Plugin Privacy Notice for ChatGPT and Claude
Last updated: 4 October 2026
ChatGPT tools use the authorised platform handoff. Claude tools select files only inside our own PageJoy panel and never read files uploaded to the Claude chat. Server file copies follow the deletion rules below; hashed free-use records, account security and workspace records have separate lifetimes. The platforms handle their own information under separate terms.
1. Who provides the plugin
PageJoy provides the plugin at pagejoy.app. Our support and privacy contact is support@pagejoy.app.
This notice supplements our Privacy Notice, Terms of Service and Acceptable Use Policy. It applies to processing by our plugin server. Platform use is governed separately by the platform's terms.
2. How a file moves
2.1 ChatGPT
- You authorise a PageJoy operation through ChatGPT. A file supplied through ChatGPT may already be held by OpenAI.
- The authorised handoff sends the file and request information to our processing server where the operation requires it. The exact permissions and handoff are a free account connection before either chat uses a tool. Permissions identify the selected tool; your workspace role and plan must allow each action. ChatGPT uses an authorised attached-file handoff; Claude uses only our panel file picker.
- Our server completes the operation and returns the result through a download to your browser; no hosted temporary output link is used.
- Our stated design is to delete input and result copies received by our processing server immediately after returning the result. Section 4 covers failures and the verification required.
2.2 Claude
- You select a file only inside our own PageJoy panel.
- Our Claude tools never read, retrieve or extract files uploaded to the Claude chat. They do not query Claude chat history, memory or conversation summaries.
- The panel's local or server processing, file recipients and result delivery are files chosen in our panel are processed on your device. Our tools do not read files from the Claude chat or send these panel files to another recipient and a download to your browser. We do not automatically return file contents to Claude.
- If that operation sends file copies to our processing server, they follow section 4. A file selected in the panel is not automatically a file held by Anthropic; any result shared back to Claude must follow the disclosed, authorised result route.
Account connection and file processing are separate functions. A sign-in does not give a tool access to files beyond the permissions and file selection described above.
Website PDFs and photos are processed in your browser and are not uploaded to us. We do not use AI to process website files and do not train AI on customer files. Plugin processing is a separate flow.
A result shared back to ChatGPT or Claude may become part of information held by that platform. Copies you download are under your control. Deleting a copy on our server does not delete copies held by a platform or your device.
3. Information received and why
The file can contain personal information about you or other people. We use its contents to perform the requested file operation. The other request information we receive is selected tool and operation, OAuth account and scope, applicable workspace reference and authorised document fields or chosen file; no chat history or memory permission, used for verify account access and role, enforce the allowance, complete the requested operation and return its result. Section 2 distinguishes ChatGPT permissions and handoff from file selection in our own Claude panel. Account connection scopes are limited to the tool and any authorised Templates read or write action; they do not grant billing, account security, other-workspace files or chat history. Each execution must also check the current workspace role and entitlement.
A free account is required before using either ChatGPT or Claude. An account may also be created from a confirmed email for a free website download or when you pay. Sign-in uses Google, Microsoft, Apple where enabled, or email. We use Supabase Auth and our sign-in broker for identity, account sessions and security checks. Account information and saved Templates details in Business workspaces, whether free or paid, and paid Personal accounts are stored in our Supabase database. Ask support for information about the location relevant to your account. That stored information follows the main Privacy Notice rather than the immediate file-deletion rule.
3.1 Monthly free-use records
The free allowance is 3 uses per tool each month. In both ChatGPT and Claude, the monthly free-use count is tied to your free PageJoy account. We store a keyed account identity, the tool and UTC month association, completed-output identifiers to prevent duplicate counting, and pending reservations. We treat these as pseudonymous personal information. No anonymous ChatGPT quota identifier or anonymous ChatGPT permission is used. These records enforce the allowance of 3 completed uses per tool per month and are separate from file copies.
The exact tool, period and additional record fields for both platforms are a keyed account identity, tool, UTC month, completed-output identifiers and pending reservations; no anonymous ChatGPT subject record is needed. These records administer the free allowance; they are not file content and are outside the immediate file-deletion rule.
| Record | Why we keep it | How long we keep it |
|---|---|---|
| ChatGPT free account link, tool and month association and completed-output identifiers | Apply the free allowance to the same user and prevent duplicate counting | monthly account-linked records remain until the account is purged. Older monthly records do not expire automatically. Both platforms require a free account |
| Claude free account link, tool and month association and completed-output identifiers | Apply the free allowance to that account and prevent duplicate counting | monthly account-linked records remain until the account is purged. Older monthly records do not expire automatically. Both platforms require a free account; account-linked records follow the account purge rules in the main Privacy Notice |
Only successful completed outputs count towards the monthly free allowance. Failed work and duplicate completion receipts do not consume another use. Counts reset on the first day of each calendar month at 00:00 UTC, without rollover. Website counts transfer from the browser to the confirmed account; both chats use a free account. Older monthly records remain until the account is purged. Account deletion or a privacy request through Contact and Complaints can address those records. Clearing browser data removes the separate browser identity but does not delete server account records.
For these quota purposes we are the data controller. The stated legal basis is Article 6(1)(f), legitimate interests in administering the free allowance and preventing abuse, supported by only a pseudonymous browser or account key, tool, UTC month and output receipt are needed; file contents are excluded. You may object through Contact and Complaints. Our main Privacy Notice explains the relevant rights, security and transfers.
3.2 Connection security, bot checks and short limits
Cloudflare Turnstile checks protected sign-in actions. Its browser and verification data are disclosed in the main Privacy Notice and the Service Providers list. If the host cannot embed the check, sign-in uses our top-level page.
Our server processes a network address for request protection and stores a keyed rate identifier and request timestamps. Authenticated plugin requests have a limit of 30 requests in 1 minute for the network and account. It also applies the general 180-per-minute and path 60-per-minute limits, and a 20-per-minute network limit on token exchange. Account limits work across devices. These are short request limits, separate from the monthly free allowance.
Connected account authorisation codes expire after 60 seconds and work once. Access tokens last 5 minutes; refresh grants rotate and have a maximum 30-day validity unless revoked sooner. A revoked grant is refused on the next request. Revocation and token expiry do not themselves prove that every related database record has been erased.
Request timestamps outside the applicable minute, hour or day window are removed when the key is next used. Inactive hashed keys do not expire automatically. Account-linked session, callback and connection records are removed at account purge; expiry or revocation stops access but does not necessarily erase the record at the same time. The main Privacy Notice describes private account activity, optional 2-step sign-in, alert-email data and their separate retention. No authenticator seed, backup code, authentication token, raw platform identifier, user-linked security activity or file name belongs in public analytics or error reports.
Operational records contain a fixed operation or event, source, status and time. They exclude file contents, file names, signed links and raw platform identity from public telemetry. We use these records to diagnose failed requests and count successful outputs. Diagnostic records have no automatic deletion deadline and are not sent to an external error tracker or telemetry archive. Our company operates the Next.js server and Supabase database; no public chat file-processing service or processing queue is in use.
4. Deletion and failures
Our stated design is to delete input and result copies received by a separately authorised processing server immediately after returning the result. For the current Claude panel, files stay in memory until you clear them or close the panel; it has no server file-processing path. Results are downloads to your browser, without a hosted temporary output link. Section 2 describes the different file routes.
The immediate deletion promise concerns plugin input and result files received by that server. It does not delete the monthly free-use records in section 3.1, short rate records, your account security information, or a shared Business workspace document or activity entry separately saved under the main Privacy Notice.
If you request account deletion, you have seven days to cancel it in Account settings. The request revokes other browser sessions and connected-chat grants. After the deadline, your account is removed on the next successful cleanup; there is no fixed maximum time until completion. Cancellation does not restore revoked connections. Shared documents and activity remain until the workspace closes, with former-member identifiers minimised. Inactive hashed request-limit keys follow their separate retention rules. Personal receipts, account security records and account-linked ChatGPT quota are removed at account purge. These rules do not allow active credentials or all security history to be kept for ordinary use. Unlinked browser quota and hashed request-limit keys follow their separate retention rules and rights routes.
5. OpenAI and Anthropic copies
We do not control the platforms' storage, chat history, account settings, retention or use of information. Different platform products and settings can have different rules. To understand your platform's practices, read OpenAI's Privacy Policy and Anthropic's Privacy Policy. For Claude retention information, see Anthropic's retention explanation.
Our statement that we do not train AI on customer files describes PageJoy. It does not make that promise on behalf of OpenAI or Anthropic. Use their own controls and request routes for information they hold.
6. Use only files you are entitled to send
Make sure you have the right to use the file and disclose it to each actual recipient in the authorised route described in section 2. If it contains someone else's personal information, provide the notices, permissions and other legal basis required for your use. A platform's acceptance of a file does not establish those rights.
The types of information excluded from plugin processing are passwords, authentication secrets, complete card details, government identification, regulated health data, criminal-offence records and other sensitive data not required for ordinary business paperwork. The procedure for sensitive or regulated information, if permitted, is do not send sensitive or regulated information through the plugin; contact support about suitability without including that information.
Platform use also follows OpenAI Plugin Guidelines and Anthropic Software Directory Policy.
Our Platform and Research Sources page links to platform policies. Those links do not mean that a platform has approved our tools.
7. Business use and roles
For personal users, the applicable controller role and lawful basis for transient file processing are we control the personal account and requested task administration; necessary transient processing follows the requested service contract under Article 6(1)(b). For business files processed solely on a business customer's instructions, our role is processor where the addendum covers that operation. The Data Processing Addendum applies only where it has been made binding and its scope covers that operation.
Our company operates the database and has no external customer-data subprocessor for the current business processing scope. Any additional provider must be authorised under the addendum before receiving customer data. OpenAI and Anthropic operate separate platform services. The Service Providers list and DPA explain those roles.
Business workspace roles and sharing are explained in the main Privacy Notice. If a result is separately saved to a shared Templates workspace, that stored copy follows the workspace permissions and retention rules rather than the transient plugin file rule. Any such saving or sharing must follow an authorised customer's instruction and the disclosed flow.
8. Rights, transfers and complaints
For our processing, contact support@pagejoy.app or /legal/contact. Our main Privacy Notice explains applicable UK, EU and EEA, US, Canadian and Australian rights, representatives, overseas safeguards and complaint routes. Our file-deletion design means we may no longer hold a processed file when you ask about it. We still handle requests concerning account or other information we retain.
If we process data for a business customer, we help that customer respond to the request. For OpenAI or Anthropic copies, use the platform's own request route. You keep the privacy rights given by mandatory law in your country.
Customer records remain on a computer operated by our company. Any restricted provider transfer requires the applicable safeguards and assessment before it starts.
We acknowledge data protection complaints within 30 days, investigate without undue delay, keep you informed and explain the outcome. You may contact the competent regulator under the main Privacy Notice. UK complaints guidance.
9. Changes
We notify you of material plugin privacy changes using a dated notice on the relevant policy page and, for affected account users, an email before a material new processing purpose starts; any required permission is requested separately. Where a change needs consent or new permission, we obtain it before the changed processing starts.