PRIVACY POLICY

Your data, and what we do with it.

Last updated: June 21, 2026

Who we are

Pagebox is a static-site host with access control: you upload a page (a deck, a document, a prototype, or any HTML), Pagebox gives you one private link, and you choose exactly who is allowed to open it. This policy explains what information Pagebox collects, how we use it, and the choices you have. By using Pagebox you agree to the practices described here.

Information we collect

We keep data collection to the minimum needed to run the service.

From Google Sign-In

When you sign in with Google — whether you are publishing a page or viewing one someone shared with you — Google sends us a limited profile from the scopes openid, email, and profile. From it we receive and store:

  • Your email address (and whether Google has verified it) — used as your identity and to decide who may open a page.
  • Your name — shown in the dashboard and account menu.
  • Your Google account identifier (the sub claim) — a stable ID for your account.

We request online access only. We do not receive or store a Google refresh token, and we never access your Gmail, Google Drive, contacts, calendar, or any other Google service.

Content you upload

The files that make up the pages you publish (HTML, images, styles, scripts, and other static assets), along with metadata such as a title, the share settings you choose, and version history.

Sharing settings

The email addresses and company domains you list when you decide who is allowed to open a page, and any access requests submitted by people asking to view it.

Page views

When a page is opened, we record the view: the verified name and email of the signed-in viewer (or no identity, shown as “anonymous”, for a public page opened without signing in) and the time. A page’s owner can see who has opened it, how many times, and when, and may be emailed the first time a new viewer opens it.

How we use your information

  • To authenticate you and keep you signed in.
  • To enforce access control — checking a viewer’s verified email against the audience you defined for a page.
  • To store, serve, and version the pages you publish.
  • To operate, maintain, secure, and improve the service.

We do not sell your personal information, and we do not use it for advertising.

How Google user data is handled

Pagebox’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use the Google profile data only to provide and improve the sign-in and access-control features described above, we do not transfer it to others except as needed to provide the service or as required by law, and we do not use it for advertising.

How we store and protect it

  • Your session is held in a signed, HTTP-only cookie and expires after 30 days.
  • Account and page metadata is stored in a managed PostgreSQL database; uploaded files are stored in cloud blob storage.
  • Pages are reachable only through a long, unguessable link, and uploaded content is served from an isolated, sandboxed origin behind a per-view access check.

No method of transmission or storage is perfectly secure, but we apply industry-standard safeguards to protect your data.

Sharing and disclosure

We share data only with service providers that help us run Pagebox (for example, hosting, database, and storage providers), and only as needed to operate the service. We may disclose information if required by law or to protect the rights, safety, and security of Pagebox and its users. Pages are visible only to the viewers you authorize.

Data retention and your choices

  • You can delete any page you publish at any time from your dashboard.
  • You can sign out to end your session.
  • You can revoke Pagebox’s access to your Google account at any time from your Google Account permissions page.

Children's privacy

Pagebox is not directed to children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be highlighted where appropriate.