Privacy Notice
Last updated: 4 October 2026
This notice explains how PageJoy handles personal information. Website PDF and Photo files stay on each person's device. ChatGPT and Claude use different file routes; account, free-use, security and shared workspace records have separate retention rules.
1. Who we are
PageJoy operates pagejoy.app and is the data controller for the purposes described below. Contact us at support@pagejoy.app about privacy or to exercise a right.
We decide how account, free-use counting, subscription administration, our service security and support information is used. For those purposes we are the data controller. When we process a business customer's shared business details, clients, items, Templates documents, document approvals and workspace activity records solely on its instructions, we act as its processor. The business customer is the controller, or an authorised processor for another controller. The Data Processing Addendum explains that arrangement. The business customer must provide required privacy information to its members, clients and other people whose information it uses.
Our privacy contact is use Contact and Complaints or write to the registered office. No separately named privacy officer or data protection officer is published. Our data protection officer details, if an officer is required or appointed, are use Contact and Complaints or write to the registered office. No separately named privacy officer or data protection officer is published.
2. Three different ways information is handled
2.1 Website files
PageJoy PDF and PageJoy Photo process PDFs and photos in your own browser. These files are not uploaded to us. We do not use AI to process website files. This statement concerns file processing. Account data, saved Templates details and information described below use separate flows.
Templates details saved in Personal mode while you are not signed in stay in your browser. Browser storage may be removed by your browser, device settings or by clearing website data. Save a copy of work you need to keep.
2.2 Saved invoice details and workspaces
Saved Templates documents, business details, clients, items and logos in Business workspaces, whether free or paid, and paid Personal accounts are stored in our Supabase database. Ask support for information about the location relevant to your account. Some of these details may identify other people. Their exact fields are business name, contact and address details, tax and payment details, logo, clients, saved items, document type and number, dates, line descriptions, quantities, prices, tax, currency, totals, notes, status, links, approvals and design preferences.
Personal and Business workspaces are available at the same prices. Business workspaces can have an Owner, Members and Viewers. The current member limit is 2; how the limit counts the Owner and other roles is two people in total, including the Owner and every Member or Viewer. A Business workspace's members share its business details, clients, items and Templates documents. The Owner can approve documents, remove members and change roles. There is a workspace activity log. PDF and Photo work remains on each person's device and is not shared through the Business workspace or uploaded to us through the website tools.
The role permissions, including which shared records each role can view, create, edit, approve, export or delete, are Owners manage billing, members, business details, approvals, exports, deletion and all shared records. Members create and edit shared records, submit documents and send only when approvals permit. Viewers read, download and export without editing or approving. Owners see all workspace activity; Viewers see document activity only. Roles never grant another person access to local PDF or Photo files. Membership record fields are workspace ID, user ID, email and role; invitation records also include intended email, role, status, token hash and expiry. Activity log fields, including which member and action are recorded and whether document or client details appear, are workspace ID, actor ID and email, action, optional document ID and timestamp; document approvals or requested changes can hold the review comment. The providers, storage regions and remote access locations for shared Templates documents and activity records are a computer operated by our company. Ask support for information about the location relevant to your account.
The business customer controls its shared business records; an individual member's account does not by itself make that person the controller of all workspace data. The Owner administers the workspace for that customer. Members should use workspace information only within their authorised role and for the customer's lawful purposes. A departing member's personal account records remain separate from the shared workspace records.
When membership ends, permission to access that Business workspace ends on the next server request. The personal account remains. Shared documents and activity remain with the workspace, and account purge replaces authorship with a former-member identifier. Removal does not itself instruct us to delete the business customer's shared records. Copies already downloaded or cached cannot be recalled; those copies require separate handling by the person and the business customer.
If the Owner cancels renewal, paid access continues to the end of the paid term. Cancellation is separate from deletion of the workspace or an individual account. What the Owner and members can access at the paid term's end, any export window, the treatment of shared documents and any later deletion are paid access lasts to the displayed end date. After that the free allowance applies and existing shared records remain accessible to authorised roles for viewing and export. Cancelling renewal does not delete the workspace. Export and deletion requests are handled through use Export workspace data while signed in to download JSON, and save needed Templates files or browser backups. The Owner can close the Business workspace after paid access ends; contact support for a return, deletion or ownership request. Section 7 explains the retention rules.
2.3 ChatGPT and Claude plugins
ChatGPT file tools require a free account connection and an authorised attached-file handoff. Permissions identify the selected tool; your workspace role and plan must allow each action. A file supplied through ChatGPT may already be held by OpenAI. When a supported operation sends it to our server, we process it for that operation and return the result.
Claude tools select files only inside our own PageJoy panel. They never read or retrieve files uploaded to the Claude chat. Files selected in the panel are processed on your device and returned as a browser download. We do not send these panel files to another recipient or automatically return their contents to Claude. A result you separately choose to share is then subject to the recipient's own handling.
For plugin input and result copies received by our processing server, our stated design is to delete those copies immediately after returning the result. We do not train AI on customer files. The sign-in security reference does not verify the product's file processing or deletion implementation.
OpenAI and Anthropic handle your chats under their own terms and privacy information. Our deletion does not delete their copies, your chat or a result you keep. Read our Plugin Privacy Notice before sending a file through a plugin.
In both ChatGPT and Claude, the monthly free-use count is tied to your free PageJoy account. We store a keyed account identity, the tool and UTC month association, completed-output identifiers to prevent duplicate counting, and pending reservations. We treat these as pseudonymous personal information. No anonymous ChatGPT quota identifier or anonymous ChatGPT permission is used. These records enforce the allowance of 3 completed uses per tool per month and are separate from file copies.
These quota records are separate from the files we delete immediately. Their retention and monthly reset are explained in section 7; clearing browser data does not delete a server account quota record.
2.4 Confirming an email for free downloads and marketing
Your first free website download, across any tool, is available without an email. From the second free download, you confirm your email with a six-digit code or a chosen sign-in provider on the same page. This creates a free account, transfers the browser count to it and keeps your open file and edits on your device. Both ChatGPT and Claude require a free account before the first use.
We keep the account ID, confirmed email, sign-in methods, browser-to-account count transfer, tool and UTC month, output receipt identifiers and pending reservations to deliver the download, apply the free allowance across devices and protect access. Account and account-linked free-use records remain until account purge after the seven-day cancellation window. Earlier monthly records do not automatically expire. File contents are not included in those records.
The box "Send me tips and offers from PageJoy" is unticked by default. We send marketing only to people who tick it. We keep the current marketing choice and its recorded date with the account until the choice is changed or the account is purged; we do not keep a separate archive of earlier marketing choices. Marketing is optional and does not affect free access. Stop it using the unsubscribe route in a marketing email, turning Product news off in Account notifications, or contacting support. Necessary sign-in codes, receipts and security alerts are separate from marketing.
3. Information, sources and purposes
No account is needed for your first free website download. From the second free download, you confirm an email on the same page, which creates a free account and transfers your browser count. Both ChatGPT and Claude require a free account before the first use. A free account does not authorise charges. Sign-in uses Google, Microsoft, Apple where enabled, or email. We use Supabase Auth for identity and our sign-in broker for account sessions and security checks. Account data is stored with a company-operated Supabase database in a computer operated by our company. Ask support for information about the location relevant to your account. The approved Supabase Auth deployment, provider contract and processing locations are in the Service Providers list. Apple private relay addresses are treated as the addresses you supply; we do not try to discover the real address behind them.
The Business workspace Owner pays for members on one subscription at $4.99 per person per month. We use the Owner's subscription information and the applicable member count to administer billing and paid access. The rule identifying which roles and people are billable is every role counts as one person, including the Owner and Viewers; the Owner pays for all people together. The payment fields we receive are checkout, event and receipt identifiers, workspace and Owner IDs, chosen plan, country, currency, quantity, amounts, status, consent time, business name and tax ID if supplied. We do not receive the full card number; the Subscription and Refund Terms explain member billing and changes.
| Information | Where it comes from | Why it is used |
|---|---|---|
| Account and sign-in information: account identifier, verified email, sign-in methods and account ID, verified email, linked provider and identity IDs, sign-in methods, optional name, workspace preference and notification settings; authentication tokens and security state stay on the server | You, Google, Microsoft or Apple if chosen, and Supabase Auth | Create and manage your account and provide access |
| Authentication challenges and sessions: challenge identifier and keyed code hash, purpose, expiry, wrong-try count, browser or session binding; session identifier, device type, last-active time, expiry, confirmed second-step state and server-held provider tokens | Your sign-in and security actions, browser and authentication providers | Verify codes, bind callbacks, manage sessions, stop replay and revoke access |
| Network and identity rate records: keyed network, account, browser identifier, action and request timestamps | Requests to our service | Apply short limits and prevent repeated or abusive requests |
| Account security activity: account identifier, event identifier, fixed event type and time, including sign-ins, known-account code failures and lockouts, sign-in method and second-step changes, invitations, revocations and deletion requests | Your account actions and security checks | Show your private account security history and investigate account protection issues |
| Optional 2-step information: encrypted authenticator seed, last accepted time step, keyed hashes of unused backup codes and setup expiry | Your optional authenticator setup and verification | Verify the second step, reject replay and allow single-use recovery codes |
| Security-alert and sign-in email data: recipient email, message type and time, code or invitation content where needed, and limited device information | Account and verification actions | Deliver codes, invitations and alerts about new devices, method or second-step changes, changed email and deletion requests or cancellation |
| Cloudflare Turnstile bot-check information: browser and challenge data and, verification, network address; the fields are browser, user-agent, network and challenge signals, site context, token and verification result. Cloudflare's notice explains its separate handling and retention | Your browser, Cloudflare's script and our verification request | Check that protected requests are legitimate and prevent abuse |
| Device approximate location | Not collected by an approximate-location lookup | We do not use this feature |
| Saved Templates details in free or paid Business workspaces and paid Personal accounts: business details, clients, items, logos and business name, contact and address details, tax and payment details, logo, clients, saved items, document type and number, dates, line descriptions, quantities, prices, tax, currency, totals, notes, status, links, approvals and design preferences | You or a person acting for your business | Save and retrieve your invoice work on your instructions |
| Shared Business workspace data, whether free or paid: business details, clients, items, Templates documents, approvals, workspace ID, user ID, email and role; invitation records also include intended email, role, status, token hash and expiry and workspace ID, actor ID and email, action, optional document ID and timestamp; document approvals or requested changes can hold the review comment | The business customer, its Owner and authorised members, and their workspace actions | Provide the shared workspace, apply role permissions, record approvals and show the customer's activity log on its instructions |
| Plugin files received by our processing server, the requested operation and selected tool and operation, OAuth account and scope, applicable workspace reference and authorised document fields or chosen file; no chat history or memory permission | Authorised ChatGPT handoff or selection inside our Claude panel, as applicable | Complete the requested operation and return its result |
| ChatGPT free-use record: free account link, tool and month association, completed-output identifiers and a keyed account identity, tool, UTC month, completed-output identifiers and pending reservations; no anonymous ChatGPT subject record is needed | Your PageJoy account and successful outputs | Apply the free allowance to the account and prevent duplicate counting |
| Claude free-use record: free account link, tool and month association, completed-output identifiers and a keyed account identity, tool, UTC month, completed-output identifiers and pending reservations; no anonymous ChatGPT subject record is needed | Your PageJoy account and successful outputs | Apply the free allowance to the account and prevent duplicate counting |
| Payment and subscription information we receive: checkout, event and receipt identifiers, workspace and Owner IDs, chosen plan, country, currency, quantity, amounts, status, consent time, business name and tax ID if supplied. We do not receive the full card number | Stripe Managed Payments and you | Match your payment to access, handle subscription administration and answer billing enquiries |
| Support and complaint information: your email, account or order reference if supplied, message, requested outcome and any safe sample you choose to send | You or your authorised representative | Answer questions, investigate complaints and fulfil rights requests |
| Service, security and error information: fixed event name or route, source, time, HTTP status and operational error code; private authentication and rate records are separate. File contents, file names and signed links are excluded | website requests, account sign-in and application events | operate requested functions, diagnose failures, count finished downloads and protect account access |
| Analytics information, only after you press Accept in the analytics banner: a random analytics ID, the page address, the event (page opened or download finished), the referring site, browser, device type and country; no file contents, file names, signed links or account secrets | sent to our third-party analytics providers, which may process it outside the UK under their data-processing terms; our own event counts go through our server with no network address and no location lookup | understand which pages and tools are used and where requested tasks fail |
3.1 Account security and short limits
Account security activity is private to the account. It is separate from the Business workspace activity log that the customer controls. Authenticator sign-in is optional and off by default. We keep its seed encrypted because it is needed to verify codes; backup codes are stored as keyed hashes, and a used backup code is removed. Setup expires after 10 minutes. Turning 2-step sign-in off removes its active seed and unused backup-code hashes from the account's active profile. The actual purge and backup rules are in section 7.
Sign-in codes are valid for 10 minutes, are consumed after a successful check and lock after five wrong tries. Fresh security proof lasts 5 minutes. Browser sessions have a maximum 30-day validity and can be revoked sooner. Plugin authorisation codes last 60 seconds and work once, access tokens last 5 minutes, and rotating refresh grants last at most 30 days unless revoked sooner. These validity periods are not promises that an expired database record has been erased.
Our security service applies network and, where relevant, account or hashed-identity limits across rolling windows. General and route limits use 1 minute; code requests also have a 1-minute cooldown and a 1-hour cap; contact and support share a 1-hour cap; Owner invitations also have a rolling 24-hour cap. The exact limits and their scope are explained on our Security page. A rate window limits which requests count towards that check. The separate retention period in section 7 controls when stored keys and timestamps must be purged.
Authentication codes, tokens, authenticator seeds, backup codes, raw platform identifiers, user-linked account activity and file names are excluded from public analytics and error reports. Account security emails use the selected email delivery provider. Browser memory may temporarily contain setup and verification information; our sign-in service stores none of it in localStorage, sessionStorage or IndexedDB. These secrets are excluded from public diagnostic logs.
You do not have to provide optional information. Without information necessary for sign-in, payment or a requested task, we cannot provide that part of the service. The fields that are mandatory and the effect of withholding them are a confirmed email and sign-in proof are needed from the second free website download and before either chat connection. A requested task needs its relevant fields; payment needs checkout details. Without them that function cannot proceed. Marketing consent is optional.
Do not send us a file through support unless it is needed to resolve your issue and you are entitled to disclose it. A file sent in an email is not covered by the website's browser-only processing statement. The support attachment procedure is describe the problem first. Send a redacted sample only when support requests it and explains a safe route. Do not send credentials, full card details or unnecessary client information.
For team enquiries submitted through Plans, we email your name, work email, company, team size and message to support@pagejoy.app and do not store this information on the website.
4. Why the law allows processing
UK GDPR and EU GDPR Article 6 require a lawful basis for personal information we control. The table lists a legal basis for each purpose. Processor activity follows the business customer's lawful instructions instead of relying on our account administration basis.
| Purpose | Legal basis | Limit |
|---|---|---|
| Provide an individual's account and requested paid service | Article 6(1)(b), performing the contract | Only information objectively needed for that contract |
| Administer a business customer's account and answer a business contact | Article 6(1)(f), legitimate interests in delivering and administering the service | A documented assessment must show those interests do not outweigh the person's rights |
| Keep user-linked monthly free-use counts | Article 6(1)(f), legitimate interests in administering the free allowance and preventing abuse | Necessity, minimisation and safeguards: only a pseudonymous browser or account key, tool, UTC month and output receipt are needed; file contents are excluded. You may object through Contact and Complaints |
| Meet legal recordkeeping and other mandatory duties | Article 6(1)(c), legal obligation | The specific duties are accounting, tax, authorised-payment, cancellation or claim records required by the law applying to your transaction |
| Protect the service and investigate issues | Article 6(1)(f), legitimate interests in protecting accounts and service access | Interests, necessity and safeguards: private keyed identifiers, short request windows and access checks protect accounts; no file contents or secrets enter public telemetry, and a concern can be reviewed by support |
| Optional analytics or optional communications, if used | consent: analytics runs only after you press Accept in the analytics banner, and tips and offers only if you tick that box | The permitted choices are the analytics banner, Analytics settings at the bottom of every page, the unticked tips-and-offers box and the Product news setting; no marketing is sent unless you choose it |
Where we rely on consent, you may withdraw it by turning Product news off in Account notifications, using the unsubscribe route in a marketing message or contacting support@pagejoy.app. Withdrawal does not end necessary account or security messages or undo lawful processing before withdrawal. We explain any resulting loss of an optional feature before you withdraw.
We have no advertising and do not sell personal data. Whether any provider disclosure falls within a statutory definition of sale, sharing or targeted advertising must also be checked.
Privacy information must describe purposes, recipients and retention under Articles 13 and 14. ICO guidance on privacy information. A legitimate interests assessment must support that basis. ICO legitimate interests guidance.
5. Who receives information
Our Service Providers list describes Stripe, including Link, Supabase Auth, Cloudflare Turnstile and our company-operated Supabase database. Cloudflare Workers is our current website hosting provider; its privacy policy and DPA describe its handling of information. Vercel is not in use today and receives no application records from this service. Resend sends every PageJoy email, including sign-in codes, security alerts and Business invitations, and receives the recipient's email address and the message. When a server error happens, Sentry receives a fixed error message, the time, whether it was the live or preview site and which part of the service failed; it receives no customer details and stores this in Germany. Analytics runs only after you press Accept, through our third-party analytics providers. Google, Microsoft and Apple where enabled are used for sign-in only. We do not use an approximate-location lookup service. Read the Service Providers list for the purposes, information and roles involved.
Cloudflare Turnstile receives browser and verification data for bot checks. Cloudflare also has independent purposes described in its Turnstile Privacy Addendum. The provider list records the applicable roles, locations and transfer safeguards.
Stripe Managed Payments provides the merchant of record arrangement for paid purchases and handles sales tax and VAT. The payment seller is shown at checkout and on your receipt. Stripe's independent payment processing is governed by its privacy information. The information shared with us is limited to checkout, event and receipt identifiers, workspace and Owner IDs, chosen plan, country, currency, quantity, amounts, status, consent time, business name and tax ID if supplied. We do not receive the full card number.
If a lawful demand requires disclosure, we verify the requester, authority and legal scope. We disclose only required information to the authority or person entitled to receive it, record the decision and notify the affected customer where lawful.
6. Countries and transfers
Our application records are stored on a computer operated by our company. Bot-check, payment and sign-in providers use their own infrastructure under their privacy notices. Ask support for the locations relevant to your account and use. A storage location does not establish where every provider or support worker can access information.
Any transfer subject to UK GDPR or EU GDPR Chapter V requires the applicable safeguards and assessment before it starts. This may be an applicable adequacy decision or regulation, or completed contractual safeguards with the required transfer assessment. You can ask support@pagejoy.app for information or a copy of relevant safeguards, subject to lawful redactions.
The UK rules also cover making information accessible to a separate overseas organisation. ICO international transfers guide.
7. How long information is kept
| Information | Period or event that ends storage |
|---|---|
| Website PDFs and photos | Not uploaded to us; local copies are controlled by your browser and device |
| Personal Templates details saved without sign-in | until you or your browser clear the saved data; no automatic expiry is set or earlier removal through your browser or clearing this site data in your browser settings |
| Account information | while the account exists and until deletion is completed after the seven-day cancellation window. We do not delete an account solely because it is inactive; account deletion has the 7-day cancellation window and purge procedure below |
| Saved Templates details in paid Personal accounts | until the authorised customer deletes records, closes the workspace or completes an applicable account purge. Older records do not expire automatically, and cancelling renewal does not erase them; deletion and export procedure: use Export workspace data while signed in to download JSON, and save needed Templates files or browser backups. The Owner can close the Business workspace after paid access ends; contact support for a return, deletion or ownership request |
| Shared Business workspace records and Templates documents, whether free or paid | Until the authorised customer deletes records, closes the workspace or completes an applicable account purge. Older records do not expire automatically. Removing membership ends shared access on the next server request; account purge replaces authorship with a former-member identifier. Cancelling renewal leaves records available to authorised roles for viewing and export. Use Export workspace data and save files you need; the Owner can close the workspace after paid access ends |
| Workspace activity log and approval entries | until the workspace is closed. Account deletion replaces the former member's identity with a minimised identifier. Older entries do not expire automatically |
| ChatGPT account-linked monthly free-use records, including completed-output identifiers | monthly account-linked records remain until the account is purged. Older monthly records do not expire automatically. Both platforms require a free account; deletion request method: Account settings account deletion, or a privacy request through Contact and Complaints; clear site data for the separate browser identity |
| Claude account-linked monthly free-use records, including completed-output identifiers | monthly account-linked records remain until the account is purged. Older monthly records do not expire automatically. Both platforms require a free account; remove account-linked usage when the account is purged unless a specifically approved exception applies |
| Authentication challenges, sessions, callback state and connected-plugin grants | account-linked records are removed when the account is purged. Codes, callbacks, sessions and grants stop working at expiry or revocation. Expired records are not necessarily erased at the same time; validity and revocation periods are in section 3.1 |
| Network and identity rate-limit keys and timestamps | timestamps outside the applicable minute, hour or day window are removed when that key is next used. Inactive hashed keys do not expire automatically |
| Private account security activity | for the account lifetime, then erased when the account is purged. Earlier activity does not expire automatically |
| Authenticator seeds, setup records, replay state and backup-code hashes | encrypted active factors remain until disabled or the account is purged. Used backup hashes are removed immediately. Setup stops working after ten minutes; expiry does not itself erase an unused setup record |
| Security-alert, code and invitation delivery records and queued messages | delivered messages are removed from the delivery queue; pending account messages are removed at account purge. Copies held by our email service remain until its operator deletes them |
| Cloudflare Turnstile verification and bot-check records | verification tokens last up to five minutes and work once. We keep no separate bot-result archive. Private request-limit and security records follow their own retention rules; Cloudflare's independent processing follows its own notice and applicable rights |
| Device and rough-location records, if used | not used; no approximate-location lookup is enabled |
| Plugin input and result files on our server | Deleted immediately after the result is returned; failure handling: panel file copies stay in memory until you clear the files or close the panel. We do not operate a server file-processing path for this panel |
| Payment and mandatory records held by us | payment and receipt records remain until personal-account purge or workspace closure. Stripe keeps its own records under its separate legal duties, reflecting accounting, tax, authorised-payment, cancellation or claim records required by the law applying to your transaction |
| Support, complaints and rights requests | until the request and any related complaint, refund or rights issue is resolved and the records are no longer needed |
| Technical and error information | diagnostic records have no automatic deletion deadline. No external error tracker or telemetry archive receives these records |
| Analytics information | kept by our third-party analytics providers under their own retention settings; we keep no separate copy. The random analytics ID in your browser stays until you press Reject or clear your browser storage |
| Backups of stored account or invoice data, if used | no company-managed backup is made. Exports you download remain on your device until you remove them; account deletion cannot remove those copies |
Only completed outputs count towards the free allowance for each tool in a UTC calendar month. Failed work and duplicate completion receipts do not consume another use. Counts reset on the first day of each calendar month at 00:00 UTC, without rollover. Website counts transfer from the browser to the confirmed account; both chats use a free account. Earlier monthly account records remain until account purge. Immediate plugin file deletion does not apply to these counts, account records, shared workspace documents or activity logs.
7.1 Account deletion and the 7-day cancellation window
After you confirm an account deletion request with a fresh email code, we set a deadline 7 days later. You can cancel the request in Account settings before that deadline. The request revokes other browser sessions and connected-chat grants; the current account session remains available for reviewing or cancelling the request. Cancellation removes the scheduled deadline but does not restore previously revoked sessions or plugin connections. Access during that window is as follows: the requesting session may use Account settings and its existing authorised product access before the deadline; other sessions and chat grants are revoked. All ordinary account access ends at the deadline. We do not purge the account before the 7-day deadline.
After the seven-day deadline, the account is removed on the next successful cleanup. There is no fixed maximum time between the deadline and completed cleanup. The purge covers private account data, the authentication profile and factors, sessions, chat grants, account-linked quota records, private activity, challenges, invitations, pending notices and the individual's product data we control. Shared Business records follow the business customer's instructions and the Data Processing Addendum. Deleting a member's account ends their authority and minimises their identity in shared records; it does not give them authority to erase the whole workspace. Downloaded or cached copies cannot be recalled.
Shared documents and activity remain until the workspace closes, with former-member identifiers minimised. Inactive hashed request-limit keys follow their separate retention rules. Personal receipts and account security records are removed at account purge. Only records needed for a specific lawful purpose, such as a payment, tax duty, claim or narrowly justified security need, may be retained under that purpose and its applicable period. This does not allow active credentials, all security history or file copies to be kept for ordinary use. Stripe's separate records follow its legal duties and privacy information; deleting our account does not delete Stripe's records.
Account deletion removes ChatGPT account-linked quota records. Unlinked browser quota and hashed request-limit keys follow their separate retention rules and rights routes. We do not make company-managed backups. Exports you download remain on your device until you remove them, and account deletion cannot recall them. Deleted data must not be restored to active use. Account deletion, paid renewal cancellation, workspace deletion and a statutory erasure request are different actions. Contact support@pagejoy.app to exercise a privacy right; the cancellation window does not delay a legal deadline or remove an applicable right.
8. Security and decisions
We check sessions on protected server requests, use one-use email codes, offer optional authenticator sign-in, encrypt private account security records and enforce workspace roles and request limits on the server. We do not claim an independent security certification. Read the Security page for further details and how to report an issue.
We do not train AI on customer files and do not use AI to process website files. Automated quota counting, payment processing and sign-in are separate from those statements. Information about any automated decisions with legal or similarly significant effects is quota and request limits can automatically refuse a request; they do not decide credit, employment or legal status. Contact support to ask for a review of an access refusal.
9. Your rights and requests
Email support@pagejoy.app or use /legal/contact. Tell us which information or use your request concerns. We may ask for proportionate information to verify identity or an agent's authority. We do not require more information than needed for that check. You do not need a paid account to make a request.
Where UK GDPR or EU GDPR applies, rights include access, correction, erasure, restriction, portability where its conditions apply, and objection to processing based on legitimate interests. You may object to direct marketing at any time. Rights have legal limits. If a limit applies, we explain our decision and the available challenge route. We respond within the applicable legal deadline, normally one month for UK and EU GDPR requests, with lawful extensions or adjustments explained to you.
Where we hold information only as a processor for a business, we help that business respond to your request. We may direct you to it rather than decide the request ourselves. We cannot retrieve website file content that was never uploaded to us.
9.1 United States
Where a state privacy law covers our processing and your request, you may have rights to access, obtain a portable copy, correct, delete, opt out of sale, targeted advertising or certain profiling, and appeal a refused request. Some laws also give rights to recipient lists or to question profiling. Rights differ between states. We do not retaliate against you for exercising a legal privacy right. A request or appeal can be sent to support@pagejoy.app or /legal/contact. The appeal procedure and regulator contact for your state are send an appeal through Contact and Complaints, identifying the decision and your state. We explain the review outcome and the relevant state Attorney General or privacy regulator route where your law requires it.
Where California's response rules apply, requests to know, correct or delete normally receive a response within 45 days, with a permitted further 45 days when needed and explained. Many other state laws use a 45-day starting deadline, subject to their own rules. Iowa uses 90 days, with a permitted further 45 days when needed and explained. We follow the deadline for your request, including any shorter opt-out deadline. CCPA request regulations, Iowa Code section 715D.3, Utah response guidance.
California rights, where the CCPA applies, include knowing categories and specific information, correction, deletion, portability and applicable sale, sharing and sensitive-information controls. The CCPA has scope tests. The current adjusted revenue figure is $26,625,000, alongside separate volume and sale or sharing revenue tests. CPPA scope FAQ, current monetary thresholds.
Our California category and disclosure information for the preceding 12 months is described in sections 3, 5 and 7, including sources, purposes, recipients and retention. We do not sell personal information or use it for advertising. File contents may include categories beyond the account information described there.
Global Privacy Control and other legally recognised preference signals are handled as follows: we do not sell personal information or use advertising or optional cross-site tracking. This signal does not change account preferences.
Other state tests differ. Colorado has consumer-volume and sale-related tests. Texas generally exempts businesses that qualify as small under federal SBA standards, with an exception for selling sensitive information. Connecticut includes sensitive-data processing as a separate scope trigger. Colorado privacy law, Texas privacy law, Connecticut privacy law.
CalOPPA can require a commercial website privacy notice even when the CCPA's scale tests are not met. If your browser sends a Do Not Track signal, analytics does not run. We use no advertising and no cross-site analytics. Site analytics runs only after you press Accept. Third-party collection across services through our website, if any, is no advertising software is used. Sign-in, payment and bot-check providers operate separate services under their own privacy notices. California Attorney General explanation of CalOPPA.
Health-file processing can need separate controls under the Washington Attorney General's health privacy guidance and Nevada Revised Statutes chapter 603A.
9.2 Canada
Where PIPEDA applies, you may request access and correction and challenge our handling of your information. We normally respond to an access request within 30 days and explain any lawful refusal or extension. Where consent is required, we seek meaningful consent and explain optional choices. You may withdraw consent subject to lawful restrictions, with the consequences explained. Canadian consent guidance, access and correction guidance.
Provincial laws may also apply. Where Quebec's private-sector law applies, you may request access and correction. You may also request qualifying computerised information collected from you in a commonly used structured format, or its transfer to an authorised recipient, subject to statutory limits. Where a decision is made entirely by automated processing, applicable rights include information about the decision and an opportunity to seek review by a person. There are also conditional rights concerning cessation of dissemination and de-indexing. These are not an unrestricted right to delete every record. Quebec rights guidance.
Contact us with your location so we can identify the mandatory privacy rights and request route that apply to you. For Quebec privacy questions, use Contact and Complaints or write to our registered office. No separately named privacy officer or data protection officer is published.
Quebec requires extra information for identification, location or profiling technologies, and assessments for relevant transfers outside Quebec. Quebec collection guidance, Quebec transfer guidance.
9.3 Australia
Where the Privacy Act 1988 and Australian Privacy Principles apply, you may seek access, correction and make a privacy complaint. Overseas recipient countries are listed in section 6 and the Service Providers list. OAIC rights guidance.
Coverage depends on the business and activity, including its Australian connection. OAIC small-business guidance, OAIC Australian-link guidance.
9.4 Other countries
You keep the privacy rights that mandatory law gives you where you live. Tell us your location if it helps us identify the law, request route and regulator that apply.
10. Representatives, children and complaints
EU and EEA representative, where required: no EU or EEA representative has been appointed. Contact our UK company through the details above. A UK representative is not appointed; the service provider is the UK company identified above.
The two representative tests are separate. ICO guidance on EU and UK representatives.
The service is intended for adults aged 18 or over. We do not verify age or offer a parental-consent process. Contact us if a child has supplied account information.
Complain to support@pagejoy.app. We acknowledge a data protection complaint within 30 days. We investigate without undue delay, keep you informed and explain the outcome. This is a duty under the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025. Current complaints guidance.
You can also contact your competent regulator. In the UK this is the Information Commission, successor to the ICO, through ico.org.uk. In the EU or EEA you may complain to the authority for your habitual residence, work or the alleged infringement. In Canada the relevant body may be the Office of the Privacy Commissioner of Canada or a provincial regulator. In Australia it may be the OAIC, normally after raising the matter with us and allowing a reasonable response period. Statutory court and regulator rights remain available.
11. Changes
We update this notice when our processing or legal duties change. For a material change we give notice through a dated notice on the relevant policy page and, for affected account users, an email before a material new processing purpose starts; any required permission is requested separately before new processing starts where required. We obtain new consent where the law requires it. The date above identifies the current version.