Pagework Privacy Policy
Last updated: 31 August 2026
1. Who we are
Pagework ("Pagework," "we," "us," or "our") is a manuscript-first writing application for novelists, operated by:
Pagework Pty Ltd ABN/ACN: 123456778 Registered address: Dromoyne, New South Wales 2046
Pagework is available at https://pagework.com.au (the "Service").
If you have any questions about this policy or how we handle your personal information, contact us at:
Privacy contact: privacy@pagework.com.au Postal address: Dromoyne, New South Wales 2046
This policy explains what personal information we collect, why we collect it, how we use, store, and protect it, who we share it with, and the choices and rights you have. It applies to everyone who uses the Service — visitors, registered users, and subscribers.
We are a small, growing company. We've tried to write this policy in plain English rather than dense legal boilerplate, and we welcome questions if anything is unclear.
2. Our commitment to your manuscript
Many of our users are novelists working on unpublished, unpublished-adjacent, or commercially sensitive manuscripts. We understand this content is uniquely valuable and personal, and we design and operate Pagework with that in mind:
- We never claim ownership of your writing. You retain all intellectual property rights in the manuscripts, chapters, scenes, and other content you create in Pagework ("Your Content").
- We do not read, review, or use Your Content for any purpose other than providing and improving the Service to you, except where required to investigate abuse, fraud, or a legal obligation, or where you explicitly ask us to (e.g., a support request).
- We do not sell Your Content, and we do not use Your Content to train our own or third-party general-purpose AI/machine-learning models. Your writing goes to an AI provider only for a manuscript you have switched AI on for, and only when you actively invoke a feature — never in the background, and never to train a model. §6 sets out the full rules, including the one thing we cannot yet promise you.
- Your Content is stored per-scene in our database and is never bulk-exported or processed outside the infrastructure described in this policy without a lawful basis.
3. Information we collect
3.1 Information you give us directly
- Account information: name, email address, and password (if you sign up with email) or your Google account identifier and basic profile information (if you sign up with "Sign in with Google").
- Your Content: the manuscripts, chapters, scenes, titles, notes, and other writing you create or upload in the Service.
- Payment and billing information: if you subscribe to a paid plan, our payment processor (Stripe — see §5) collects your card details and billing address directly. We do not store your full card number.
- Communications: anything you send us via email or support requests, including attachments.
3.2 Information collected automatically
- Usage and product analytics: pages viewed, features used, session length, editor interactions (e.g., autosave events, word-count events), device/browser type, operating system, and approximate location derived from IP address (city/region level, not precise geolocation).
- Log and diagnostic data: IP address, browser type, referring URL, timestamps, and error/crash reports (including stack traces) when something goes wrong, to help us fix bugs.
- Cookies and similar technologies: see §8.
3.3 Information from third parties
- If you sign in with Google, Google shares your name, email address, and profile photo with us as authorized by you during the OAuth consent flow.
3.4 Information we do not intentionally collect
- We do not knowingly collect government identifiers (e.g., passport, driver's licence, tax file numbers), health information, or other sensitive information as defined under the Australian Privacy Act 1988 or GDPR Article 9, and we ask that you do not include such information in Your Content or in communications with us.
- Pagework is not directed at children. See §12.
4. Why we collect and how we use your information
We collect and use personal information only for the following purposes, consistent with the Australian Privacy Principles (APPs), the GDPR's data-minimisation principle, and CCPA/CPRA "business purpose" requirements:
| Purpose | Examples | Legal basis (GDPR) | |---|---|---| | Provide the Service | Storing and rendering your manuscripts, syncing autosave, authentication | Contract (necessary to provide the Service you signed up for) | | Process payments | Billing for paid subscriptions via Stripe | Contract | | Communicate with you | Transactional emails (magic links, receipts, password resets), responding to support requests | Contract / legitimate interest | | Improve the product | Aggregated/anonymised analytics on feature usage, crash diagnostics | Legitimate interest | | Security and fraud prevention | Detecting abuse, unauthorized access, or breach of our Terms | Legitimate interest / legal obligation | | Legal compliance | Responding to lawful requests from regulators or courts | Legal obligation | | Marketing (opt-in only) | Product updates or newsletters, only if you opt in | Consent |
We do not use Your Content (the actual text of your manuscripts) for advertising, profiling, or any purpose beyond providing the Service to you, as described in §2 and §6.
5. Who we share information with
We share personal information only with the service providers ("subprocessors") who help us run Pagework, under contracts that require them to protect your data and use it only for the purposes we specify. We do not sell personal information, and we do not share Your Content with data brokers or advertisers.
Where your words actually go — in plain English. When you type, your words travel encrypted from your browser to our application servers (hosted on Vercel) and are saved in our database (hosted on Supabase), encrypted in transit and at rest. If something breaks, an error report goes to Sentry — with manuscript text scrubbed out before it is sent. Usage analytics go to PostHog so we can see which features help writers — with editor content masked and session recording switched off, so your writing itself is not captured; PostHog does receive your email address so events can be linked to your account. The emails we send you (magic links, receipts) are delivered via Resend. If you subscribe, your card details go directly to Stripe — Pagework never sees or stores them. AI-assisted writing is the one place your words can leave that path — and only if you switch it on. No AI feature is available to writers yet: the machinery for the first one has been built, but it is switched off, and no part of the app can reach an AI provider today. We are publishing the rules that govern it now, before the first feature ships, rather than after. That first feature is a whole-manuscript read — it goes through the whole of your draft as it stands and comes back with a structural report: what's working, what isn't, and what to fix first — and when it ships, asking for one sends the whole of that manuscript from our servers — never from your browser — to an AI provider named in the table below. Most of it travels as a series of chapter-sized requests, and some passages travel more than once, because later steps of the read go back over stretches of neighbouring chapters together, and fetch again the scenes its findings point at — §6 walks through each step. It is sent only for a manuscript you have given AI consent for, and only because you asked for that read. It is never used to train a model. §6 says exactly how much is sent, and what that does and does not promise.
| Provider | Purpose | Data involved | Location | |---|---|---|---| | Supabase | Database, authentication, storage | Account data, Your Content (manuscripts), auth tokens | US (us-east-1) | | Vercel | Application hosting | All data transiting the app | Global CDN / US | | Stripe | Payment processing | Billing name, card details, billing address | US (PCI-DSS compliant) | | Resend | Transactional email delivery | Email address, email content (e.g., magic links, receipts) | US | | Sentry | Error/crash monitoring | Diagnostic logs, stack traces, may incidentally include fragments of app state | US/EU (configurable) | | PostHog | Product analytics | Usage events, device/browser metadata, your email address (so events can be linked to your account) | US | | Google | "Sign in with Google" OAuth | Name, email, profile photo (only if you use this sign-in method) | US | | Anthropic — our AI provider (no AI feature is live yet) | AI-assisted writing features (see §6) | The manuscript text the feature you invoked actually reads, plus the read's own working notes — summaries in our words. For the whole-manuscript read we have built, that is all of that manuscript — every chapter, and some passages more than once across the read's five kinds of step (§6). Sent from our servers, only for a manuscript you have given AI consent for. Never your account details | US |
About the AI row. Anthropic is the only AI provider Pagework is able to send your writing to, and the table above is the complete list — the same list §6 refers to. Our AI plumbing is deliberately built so that it is not tied to one supplier; routing to any other provider would take a deliberate configuration change, and adding a provider means adding a row here, and to our internal subprocessor register, in the same release. No AI feature is available to writers yet, so nothing is flowing down this path today (see §6). Every other provider in the table is in active use.
We will update this table as our subprocessor list changes, and we encourage you to check back periodically. We may also disclose information:
- To comply with the law — if required by a valid subpoena, court order, or other legal process, or to protect the rights, property, or safety of Pagework, our users, or the public.
- In a business transfer — if Pagework is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy (or a policy at least as protective).
- With your consent — for any other purpose we disclose to you and you agree to.
5.1 International data transfers
Our infrastructure is primarily hosted in the United States. If you are located in the EU/UK/EEA or elsewhere outside the US, your information will be transferred to and processed in the US. Where required, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards with our subprocessors to protect data transferred internationally.
6. AI-assisted writing features
Where this stands today. There is no AI feature you can use in Pagework yet. The machinery for the first one — a whole-manuscript read — has been built, but it is switched off: no writer can trigger it, and no part of the app can reach an AI provider today. We are publishing these rules before the first AI feature ships rather than after, because our previous policy promised we would — and because a rule written in advance is easier to hold ourselves to.
The rules below are binding from the moment the first AI feature becomes available, and they apply to every AI feature, whichever one it is.
- Nothing is sent without your consent, and consent is per manuscript. AI is off for every manuscript until you turn it on for that manuscript. We record which manuscript you consented for, which feature it covers, when you granted it, and which version of this policy you were shown. You can withdraw consent at any time, and once you do, nothing further from that manuscript is sent.
- Nothing is sent unless you ask for it. Even with consent switched on, text goes to an AI provider only when you actively invoke a feature. Nothing is sent in the background and nothing is sent as you type. One honest nuance: a read you have asked for runs on our servers, so it keeps working — and keeps sending, step by step — after you close the app, until it finishes, fails, or you cancel it or withdraw consent. It never starts by itself.
- How much is sent: a whole-manuscript read sends your whole manuscript — and parts of it more than once. The first AI feature we have built reads your draft as it stands in five kinds of step, and here is what each one sends. First it reads every chapter of that manuscript, one chapter per request. Then it goes back over the prose in overlapping stretches of neighbouring chapters, because some problems — a voice that drifts, a promise set up early and dropped late — only show up between chapters; those requests send prose the provider has already seen once. Next, one or more standing-back steps work out the shape of the whole book; they send the notes the earlier steps produced, written in our words, and your own answer about what kind of book this is — not your prose. Finally, for each finding in your report, the read sends the scenes that finding points at once more, to pull out the exact passage that proves it. Splitting a book into chapter-sized requests is how we keep the app fast and how a read survives being interrupted; it is not a limit on how much of your book is sent. Across a single read the provider receives all of it — some passages two or three times — and we would rather say so plainly than let "a chapter at a time" sound like less than it is.
- A feature that needs only a passage will be described here separately, before it ships. If we later build something that works on just the scene you are editing, or on a passage you select, this section will say so and say what it sends. What holds for every feature is the limit itself: we never send more of your manuscript than the feature you invoked has to read, and we never send any of it for a manuscript you have not switched AI on for.
- The request goes from our servers, never from your browser. The credentials needed to reach an AI provider exist only on our servers, so your browser cannot and does not talk to an AI provider directly.
- It is never used to train any model — not ours, and not the provider's. We use the AI providers named in §5 on commercial API terms that exclude training on API inputs, and we do not switch on any provider setting that would permit it.
- What we cannot promise you yet: that the provider stores nothing. Your writing is never used to train any model. Under the provider's published policies, what we send is typically deleted within about 30 days — we don't have a special agreement that shortens that, and content their safety systems flag can be held longer. We can only tell you what their policies say; we can't see their systems. Preventing any provider-side storage entirely would require a separate zero-data-retention agreement negotiated with each provider, and we do not have one in place. So, plainly: *never used for training* is something we can stand behind contractually; *never stored anywhere by the provider* is not, and we will not tell you otherwise. If we obtain such an agreement, we will say so in this section.
- What Pagework itself keeps. We keep the record of your consent described above, and our ordinary operational logs. We do not keep the raw text of a request to an AI provider, or the raw reply. A read does leave three things behind, though, and we would rather name them than let a comfortable sentence quietly stop being true. A short structured note about each scene: who the point-of-view character is, where and when it takes place, who is in it, what changes, and a one-line summary written in our words. It is kept so that asking for a second read does not have to pay to read an unchanged scene twice. The report itself, including short quoted passages from your manuscript: usually a sentence or two, never more than a long paragraph — our code enforces a hard cap of 1,000 characters on every quote. Before a quote is stored, our own server checks it, character for character, against your actual scene; a passage the model merely claims to have read is discarded, never published. A quoted passage is a genuine extract of your words — a small one, and we are not going to call it anything else. The read's working notes: the summaries its in-between steps produce — a digest of each act, and observations about voice and recurring images — each written in our words, and a note caught copying your sentences is dropped rather than stored. They exist so the read can stand back over the whole book, and so an interrupted read can pick up where it left off; they are readable only by our servers, never by your browser. All three are derived from your manuscript, all are stored in the same database as your manuscript and under the same protections, the notes and reports you can open are visible only to you, and all of them are deleted when the manuscript is permanently deleted or your account is closed. Delete a scene for good and any quote taken from it is erased in the same moment. None of them is used to train any model. Manuscript text is scrubbed out of our error reports and product analytics before they leave the app, AI requests and responses included.
- AI output is a suggestion, not an instruction. Some AI features describe what they found and leave the judgement to you; others may offer an opinion, or a suggested order of changes. Either way, nothing is applied to your manuscript unless you apply it.
- You never have to use it. Every writing, storage, version-history and export feature in Pagework works with AI consent switched off, permanently, on every plan.
- We will update this policy before any AI feature goes live, and before we add or change an AI provider — and because that is a material change, we will tell you about it as described in §13.
7. Data retention
- Account and manuscript data: retained for as long as your account is active, plus a reasonable grace period after account deletion (see §9) to allow for recovery of accidentally deleted content, unless you request earlier deletion.
- Version history: each scene keeps two separate sets of saved versions, and older ones are automatically removed as newer ones are saved — up to 50 ordinary versions (the routine snapshots taken as you write, plus the snapshot we take just before you restore an older version), and up to 50 "saved from another device" copies (explained in the next point). So one scene can hold up to 100 saved versions in total.
- What a "saved from another device" copy is: if the same scene is edited in two places at once — two devices, or two browser tabs — one set of words would otherwise be overwritten by the other. Instead we keep those words as their own version, labelled "Saved from another device" in your version history, so nothing you wrote is lost. They are kept in a separate set on purpose: ordinary saving can never push one out, however much you write afterwards. They are only ever replaced by newer copies of the same kind, oldest removed first.
- A time-based policy is still being defined. Until then, version-history retention is by count — up to 50 of each kind per scene — and not by age.
- AI consent records: if you switch AI on for a manuscript, we keep the record of that decision — including the withdrawal, if you withdraw it — for as long as the manuscript exists, because the withdrawal is the part that matters most. It is deleted when the manuscript is permanently deleted, and when your account is deleted.
- Writing Coach scene notes and reports: the structured scene notes and the reports a read produces — including the short quoted passages that support each note — are kept for as long as the manuscript exists, so you can re-open an older report and see a revision working. The read's server-only working notes (§6) live under the same rule: nothing a read leaves behind outlives the manuscript it came from, or your account. They are deleted when the manuscript is permanently deleted, and when your account is deleted; a quoted passage is also erased the moment the scene it came from is permanently deleted.
- Billing records: retained as required by tax and accounting law (typically 7 years in Australia).
- Analytics and log data: retained for a limited period (typically 12–24 months) before being deleted or aggregated/anonymised.
- Backups: deleted data may persist in encrypted backups for a limited period before being purged in the normal backup rotation cycle.
8. Cookies and similar technologies
We use a limited set of cookies and local storage to:
- Keep you signed in (authentication/session cookies) — strictly necessary.
- Remember your preferences (e.g., editor settings) — functional.
- Understand how the product is used, via PostHog — analytics.
We do not use third-party advertising cookies or cross-site tracking cookies. Where required by law (e.g., for EU/UK visitors), we will present a cookie consent mechanism for non-essential cookies and honour your choice.
9. Your rights and choices
Depending on where you live, you have some or all of the following rights over your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate or incomplete information.
- Deletion / erasure — ask us to delete your account and personal information ("right to be forgotten" under GDPR; deletion rights under the Australian Privacy Act and CCPA/CPRA).
- Portability — request an export of Your Content and account data in a portable format (Pagework also lets you export your manuscripts directly from the Service).
- Objection / restriction — object to or ask us to restrict certain processing (GDPR).
- Opt out of sale/sharing — not applicable, as we do not sell or share personal information for cross-context behavioural advertising (CCPA/CPRA).
- Withdraw consent — where processing is based on consent (e.g., marketing emails), withdraw it at any time (e.g., via the unsubscribe link).
- Non-discrimination — we will not penalise you for exercising any privacy right.
To exercise any of these rights, email privacy@pagework.com.au. We will verify your identity before actioning the request and respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA).
If you are in the EU/UK and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority. In Australia, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
10. How we protect your information
We apply layered technical and organisational safeguards appropriate to the sensitivity of manuscript data:
- Encryption in transit (TLS/HTTPS) across the Service.
- Encryption at rest for our production and staging databases (Supabase-managed Postgres).
- Row Level Security (RLS) enforced at the database level so that one user's account cannot read another user's data — verified against the live database after every schema change, not just declared in code.
- Access to production systems is restricted to authorised personnel; secrets and credentials are never committed to our source code repository.
- Staged environments: all schema/database changes are tested on a separate staging database before being applied to production, with a rollback plan in place.
- Continuous monitoring for application errors and anomalies (Sentry) and a documented incident-response process, including rollback and founder notification procedures.
No system is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and any relevant regulator as required by applicable law (e.g., the Notifiable Data Breaches scheme under the Australian Privacy Act, or GDPR Article 33/34).
11. Data breach notification
In the event of an eligible data breach likely to result in serious harm, we will:
- Contain and assess the breach as quickly as possible.
- Notify affected individuals and, where required, the OAIC (Australia), relevant EU/UK supervisory authorities, and/or affected US state regulators, within the legally required timeframe.
- Provide guidance on steps you can take to protect yourself.
12. Children's privacy
Pagework is not directed to, and is not intended for use by, individuals under the age of 16 (or the minimum age required by your local law, if higher). We do not knowingly collect personal information from children. If we learn we have inadvertently collected information from a child, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@pagework.com.au.
13. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page with a revised "Last updated" date, and where changes are material, we will notify you by email or an in-app notice before they take effect.
14. Contact us
If you have questions, concerns, or complaints about this policy or our data practices:
Email: privacy@pagework.com.au Postal address: Dromoyne, New South Wales 2046