Privacy Policy

Last updated: June 9, 2026

PageDuo.ai is operated by PageDuo Inc. ("PageDuo", "we", "us"), the data controller for the personal data described in this policy — except where Section 1 notes that a published page's owner is the controller for what their forms collect. This Privacy Policy explains what we collect, where it lives, and your choices.

1. What we collect

Account data: your email address, display name, optional country, and authentication credentials (password hash or OAuth identity). Workspace data: the HTML files, folders, media, comments, and form submissions you create or upload. Technical data: IP address, browser type, and — only with your consent (see Section 5) — usage events such as page views and feature usage, used to operate and improve the service.

Activity data (account-bound). When you are signed in and using the Service, you agree that PageDuo collects and stores all of your activity on the site bound to your account — including your usage, interactions, engagement, navigation within the app, the edits and AI generations you make, and the actions you take on your content and the feed. This first-party operational record is a term of using the Service (see the Terms & Conditions, "Your account"); we use it to operate, secure, analyze, and improve the Service and to rank and recommend the public feed. This is distinct from the consent-gated product analytics in Section 5: that opt-in covers the specific analytics-cookie and anonymous-visitor tracking, which you can decline, whereas this account-bound activity record is the operational data the Service needs to function for your account.

If you provide a phone number (optional, asked during signup), we collect it for account recovery and authentication purposes only — plus, if you use the booking feature, to pre-fill your own notification settings. You can view, change, or delete it any time in Settings. We do not share or sell your phone number.

If you submit a form on someone else's published page, the values you enter and your browser's user-agent are transmitted to and stored by PageDuo on behalf of that page's owner, and your IP address is processed for spam and abuse prevention (only a hash is stored). The page owner is the data controller for what their forms collect; PageDuo stores it as their processor. The page owner is responsible for any additional privacy notice their jurisdiction requires.

If you try PageDuo as a guest, the content you create is stored under a temporary guest account. Guest accounts inactive for more than 90 days are deleted along with their content and storage.

2. Where your content lives

Your files and media are stored in cloud object storage and a managed database operated on Amazon Web Services in the United States. Content is scoped to your workspace: only workspace members and people you explicitly share with can access it. Pages you publish are public at their published URL — publishing is always an explicit action.

3. AI processing

PageDuo is an AI-native editor. When you use an AI feature — generation, editing, beautify, media search, comment summaries, prompt suggestions, and the optional AI Auto-fix that repairs page errors automatically (on by default; disable it in Settings) — the relevant content is sent to our AI providers to produce the result: your prompt, the page or element being worked on, and any reference materials you attach. The UI discloses when attached materials will be sent to the AI.

Our default AI provider is Anthropic; some requests may run on AI models we host ourselves (no third party receives those). If you bring your own API key (BYOK), your requests go to the provider whose key you supplied (such as OpenAI or Google) under that provider's terms.

We retain a per-account AI activity log — your chat history with the AI, meaning the prompt you typed and the response produced (both size-capped) — so you can review and re-run your past AI requests; it is deleted with your account. Files created through the AI Agent may include your original prompt as a hidden note inside the document for traceability; it travels with the file if you publish, share, or export it, and you can remove it by editing the file.

We do not sell your content, and we do not use your private content to train models. Our AI providers process your content to serve your request; Anthropic's API terms do not permit using it to train their models.

4. Email

We send transactional email (verification, invitations, password reset, share notifications) via Amazon SES. Invitation emails contain single-use codes. We do not use third-party marketing trackers in email; links go directly to pageduo.ai (or the environment that sent them).

5. Cookies and analytics

We use strictly-necessary cookies for sign-in sessions. Product analytics — usage events and an anonymous visitor identifier cookie — run only after you opt in through the cookie banner; until you choose, and whenever you decline, nothing is recorded or transmitted. One narrow exception: if the app crashes, we send a crash report so we can fix it — without your opt-in it is identifier-free (a one-time random id, no page address, no browser details); the fuller report only ships once you have opted in. You can change your choice at any time in Settings → Cookies & analytics, and declining never limits core functionality. Published pages show their own consent banner with the same rule.

Feed ranking and recommendations. PageDuo's public feed ranks and recommends published pages. To do that we use information about published content only: the published page itself (it is public by your choice to publish), aggregate engagement statistics (view/play counts, copy counts, comment counts — counts, not who did them), and comments left on published pages (which are publicly visible on those pages). Consent-gated analytics events additionally feed this ranking only for users who opted in. We may also use these same published-content signals to train and tune the ranking and recommendation models behind the feed. Private, unpublished workspace content is never used for feed ranking or for training those models, and unpublishing a page removes it from the feed. If you are signed in and told us about yourself when you signed up, we use that description — processed by our AI provider — to estimate which published pages match your interests and order your feed; it is used only to serve you, is never shown to other users, and you can change it by updating your profile.

6. Sharing and third parties

We share data with the processors needed to run the service: cloud hosting (AWS), our AI providers for the features you invoke (Section 3), and payment processing (when billing launches). In addition: when you use media search, your search query (and page text used to suggest search terms) is sent to the media providers we search — Brave Search, YouTube, Openverse, Apple iTunes, and Forvo. Published pages that display live data (for example weather, market prices, or encyclopedia extracts) may fetch it from public data services either through our servers or directly from the visitor's browser — in the direct case those services see the visitor's IP address, as with any website that embeds third-party content. Each processor receives only what its function requires. We do not sell personal data.

7. Retention and deletion

Your content is retained while your account is active. Deleting your account removes your user record, your AI activity log, and the workspaces only you own — their folders, pages, versions, comments, audit logs, and stored files; the deletion cascades through our database and object storage. Your analytics data is an exception: it is retained for 180 days after you delete your account, then permanently removed — we keep it for that period for security, fraud-prevention, and aggregate product-statistics purposes, after which it is deleted. A workspace you share with other members is transferred to a remaining member instead of deleted, so their content stays available; content you contributed to OTHER people's workspaces (pages, versions, comments) stays with those workspaces and is disassociated from you. Deleted data may persist for a limited time in operational backups before those rotate out.

8. Your rights

You can download any folder as a ZIP and any file as plain HTML from the app, and export form submissions per page as CSV. You can correct your profile (including your phone number) in Settings, change your cookie choice in Settings, and delete your account from Settings or by emailing [email protected]. Depending on your jurisdiction you may have additional rights (access, portability, erasure, objection, complaint to a supervisory authority) — contact us and we will honor them.

9. Children

PageDuo is not directed at children. You must be at least 13 years old (or the digital-consent age in your country) to create an account. If we learn we have collected personal data from a child below that age, we will delete it and close the account.

10. Security and incidents

Content is encrypted in transit; access is scoped by workspace membership and verified on every request. If a security incident affects your personal data, we will notify you and the relevant authorities as required by applicable law.

11. Changes

We will update this policy as the product evolves and change the "Last updated" date above. Material changes will be announced in-product.

12. Contact

Questions about privacy: [email protected].