Effective [EFFECTIVE_DATE]

Privacy Policy

This Privacy Policy explains how [TRADING_NAME] (“we”, “us”, or “our”) collects, uses, stores, and shares your personal data when you use the p[ai]ges writing platform. We are the data controller for the purposes of applicable data protection law.

Please read this policy carefully. By using the service you acknowledge that you have read and understood it.

1. What information we collect

Information you give us

  • Account data: your email address and hashed password when you register.
  • Profile data: any display name or other information you choose to add.
  • Payment data: billing address and payment method details. Card numbers are processed directly by our payment processor (Stripe) and are never stored on our servers.
  • Your content: the manuscripts, outlines, chapter drafts, cover prompts, and other material you create or import.
  • BYOK API keys: API keys you voluntarily provide for supported AI providers. These are stored encrypted and are never logged or transmitted to third parties beyond the provider you specified.
  • Support communications: emails or messages you send to our support address.

Information we collect automatically

  • Usage data: pages visited, features used, generation counts, export actions, and similar product telemetry.
  • Log data: IP address, browser type and version, operating system, request timestamps, and HTTP status codes. Server logs are retained for [LOG_RETENTION_DAYS] days.
  • Session data: a signed, server-side session token stored as an HttpOnly cookie. We do not use third-party tracking cookies.

2. How we use your information

We use the information we collect to:

  • Create and manage your account.
  • Provide, operate, and improve the service.
  • Process subscription payments and send receipts.
  • Route AI generation requests to the appropriate provider.
  • Send transactional emails (password resets, plan changes, generation alerts).
  • Respond to support requests.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our Terms of Service.

We do not use your manuscript content to train AI models, and we do not sell your personal data to any third party.

We may send you product update emails if you are a subscriber. You can opt out of these at any time by clicking the unsubscribe link at the bottom of any such email.

3. Legal bases for processing (EEA / UK users)

Where data protection law requires a legal basis, we rely on:

  • Contract performance — to provide the service you signed up for.
  • Legitimate interests — to operate and improve the service, prevent abuse, and maintain security.
  • Legal obligation — where we are required by law to process or retain data.
  • Consent — for non-essential communications, where we ask for it explicitly.

4. AI providers and third-party services

When you use the AI generation features, we send your prompts and context to one or more AI providers (for example Anthropic, OpenAI, or Google). The content you submit to those providers is governed by their own privacy policies and terms of service. We recommend you review those policies before submitting sensitive material.

We use the following categories of third-party service:

  • Payment processing: Stripe, Inc. — for subscription billing. Stripe processes card data under its own PCI compliance programme.
  • Email delivery: a transactional email provider for sending account notifications. Your email address is shared with this provider solely for delivery purposes.
  • Cloud infrastructure: our servers and databases run in data centres in [JURISDICTION]. Your data is not intentionally transferred outside [JURISDICTION] except where required to reach AI providers or payment processors.

5. Bring-your-own-key API keys

If you provide your own API key for an AI provider, we store it encrypted at rest using AES-256-GCM. The key is decrypted in memory only for the duration of a generation request. It is never written to logs, never transmitted to any party other than the provider you specified, and never used for any purpose other than routing your requests to that provider.

6. Your content

Your manuscripts, outlines, and other content remain yours. We process them to provide the service (rendering the editor, running exports, routing generation requests). We do not read, analyse, or share your content for any other purpose, and we do not use it to train AI models.

7. Data retention

We retain your personal data for as long as your account is active. If you delete your account, we will permanently delete your personal data within [RETENTION_DAYS] days, except where we are required by law to retain it for longer (for example, financial records for tax purposes).

Server logs are retained for [LOG_RETENTION_DAYS] days for security and debugging purposes, then deleted automatically.

8. Your rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data (right to erasure).
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw consent where processing is based on consent.

To exercise any of these rights, contact us at support@paigesapp.com. We will respond within 30 days. We may ask you to verify your identity before acting on a request.

You also have the right to lodge a complaint with your local data protection authority.

9. Security

We implement industry-standard security measures including HTTPS for all data in transit, AES-256-GCM encryption for sensitive stored values (passwords are hashed with bcrypt), HttpOnly and Secure session cookies, and rate limiting on authentication endpoints.

No method of transmission or storage is 100% secure. If you discover a security vulnerability, please disclose it responsibly to support@paigesapp.com.

10. Children

The service is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, contact us and we will delete it promptly.

11. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email or by a prominent notice in the product at least 14 days before the change takes effect. The effective date at the top of this page reflects when the current version was adopted.

12. Contact

For privacy questions or to exercise your rights, contact us at: support@paigesapp.com.