Skip to content
Legal

Privacy policy, without the fog.

This is what Pagefully collects, why, who processes it, where it lives and how to have it deleted. The short version: we keep what the product needs to make your pages, we sell nothing, we show no ads, and one email to hello@pagefully.com removes it.

1. Who we are

Pagefully is made and operated by VI Ventures LLC, Glenview, Illinois, United States. We are the data controller for what is described here. Write to hello@pagefully.com about anything in this policy.

2. What this covers

This policy covers pagefully.com: the website, the free preview, your account, the app, and the emails we send. It does not cover Apple, Stripe or any other service you use alongside Pagefully; each has its own policy. Our terms of service say what the service does and what you agree to; this page says what happens to information.

3. What we collect

What we hold depends on what you do. Nothing is collected before you do something, and the free preview asks for no email and no account.

By situation
When you visit the siteOur hosting provider keeps standard server logs for a short time: the network address a request came from, the page asked for, the time and the browser. We count page views and the steps people take (a preview asked for, an account made, a key connected, a page sent) with Mixpanel, under a random browser id its script sets; the id, the page and, if you came from an ad, its campaign name are what is sent. Mixpanel also records how the page is used, where the pointer went and what was scrolled and tapped, as a replay we can watch to see where the site confuses people. Anything you type is masked in the recording, Apple’s exact strings are masked, and the form that takes your App Store Connect key is never recorded. Where we advertise, Google’s tag tells Google which clicks on our ads reached a preview or an account, so we know which ads work; it sets Google’s own cookies, listed below, and we send it nothing about you. If you have chosen Light or Dark in Settings, a cookie remembers it.
When you use the free previewThe App Store id of the app you looked up, and the name you typed if you searched, which goes to Apple’s public App Store search. A hashed identifier of your network address, made with a secret key, and a hashed identifier of a first-party cookie id, so that we can limit new previews per visitor. The address itself is never stored or logged. What was generated for that app (the brief, the page’s headlines and drawings), what it cost us, and a record that it was asked for. A preview is kept for 30 days and shown to anyone who looks up the same app in that time.
When you create an accountYour email address. The sign-in links we send, which work once and expire in an hour. Session cookies set by our sign-in provider so you stay signed in. A workspace named after the first part of your address (“Tom’s workspace”). A hashed visitor identifier, as above, recorded once so that we can limit how many accounts are made from one place in a day. Your email preferences. A cookie holding the plan you pressed on the pricing page, for seven days, so it is ready when you arrive.
When you connect App Store ConnectYour key’s id and issuer id, and the key itself, encrypted before it is stored. When it was added and last checked with Apple. Your listing in each language: name, subtitle, description, keywords, promotional text and screenshots. Your existing custom product pages and the keywords assigned to each. Your public App Store reviews. The public listings and reviews of competitors you choose to follow. The pages we make for you: their headlines, drawings and translations, and whether each was sent to Apple. A record of each job, as codes and times only; no Apple data is kept in it.
When you payStripe takes payment on its own pages and holds your card number, billing address and receipts. We hold your Stripe customer id, the subscription id and its state, the plan, the billing period, when a Pack was bought and whether its credit was used, and the ids of the events Stripe sends us.
When you write to usWhat you type in the feedback box, with your email address, your workspace name, the app and plan you were on and the screen you were looking at, emailed to us so that we can reply to you. A screenshot you report, with the issue and your note, kept in our support list and emailed to us. Any email you send to hello@pagefully.com.

4. Why we use it

  • To provide the service: to read your listing, plan and draw your pages, send the ones you approve to App Store Connect, keep them current, and show you your account. This is what you asked for by using Pagefully (under GDPR, performance of a contract).
  • To write and draw with models: your listing, reviews and screenshots are given to the model providers in section 6 so that headlines can be written and screenshots drawn. Same basis.
  • To keep the free preview open: the hashed visitor identifiers and the usage records let us limit new previews and new accounts per visitor and per day, and see abuse without knowing who anyone is (our legitimate interest in running a public, free feature).
  • To bill you: to take payment through Stripe, apply the right plan to each app, and keep the records tax law requires.
  • To email you: four kinds, and no others. Sign-in links and address confirmations, which you ask for. The competitor-changes email and the weekly note, which you can turn off at any time. We send no marketing email, and no billing email; receipts come from Stripe.
  • To answer you: when you send feedback, report a screenshot or write to us.
  • To keep the service safe: server logs, rate limits and the job records help us find faults and misuse.

5. Models and your data

To write headlines and draw screenshots, Pagefully sends your listing text, your public reviews, the public listings and reviews of competitors you follow, and your screenshots to the model providers named in section 6. A screenshot may be sent so that a model can read its layout, so that words can be set on it, or so that a new version can be drawn from it.

What is never sent to a model: your App Store Connect key, your email address, your payment details, anything from another customer, and the name of a competitor as something to write about. The writer is never given a competitor’s name, so no page you make names another app.

We use these providers through their business APIs, not their consumer products. Under OpenAI’s API terms, data sent through the API is not used to train OpenAI’s models. Where any provider offers a choice about training on customer data, we do not permit it. Each provider receives only what its job needs, and may use it for nothing else.

6. Who we share it with

We do not sell personal information, we do not share it for advertising, and we do not combine one customer’s data with another’s. A small number of providers process data for us, each for one job:

Providers
SupabaseOur database, file storage and sign-in. Holds your account, your listing and screenshots, your pages and the encrypted key, in its us-west-2 region (Oregon, United States).
VercelHosts this site and the app, and keeps their server logs.
Fly.ioRuns the engine that reads listings, studies screenshots and draws pages, in the United States.
OpenAIThe models that write headlines, briefs, page plans and translations, read the layout of a screenshot, and draw a screenshot where your own cannot be set to the standard. Receives your listing text, your public reviews, the public listings of competitors you follow, and your screenshots.
TypeSafe AIA classification model that answers short questions about your listing and screenshots: whether a line makes a claim, which screen suits which search. Receives the text and screenshots those questions are about.
ResendSends our email: sign-in links, the two optional emails, and your feedback and reports to us.
StripeTakes payment on its hosted checkout and billing portal, and holds your card and billing details. We hold only its customer and subscription ids.
AppleApp Store Connect receives, through the key you provide, the reads and writes described in the terms. Apple’s public App Store lookup and search receive the app ids and names looked up for previews, listings and competitors, with no key.
Google FontsOnly inside the app, when you pick a typeface for your screenshots: your browser loads that font from Google, so Google sees that request. The fonts of this site itself are served from our own servers.

Beyond these, we share information only if the law requires it, to protect someone’s safety or our rights, or, if Pagefully is ever sold or merged, with the new owner, who would be bound by this policy. We will tell you by email if that happens.

7. Where it is stored

Your data is stored and processed in the United States: the database and files in Oregon, the site in Portland, the engine in San Jose. If you are in the European Economic Area, the United Kingdom or Switzerland, using Pagefully means your data is transferred to the United States. Where a provider offers standard contractual clauses or an equivalent safeguard for that transfer, we use it; ask us for the current details.

8. How long we keep it

  • Account data (your email, key, listing, pages, plan state) is kept while your account exists. When you ask us to close it, we delete it within 30 days, except for payment records we must keep for tax and accounting, which are kept for as long as that law requires.
  • Removing a key deletes our encrypted copy at once. Disconnecting an app deletes our copy of its listing, screenshots, intents and pages at once. Neither changes anything in App Store Connect.
  • Previews are kept for 30 days. After that a preview is served only while the app’s public listing is unchanged, and made again when it changes.
  • Usage records hold hashed identifiers, never an address or email, and are kept so that patterns of abuse stay visible.
  • Server logs are kept by our hosting providers for a short period and then discarded.
  • Links to pictures are signed and last up to two weeks; preview-size pictures are behind ten-minute links.
  • Emails you send us, including feedback and reports, are kept in our mailbox for as long as we need them to help you.

9. Security

  • Your App Store Connect key is encrypted with a key held outside the database before it is stored. It is never written to a log, never sent to a browser, and never shown again after you add it. A failure logs a code and a job id, never a key, a token or an Apple payload.
  • Data is encrypted in transit and at rest with our providers.
  • Each customer’s data is kept separate. Reads from a browser go through row-level security, and every write goes through our server after it has checked that you belong to the workspace. The browser never writes to the database.
  • You stay in control at Apple: revoking the key in App Store Connect, under Users and Access, Integrations, stops Pagefully at once, whatever we hold.
  • No system is perfectly secure. If we learn of a breach that affects you, we will tell you by email without undue delay, and tell the authorities where the law requires.

10. Your choices and rights

Things you can do yourself, in the product:

  • Turn off the competitor-changes email and the weekly note in Settings, or with the link at the foot of either email. Sign-in links cannot be turned off, because they are how you get in.
  • Remove your key, replace it, or disconnect an app, in Settings.
  • Clear the preview and theme cookies in your browser at any time.

Things you can ask us for, by writing to hello@pagefully.com from the address on your account:

  • Access: a copy of the personal information we hold about you.
  • Correction: fixing anything that is wrong, including changing your email address.
  • Deletion: closing your account and deleting what we hold, as section 8 describes.
  • Portability: an export of your data in a machine-readable form.
  • Objection or restriction: asking us to stop or limit a use of your data, including the uses based on our legitimate interests.

These are rights you have under the GDPR and UK GDPR if you are in the EEA, the UK or Switzerland, and under the CCPA if you are in California; we offer them to everyone. We answer within 30 days, we will never treat you differently for asking, and we may check that a request really comes from you before we act on it. If you think we have got something wrong, you can also complain to your local data protection authority. We do not sell or share personal information as those words are defined in the CCPA, and we have not done so in the past 12 months.

11. Cookies

We set a small number of first-party cookies, and the one advertising cookie Google’s tag sets.

  • Sign-in session: set by our sign-in provider when you sign in, so you stay signed in. Removed when you sign out.
  • Preview visitor (pf_v): a random id set when you ask for a preview, kept for a year, so that we can limit new previews per visitor. Only a hash of it is stored.
  • Analytics (mp_…_mixpanel): set by Mixpanel’s script on your first page, kept for about a year, so that the pages one browser sees and the account it makes are counted as one visitor. It identifies the browser, not you, until you make an account.
  • Google Ads (_gcl_au and the like): set by Google’s tag when the site is loaded, for about 90 days, so that a click on one of our ads can be matched to a preview or a sign-up here. Google’s own notice covers them.
  • Theme (ip-theme): set only when you choose Light or Dark in Settings, so the choice holds on this browser.
  • Plan choice (ip_plan): set when you press a plan on the pricing page, for seven days, so the right plan is ready after you sign in.

None of these is sold or shared, and none is read by anyone but us, Mixpanel for the analytics id, and Google for its own.

12. Children

Pagefully is a tool for app developers and is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us information, write to us and we will delete it.

13. Changes

We update this policy when what we collect or who processes it changes. The date at the top changes with it, and for a change that matters we also email the address on your account before it takes effect.

14. Contact

VI Ventures LLC, Glenview, Illinois, United States. Write to hello@pagefully.com. Every message is read and answered by a person. How your key is handled is also on the security page.