Privacy Policy
Last updated 2026-07-19
Launch draft pending counsel review. Questions: legal@pagerox.com.
1. What we process
Account data: name, email, authentication identifiers. Workspace content: the documents, decisions, and corrections your workspace stores in its org brain. In-flight content: Slack and email messages employees process to do their jobs.
2. Process-and-drop
Raw Slack and email content is processed in flight and dropped. Employees store only distilled knowledge items with provenance, never a copy of your message history. Which channels an employee listens to is disclosed in the workspace, and every channel can opt out.
3. What we store and for how long
Distilled knowledge is retained until superseded or deleted by your workspace. Audit logs are retained for 12 months on standard plans. Deleted accounts are soft-deleted so audit provenance survives without personal identifiers; workspace deletion removes content within 30 days.
4. Analytics
Product analytics and error tracking run on PostHog (EU region) and receive event names and allowlisted metadata only. Message content, questions, answers, and documents never reach analytics; the boundary is enforced in code, not by convention.
5. Model providers
Content needed to answer a question is sent to the model provider configured for your workspace under no-training terms. With bring-your-own-keys, your own provider agreement (and its DPA) governs those calls.
6. Subprocessors
The current list of subprocessors, and what each one touches, is published at /legal/subprocessors and updated before any new subprocessor handles customer data.
7. Your rights
Workspace owners can export or delete workspace content. Individuals can request access, correction, or deletion of their personal data via privacy@pagerox.com. We answer within 30 days.