Security
Last updated: 4 October 2026
This page explains where your files are processed and how to report a security issue. It describes our security measures and the limits of the assessments carried out.
1. Who provides the service
PageJoy operates pagejoy.app. Contact support at support@pagejoy.app.
2. Files processed on our website
When you use our website, PDFs and photos are processed in your own browser. They are not uploaded to us for processing. We do not use AI to process files on the website. We do not train any AI on customer files.
The website uses cookies for the account session, anonymous browser identity used for free counting and code binding, and the short provider sign-in callback state. Their names, purposes and lifetimes are in the Cookie and Browser Storage Notice. Our sign-in service does not put account tokens, codes, authenticator seeds, backup codes or file names in localStorage, sessionStorage or IndexedDB. Templates details saved in Personal mode while you are not signed in stay in your browser. Browser storage is part of the device you use. People who can access that browser profile may be able to access information saved there. You can clear it through your browser settings, but this may remove your saved work or sign-in information.
Keep your original file and check the result before using it. In particular, check that a redacted file does not reveal the information you intended to remove, and check the text produced from a scan. Password protection and redaction work on the file you choose. They do not change copies held elsewhere.
3. Files processed through ChatGPT and Claude
ChatGPT file operations use the authorised platform handoff described in the Plugin Privacy Notice. Files supplied through ChatGPT may already be held by OpenAI. When an operation sends copies to our processing server, our stated design is to return the result and delete those server copies immediately.
Claude selects files only inside our own PageJoy panel. Its tools never read, retrieve or extract files uploaded to the Claude chat. Files chosen in the panel are processed on your device, and the result is a download to your browser. We do not automatically return file contents to Claude or send these panel files to another recipient. A separately authorised server-processing operation follows its own disclosed file-handling and deletion rules.
The platform's own treatment of your chats and any file or result it receives follows its separate terms and privacy information. A panel selection does not by itself establish that Anthropic receives the file.
For more information, read the Plugin Privacy Notice for ChatGPT and Claude. Do not treat deletion from our server as deletion from OpenAI, Anthropic or your device.
4. Accounts, saved information and payments
No account is needed for your first free website download. From the second free download, you confirm an email on the same page, which creates a free account and transfers your browser count. Both ChatGPT and Claude require a free account before the first use. A free account does not authorise charges. Sign-in is available through Google, Microsoft, Apple where enabled, or email, using Supabase Auth and our security broker. Cloudflare Turnstile checks protected requests for bots. The actual providers, deployment regions and roles are recorded in our Service Providers list. Apple private relay registration supports delivery to a relay address; it does not authorise identifying the address behind it.
Account data and saved Templates documents, business details, clients, items and logos in Business workspaces, whether free or paid, and paid Personal accounts are stored in our Supabase database. Ask support for information about the location relevant to your account. Our Service Providers list explains the providers' roles.
Paid plans use Stripe Managed Payments. Stripe acts as merchant of record and handles sales tax and VAT. Read the Subscription and Refund Terms for the purchase and cancellation arrangements. Stripe and Link have their own payment and privacy terms.
5. Our security measures
We check sessions on protected server requests, use one-use email codes, offer optional authenticator sign-in, encrypt private account security records and enforce workspace roles and request limits on the server. We do not claim an independent security certification or a complete independent security assessment. Authentication and workspace checks do not establish that the complete service is free of security risks.
5.1 Sign-in and private account security
Email sign-in codes last 10 minutes, work once and lock after five wrong attempts. Resending invalidates the earlier code. The server keeps a keyed hash of the code, its purpose, expiry, wrong-try count and browser or session binding. Sensitive account changes require fresh proof within 5 minutes.
The browser holds an opaque HttpOnly session cookie, valid for at most 30 days, with SameSite=Lax and Secure on HTTPS. HTTPS sessions use the __Host-session cookie. The broker checks the server record for each protected request, so revocation takes effect immediately even if an old cookie remains in the browser. Provider access and refresh tokens and callback state stay in the server's encrypted private state.
Authenticator 2-step sign-in is optional and off by default. Setup expires after 10 minutes and must be confirmed before the factor is enabled. We store the authenticator seed encrypted because it is needed to check codes, the last accepted time step to prevent replay, and keyed hashes of 10 single-use backup codes. A used backup hash is removed. Turning the factor off removes its active seed and unused backup hashes. A newly signed-in session cannot read protected account data until the enabled second step succeeds. These checks apply before protected account access is allowed.
Account security activity is private to that account. Its record contains an account and event identifier, fixed event type and timestamp. Events include sign-ins, failures or lockouts for known accounts, method and second-step changes, invitations, session or connection revocation and deletion requests. It is separate from the customer's Business workspace activity log. Device rows show device type and last-active time. We do not use an approximate-location lookup for devices.
Security and verification emails use the recipient address, message type and time, and the code, invite link or limited device information needed for that message. Alerts cover a new device, sign-in method added or removed, 2-step sign-in turned on or off, changed email, and deletion requested or cancelled. No code, token, seed, backup code, raw ChatGPT identifier, user-linked account activity or file name belongs in analytics or error reports. Diagnostic logs contain only fixed event names and status numbers.
5.2 Bot checks, pseudonymous counting and rate windows
Cloudflare Turnstile receives browser and challenge data and, in production verification, the network address. A third-party bot check is not data-free. Its applicable provider roles, locations and contracts are in the Service Providers list. The Cookie and Browser Storage Notice explains its device access.
In both ChatGPT and Claude, the monthly free-use count is tied to your free PageJoy account. We store a keyed account identity, the tool and UTC month association, completed-output identifiers to prevent duplicate counting, and pending reservations. We treat these as pseudonymous personal information. No anonymous ChatGPT quota identifier or anonymous ChatGPT permission is used. These records enforce the allowance of 3 completed uses per tool per month and are separate from file copies. Failed work does not use another free allowance. The account identity does not grant access to a customer workspace.
We apply these rolling limits. Limits may operate together, so passing one does not bypass another.
| Check | Request limit | Scope |
|---|---|---|
| All routes | 180 requests in 1 minute | Network and, for signed-in requests, account across devices |
| Each route path | 60 requests in 1 minute | Network and, for signed-in requests, account across devices |
| Email code request route | 20 requests in 1 minute | Network |
| Sending an email code | At least 1 minute between requests and at most 5 in 1 hour | Both the email and the network |
| Email code check | 30 requests in 1 minute | Network |
| Google or Apple sign-in start | 10 requests in 1 minute | Network |
| Authenticator setup confirmation or verification | 5 attempts in 1 minute | Network and account |
| Owner invitation | 10 requests in 1 minute and 20 in a rolling 24 hours | Network and account for the minute limit; Owner for the daily limit |
| Contact and support | Shared cap of 3 requests in 1 hour | Network |
| Website free-use completion | 20 requests in 1 minute | Network and account or browser identity |
| Authenticated plugin operations | 30 requests in 1 minute | Network and account |
| Plugin token exchange | 20 requests in 1 minute | Network |
Network identifiers and request-limit keys are derived with a server-held key. Request timestamps remain private security data. We do not use an approximate-location lookup for devices.
Connected-plugin authorisation codes are valid for 60 seconds and work once. Opaque access tokens last 5 minutes. Refresh grants rotate and have a maximum 30-day validity unless revoked sooner. A revoked connection is refused on the next request. Each actual tool must also verify role, approval and entitlement for the operation.
Request windows and expiry times govern access, rather than when every record is erased. Timestamps outside the applicable window are removed when a key is next used; inactive hashed keys do not expire automatically. Account-linked challenge, session and connection records are removed at account purge. Private account activity remains for the account lifetime. Encrypted active authenticator factors remain until disabled or the account is purged, and used backup hashes are removed immediately. An expired setup record is not necessarily erased at the same time. Delivered messages leave the delivery queue, pending account messages are removed at purge, and copies held by our email service remain until its operator deletes them. The Privacy Notice explains these periods and your request rights.
5.3 Account deletion
Account deletion requires a separate fresh email code and sets a deadline 7 days later. You may cancel it in Account settings before that deadline. The request revokes other browser sessions and connected-chat grants; the current session remains available for reviewing or cancelling the request. Cancellation does not restore revoked sessions or connections. Other product access during that window follows the requesting session may use Account settings and its existing authorised product access before the deadline; other sessions and chat grants are revoked. All ordinary account access ends at the deadline.
After the deadline, the purge must complete within the next successful account cleanup after the seven-day cancellation window. There is no fixed maximum time between the deadline and completed cleanup. It removes the individual's account profile, factors, sessions, grants, private account activity, challenges, invitations, pending notices, account-linked usage and product data within the approved scope. Shared Business records follow the business customer's instructions and the DPA. Account deletion does not automatically identify unlinked browser quota or hashed network-rate records; separate schedules must purge them.
Shared documents and activity remain until the workspace closes, with former-member identifiers minimised. Inactive hashed request-limit keys follow their separate retention rules. Personal receipts and account security records are removed at account purge. Only a specific lawful purpose and its applicable period can justify retaining other records; this does not allow active credentials or all security history to be kept for ordinary use. We do not make company-managed backups. Exports you download remain on your device until you remove them, and account deletion cannot recall those copies. Deleted data must not be restored to active use.
The UK GDPR requires security measures appropriate to the risk under Articles 5(1)(f) and 32. This is a legal duty, rather than a statement that a particular control has been implemented. See the ICO's data security guidance.
6. Report a security issue
Send a suspected vulnerability or security incident to security@pagejoy.app. If that address is unavailable, contact support@pagejoy.app and say that the message concerns security.
Include the affected page or plugin, a short description, the time you noticed it and safe steps to reproduce it. Use a test account and test files. Remove other people's personal information, passwords, keys and payment details from the report. If you believe sensitive evidence is needed, ask how to send it securely first.
The scope of authorised security testing is your own copy, test account and synthetic files only. Public third-party systems and other customer accounts are excluded; request specific written permission before any broader test. Our reporting and disclosure arrangements are send a minimised report, allow us to reproduce it safely, coordinate disclosure and avoid accessing other people data. No reward or legal immunity is promised.
Our target to acknowledge a report is five working days. Our target for progress updates is every seven days while an actionable report remains open, or sooner for a material change.
7. Personal data breaches
We will assess a suspected personal data breach and make the notifications the applicable law requires. Under UK GDPR Article 33, a controller must notify the UK data protection regulator of a reportable breach without undue delay and, where feasible, within 72 hours of becoming aware. The Information Commission succeeded the ICO on 30 September 2026. A processor must notify the relevant controller without undue delay. Article 34 can require notifying affected people without undue delay where the breach is likely to result in a high risk to their rights and freedoms. See the published breach guidance and regulator succession announcement.
The Data Processing Addendum explains notification to our paid business customers when we process their clients' personal data. Other countries can require different notices or timescales.
8. Machine-readable security contact
Our machine-readable security contact details are available at security.txt.