Access) Act 2025 contains a narrow statistical-purpose exception. Its conditions include clear information, a free easy objection route, improvement of the service as the sole purpose, aggregate results that cannot identify people and limits on further use. A third-party provider must act on our behalf for this purpose. The separate appearance exception also has conditions and an objection requirement. Current ICO exceptions guidance.
These UK amendments are in force. They do not create a worldwide analytics exemption. EU and EEA rules arise under national laws implementing ePrivacy Directive 2002/58/EC Article 5(3), and exemptions differ between countries. ICO DUAA commencement overview, EDPB technical-scope guidance.
5. Make or change a choice
Our privacy controls are in Account, then Notifications. The controls let you turn product news on or off. Analytics uses no cookies. Where we ask for consent, optional storage or access starts only after you agree. You can refuse optional purposes and withdraw consent as easily as you gave it. Where we rely on an exception requiring an objection route, you can object free of charge using our Contact and Complaints page at /legal/contact. Analytics runs only after you press Accept, and you can change this any time under Analytics settings at the bottom of every page.
You can also manage or clear website data in your browser. Clearing it can remove locally saved invoice details and work, privacy choices and sign-in state. Blocking storage needed for a requested function may stop that function working. Clearing the browser cookie resets the anonymous browser identity and can reset browser-based free-use counting. Network limits and Turnstile checks still apply. Blocking the session cookie prevents account access, and losing provider_flow can stop a sign-in return from being accepted. Other effects of clearing site storage are as follows: clearing IndexedDB removes saved Templates work; clearing account-use keys removes the displayed count but does not erase the server account count. Export a backup before clearing saved work. Save needed work first.
Deleting browser data does not delete saved Templates details held in our Supabase database for Business workspaces, whether free or paid, or paid Personal accounts. Request account-data deletion using use Export workspace data while signed in to download JSON, and save needed Templates files or browser backups. The Owner can close the Business workspace after paid access ends; contact support for a return, deletion or ownership request or contact support@pagejoy.app.
Clearing browser data also does not delete shared Business workspace records or the server-side plugin free-use records described in section 7. Workspace export and deletion requests use use Export workspace data while signed in to download JSON, and save needed Templates files or browser backups. The Owner can close the Business workspace after paid access ends; contact support for a return, deletion or ownership request.
6. Browser privacy signals
Global Privacy Control and other recognised opt-out signals are handled as described in the Privacy Notice: we do not sell personal information or use advertising or optional cross-site tracking. This signal does not change account preferences. A signal's legal scope can differ from a cookie consent choice. Colorado recognises Global Privacy Control as a universal opt-out mechanism. Colorado official signal guidance.
7. Separate platforms
ChatGPT and Claude have their own websites, apps, storage and privacy settings. This inventory describes PageJoy's website and embedded flows within our control. The Plugin Privacy Notice explains the different ChatGPT and Claude panel routes, their recipients and relevant retention.
In both ChatGPT and Claude, the monthly free-use count is tied to your free PageJoy account. We store a keyed account identity, the tool and UTC month association, completed-output identifiers to prevent duplicate counting, and pending reservations. We treat these as pseudonymous personal information. No anonymous ChatGPT quota identifier or anonymous ChatGPT permission is used. These records enforce the allowance of 3 completed uses per tool per month and are separate from file copies. These records have separate retention rules in the Plugin Privacy Notice. The monthly reset does not itself delete past counts. Any separate device storage for sign-in or plugin access must still be included in the inventory above where it is within our control. Embedded panels use the host OAuth connection and must not depend on third-party account cookies. Claude file selection is inside our panel; the tools must not read files uploaded to the Claude chat. File-handling and retention details are in the Plugin Privacy Notice.
8. Changes and questions
We update this notice when the inventory or purposes change. Material changes and any new consent requests are communicated through a dated notice on the relevant policy page and, for affected account users, an email before a material new processing purpose starts; any required permission is requested separately. Contact support@pagejoy.app for an accessible explanation or help with choices.