Privacy Policy

Last updated 2026-07-19

Launch draft pending counsel review. Questions: legal@pagerox.com.

1. What we process

Account data: name, email, authentication identifiers. Workspace content: the documents, decisions, and corrections your workspace stores in its org brain. In-flight content: Slack and email messages employees process to do their jobs.

2. Process-and-drop

Raw Slack and email content is processed in flight and dropped. Employees store only distilled knowledge items with provenance, never a copy of your message history. Which channels an employee listens to is disclosed in the workspace, and every channel can opt out.

3. What we store and for how long

Distilled knowledge is retained until superseded or deleted by your workspace. Audit logs are retained for 12 months on standard plans. Deleted accounts are soft-deleted so audit provenance survives without personal identifiers; workspace deletion removes content within 30 days.

4. Analytics

Product analytics and error tracking run on PostHog (EU region) and receive event names and allowlisted metadata only. Message content, questions, answers, and documents never reach analytics; the boundary is enforced in code, not by convention.

5. Model providers

Content needed to answer a question is sent to the model provider configured for your workspace under no-training terms. With bring-your-own-keys, your own provider agreement (and its DPA) governs those calls.

6. Subprocessors

The current list of subprocessors, and what each one touches, is published at /legal/subprocessors and updated before any new subprocessor handles customer data.

7. Your rights

Workspace owners can export or delete workspace content. Individuals can request access, correction, or deletion of their personal data via privacy@pagerox.com. We answer within 30 days.