Pagework Privacy Policy
Last updated: 15 July 2026
1. Who we are
Pagework ("Pagework," "we," "us," or "our") is a manuscript-first writing application for novelists, operated by:
Pagework Pty Ltd ABN/ACN: 123456778 Registered address: Dromoyne, New South Wales 2046
Pagework is available at https://pagework.com.au (the "Service").
If you have any questions about this policy or how we handle your personal information, contact us at:
Privacy contact: privacy@pagework.com.au Postal address: Dromoyne, New South Wales 2046
This policy explains what personal information we collect, why we collect it, how we use, store, and protect it, who we share it with, and the choices and rights you have. It applies to everyone who uses the Service — visitors, registered users, and subscribers.
We are a small, growing company. We've tried to write this policy in plain English rather than dense legal boilerplate, and we welcome questions if anything is unclear.
2. Our commitment to your manuscript
Many of our users are novelists working on unpublished, unpublished-adjacent, or commercially sensitive manuscripts. We understand this content is uniquely valuable and personal, and we design and operate Pagework with that in mind:
- We never claim ownership of your writing. You retain all intellectual property rights in the manuscripts, chapters, scenes, and other content you create in Pagework ("Your Content").
- We do not read, review, or use Your Content for any purpose other than providing and improving the Service to you, except where required to investigate abuse, fraud, or a legal obligation, or where you explicitly ask us to (e.g., a support request).
- We do not sell Your Content, and we do not use Your Content to train our own or third-party general-purpose AI/machine-learning models. See §6 (AI features) for how AI-assisted writing tools inside Pagework work.
- Your Content is stored per-scene in our database and is never bulk-exported or processed outside the infrastructure described in this policy without a lawful basis.
3. Information we collect
3.1 Information you give us directly
- Account information: name, email address, and password (if you sign up with email) or your Google account identifier and basic profile information (if you sign up with "Sign in with Google").
- Your Content: the manuscripts, chapters, scenes, titles, notes, and other writing you create or upload in the Service.
- Payment and billing information: if you subscribe to a paid plan, our payment processor (Stripe — see §5) collects your card details and billing address directly. We do not store your full card number.
- Communications: anything you send us via email or support requests, including attachments.
3.2 Information collected automatically
- Usage and product analytics: pages viewed, features used, session length, editor interactions (e.g., autosave events, word-count events), device/browser type, operating system, and approximate location derived from IP address (city/region level, not precise geolocation).
- Log and diagnostic data: IP address, browser type, referring URL, timestamps, and error/crash reports (including stack traces) when something goes wrong, to help us fix bugs.
- Cookies and similar technologies: see §8.
3.3 Information from third parties
- If you sign in with Google, Google shares your name, email address, and profile photo with us as authorized by you during the OAuth consent flow.
3.4 Information we do not intentionally collect
- We do not knowingly collect government identifiers (e.g., passport, driver's licence, tax file numbers), health information, or other sensitive information as defined under the Australian Privacy Act 1988 or GDPR Article 9, and we ask that you do not include such information in Your Content or in communications with us.
- Pagework is not directed at children. See §12.
4. Why we collect and how we use your information
We collect and use personal information only for the following purposes, consistent with the Australian Privacy Principles (APPs), the GDPR's data-minimisation principle, and CCPA/CPRA "business purpose" requirements:
| Purpose | Examples | Legal basis (GDPR) | |---|---|---| | Provide the Service | Storing and rendering your manuscripts, syncing autosave, authentication | Contract (necessary to provide the Service you signed up for) | | Process payments | Billing for paid subscriptions via Stripe | Contract | | Communicate with you | Transactional emails (magic links, receipts, password resets), responding to support requests | Contract / legitimate interest | | Improve the product | Aggregated/anonymised analytics on feature usage, crash diagnostics | Legitimate interest | | Security and fraud prevention | Detecting abuse, unauthorized access, or breach of our Terms | Legitimate interest / legal obligation | | Legal compliance | Responding to lawful requests from regulators or courts | Legal obligation | | Marketing (opt-in only) | Product updates or newsletters, only if you opt in | Consent |
We do not use Your Content (the actual text of your manuscripts) for advertising, profiling, or any purpose beyond providing the Service to you, as described in §2 and §6.
5. Who we share information with
We share personal information only with the service providers ("subprocessors") who help us run Pagework, under contracts that require them to protect your data and use it only for the purposes we specify. We do not sell personal information, and we do not share Your Content with data brokers or advertisers.
| Provider | Purpose | Data involved | Location | |---|---|---|---| | Supabase | Database, authentication, storage | Account data, Your Content (manuscripts), auth tokens | US (us-east-1) | | Vercel | Application hosting | All data transiting the app | Global CDN / US | | Stripe | Payment processing | Billing name, card details, billing address | US (PCI-DSS compliant) | | Resend | Transactional email delivery | Email address, email content (e.g., magic links, receipts) | US | | Sentry | Error/crash monitoring | Diagnostic logs, stack traces, may incidentally include fragments of app state | US/EU (configurable) | | PostHog | Product analytics | Usage events, device/browser metadata | US | | Google | "Sign in with Google" OAuth | Name, email, profile photo (only if you use this sign-in method) | US | | Anthropic | AI-assisted writing features (see §6) | Text you submit to an AI feature, at your direction | US |
We will update this table as our subprocessor list changes, and we encourage you to check back periodically. We may also disclose information:
- To comply with the law — if required by a valid subpoena, court order, or other legal process, or to protect the rights, property, or safety of Pagework, our users, or the public.
- In a business transfer — if Pagework is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy (or a policy at least as protective).
- With your consent — for any other purpose we disclose to you and you agree to.
5.1 International data transfers
Our infrastructure is primarily hosted in the United States. If you are located in the EU/UK/EEA or elsewhere outside the US, your information will be transferred to and processed in the US. Where required, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards with our subprocessors to protect data transferred internationally.
6. AI-assisted writing features
Pagework may offer optional AI-assisted writing tools (for example, suggestions, summarization, or editing assistance) powered by Anthropic's Claude API.
- These features are opt-in / invoked by you — text is only sent to the AI provider when you actively use an AI feature (e.g., clicking "Suggest" or "Summarize"), not passively in the background.
- We do not permit our AI subprocessor to use your submitted content to train their general-purpose models, consistent with Anthropic's commercial API terms.
- We do not independently verify third-party AI vendor training practices beyond their published terms and our contract with them — if this matters to your decision to use an AI feature, we recommend reviewing Anthropic's commercial API terms directly before relying on our summary.
- You can use Pagework's core manuscript-writing and storage features without ever invoking an AI feature.
7. Data retention
- Account and manuscript data: retained for as long as your account is active, plus a reasonable grace period after account deletion (see §9) to allow for recovery of accidentally deleted content, unless you request earlier deletion.
- Billing records: retained as required by tax and accounting law (typically 7 years in Australia).
- Analytics and log data: retained for a limited period (typically 12–24 months) before being deleted or aggregated/anonymised.
- Backups: deleted data may persist in encrypted backups for a limited period before being purged in the normal backup rotation cycle.
8. Cookies and similar technologies
We use a limited set of cookies and local storage to:
- Keep you signed in (authentication/session cookies) — strictly necessary.
- Remember your preferences (e.g., editor settings) — functional.
- Understand how the product is used, via PostHog — analytics.
We do not use third-party advertising cookies or cross-site tracking cookies. Where required by law (e.g., for EU/UK visitors), we will present a cookie consent mechanism for non-essential cookies and honour your choice.
9. Your rights and choices
Depending on where you live, you have some or all of the following rights over your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate or incomplete information.
- Deletion / erasure — ask us to delete your account and personal information ("right to be forgotten" under GDPR; deletion rights under the Australian Privacy Act and CCPA/CPRA).
- Portability — request an export of Your Content and account data in a portable format (Pagework also lets you export your manuscripts directly from the Service).
- Objection / restriction — object to or ask us to restrict certain processing (GDPR).
- Opt out of sale/sharing — not applicable, as we do not sell or share personal information for cross-context behavioural advertising (CCPA/CPRA).
- Withdraw consent — where processing is based on consent (e.g., marketing emails), withdraw it at any time (e.g., via the unsubscribe link).
- Non-discrimination — we will not penalise you for exercising any privacy right.
To exercise any of these rights, email privacy@pagework.com.au. We will verify your identity before actioning the request and respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA).
If you are in the EU/UK and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority. In Australia, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
10. How we protect your information
We apply layered technical and organisational safeguards appropriate to the sensitivity of manuscript data:
- Encryption in transit (TLS/HTTPS) across the Service.
- Encryption at rest for our production and staging databases (Supabase-managed Postgres).
- Row Level Security (RLS) enforced at the database level so that one user's account cannot read another user's data — verified against the live database after every schema change, not just declared in code.
- Access to production systems is restricted to authorised personnel; secrets and credentials are never committed to our source code repository.
- Staged environments: all schema/database changes are tested on a separate staging database before being applied to production, with a rollback plan in place.
- Continuous monitoring for application errors and anomalies (Sentry) and a documented incident-response process, including rollback and founder notification procedures.
No system is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and any relevant regulator as required by applicable law (e.g., the Notifiable Data Breaches scheme under the Australian Privacy Act, or GDPR Article 33/34).
11. Data breach notification
In the event of an eligible data breach likely to result in serious harm, we will:
- Contain and assess the breach as quickly as possible.
- Notify affected individuals and, where required, the OAIC (Australia), relevant EU/UK supervisory authorities, and/or affected US state regulators, within the legally required timeframe.
- Provide guidance on steps you can take to protect yourself.
12. Children's privacy
Pagework is not directed to, and is not intended for use by, individuals under the age of 16 (or the minimum age required by your local law, if higher). We do not knowingly collect personal information from children. If we learn we have inadvertently collected information from a child, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@pagework.com.au.
13. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page with a revised "Last updated" date, and where changes are material, we will notify you by email or an in-app notice before they take effect.
14. Contact us
If you have questions, concerns, or complaints about this policy or our data practices:
Email: privacy@pagework.com.au Postal address: Dromoyne, New South Wales 2046