Privacy Policy
Last updated 2026-07-21
Launch draft pending counsel review. Questions: legal@pagerox.com.
1. Who we are and what this policy covers
Pagerox provides AI employees that work inside your Slack and web workspaces. This policy explains what personal data we process when you use the Pagerox service or visit our site, why we process it, and what choices you have.
We wear two hats, and the distinction matters. For workspace content (the messages your employees read in flight, the knowledge your workspace keeps, conversations on Pagerox surfaces), Pagerox acts as a processor: we handle that data only on the customer's instructions, under our Data Processing Agreement at /legal/dpa. For account, billing, and site data (your login, your subscription, your visit to this website), Pagerox is the controller and this policy is the primary document.
If you interact with a Pagerox AI employee inside someone else's workspace, that workspace's owner is the controller of the content involved, and their policies apply alongside this one. Pagerox employees always disclose that they are AI, and covert monitoring is prohibited by our Acceptable Use Policy.
2. Data we process and why
Account data: name, email address, and authentication identifiers, used to sign you in, secure your account, and communicate with you about the service. Sign-in is via magic-link email or Google (through Supabase Auth); multi-factor authentication is available.
Workspace content in flight: Slack and email messages that your AI employees process to do their jobs. This content is read, acted on, and dropped; it is never stored raw (see section 3).
Persisted distilled knowledge: the org brain items your workspace chooses to keep, distilled facts, decisions, and documents with provenance links back to their source, plus attributed correction memories when someone corrects an employee. Your workspace controls what is kept and can delete any of it.
Conversation history on Pagerox surfaces: chats with employees on the Pagerox web app and API are stored as conversation history so you can pick up where you left off. This is different from Slack, where nothing raw persists.
Images: images uploaded in web or API chat are stored in a private bucket scoped to your workspace. Images shared in Slack are fetched in flight for the employee to look at and are never stored.
Audit trail: a record of what employees did and who approved what, kept so workspaces can verify and supervise their AI employees. Retained for 12 months on standard plans.
Usage and billing metadata: plan, seat, and consumption data needed to run the service, meter usage, and bill correctly.
Site analytics: product analytics and error tracking run on PostHog (EU region) and receive event names and allowlisted metadata only. Message content, questions, answers, and documents never reach analytics; the boundary is enforced by a scrubbing wrapper in code, not by convention.
3. What we deliberately do not store
Raw Slack and email content is processed in flight and dropped. This is product architecture, not just policy: there is no stored copy of your Slack or email history anywhere in Pagerox. What persists is only the distilled knowledge your workspace chooses to keep, with provenance links, never the message stream itself.
We also never hold your card numbers. Payments are handled by Stripe; Pagerox sees billing status and metadata, not payment card details.
4. Model providers
Answering questions and doing work requires sending relevant content to a large language model. Content is sent to the model provider configured for your workspace (OpenAI or Anthropic) and processed in flight under no-training terms: your content is not used to train their models.
Customers may bring their own model keys. In that case, calls made with your keys are governed by your own agreement with that provider, including its data-protection terms, not ours.
5. Legal bases
Where GDPR or similar law applies, we rely on: performance of a contract, for account data, workspace processing on the customer's instructions, conversation history, and billing; legitimate interests, for service security, abuse prevention, error tracking, and the audit trail that lets workspaces supervise their AI employees; and consent, for non-essential analytics cookies (see /legal/cookies).
6. Sharing and subprocessors
We do not sell personal data. We share data only with subprocessors that operate the service: hosting (Vercel), database and storage (Supabase), model providers (OpenAI, Anthropic), payments (Stripe), transactional email (Resend), analytics and error tracking (PostHog), rate limiting (Upstash), and the connected-integration platform through which your workspace authorizes each tool an employee may use. Tool integrations only receive data when your workspace connects and authorizes that specific tool.
The current list of subprocessors, and what each one touches, is published at /legal/subprocessors and updated before any new subprocessor handles customer data.
7. International transfers
Some subprocessors process data outside the region where it originates. Where personal data leaves the EEA, UK, or similar jurisdictions, we rely on Standard Contractual Clauses or an equivalent recognized transfer mechanism with each subprocessor. Analytics data stays in PostHog's EU region.
8. Retention
In-flight content: zero retention; it is dropped as soon as processing completes. Distilled knowledge and conversation history: retained until superseded or deleted by your workspace. Audit logs: 12 months on standard plans. Account data: for the life of the account. Billing records: as required by tax and accounting law.
When a workspace is deleted, its content is removed on the schedule set out in the DPA: customer content is deleted within 30 days, and audit records survive only in anonymized form so provenance is not silently rewritten.
9. Security
Data is encrypted in transit and at rest. Every workspace is isolated at the database layer through row-level security, not application convention. AI employees operate under a permission ladder: higher-impact actions require an explicit approval record before they run, and no code path can skip it. Multi-factor authentication is available on all accounts. Chat image storage is private and workspace-scoped.
10. Your rights
You can request access to, correction of, deletion of, or a portable copy of your personal data, and you can object to processing based on legitimate interests. Workspace owners can export the org brain and delete the workspace at any time from the product.
For content inside a customer workspace, route your request through that workspace's owner; as processor we will assist them under the DPA. For account data or anything else, contact support@pagerox.com. We answer within 30 days. If you are in the EEA or UK, you may also lodge a complaint with your supervisory authority.
11. Children
Pagerox is a workplace product and is not directed at children under 16. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact support@pagerox.com and we will delete it.
12. Changes to this policy
We will update this policy as the product and the law evolve. Material changes are announced to workspace owners before they take effect, and the date at the top always reflects the latest revision. This page carries a review banner until it has completed legal counsel review.
13. Contact
Questions about this policy or your data: support@pagerox.com.