Privacy Policy

What DigiPages collects, who else ever sees it, and what is done with it.

In force from 26 August 2026. DigiPages is operated by a single developer. Questions about this document go to support@digipages.io.

1. Who we are and what this covers

DigiPages is operated by DigiPages, at Gilbert, AZ 85296, United States. We are the data controller for the information described in this policy, and you can reach us at support@digipages.io.

This policy covers the DigiPages website and the application at digipages.io.

Paddle is an independent controller, not our processor. As merchant of record Paddle is the legal seller of your subscription, and it decides for itself how to handle the payment, billing and tax data you give its checkout — for fraud screening and tax compliance it has obligations of its own that we cannot direct. So for card and billing data, Paddle's privacy policy governs rather than this one, and rights over that data are exercised with Paddle. This policy answers for everything else.

2. What we collect

Four things, and nothing else:

Your account. The name and email address you sign up with, and your password — stored hashed, never in a form we can read. If you sign up and never verify your email, that record still exists until it is cleared.

What you write. Your pages, their contents, and any images you upload. Image files are stored on our server; their filename, type, size and dimensions are stored alongside them.

Your sessions. When you sign in we store a session token, its expiry, and the IP address and browser user-agent the sign-in came from. That is what keeps you signed in and what would show an account being used from somewhere unexpected.

Your subscription status. Whether you have an active plan, which one, when the current period ends, and the customer and subscription identifiers Paddle gives us to match their records to yours.

We never see your card details. Payment is taken by Paddle on their own checkout; card numbers do not pass through DigiPages and are not stored by it.

3. Why we hold it, and on what basis

Your account. To create the account, sign you in, verify your address and let you reset a forgotten password. Basis: performance of our contract with you.

What you write. To provide the service — storing your pages and serving them back to you is the product. Basis: performance of our contract with you.

Your sessions. To keep you signed in, and to detect and investigate unauthorised access to an account. Basis: performance of our contract for the first, and our legitimate interest in keeping accounts secure for the second.

Your subscription status. To know whether to grant access, and to match Paddle's records to your account when they tell us a payment succeeded or failed. Basis: performance of our contract with you.

Records of what was sold. Kept because tax and accounting law requires it. Basis: compliance with a legal obligation. These records sit primarily with Paddle as the seller.

We do not send marketing email, so there is no consent to give or withdraw for it. The only email we send is about your account.

4. Who else sees it

Three services, each doing one job. Your pages are not shared with any of them.

Paddle takes payment and is the merchant of record — the legal seller of your subscription. They receive your email address and the billing and card details you give their checkout directly, and they hold those under their own privacy policy. See our terms for what that relationship means.

Hostinger carries the only email we send ourselves: address verification and password resets. It relays the recipient address and the message. Receipts and payment email come from Paddle, not from us. Hostinger also hosts the server below, so this is the same provider rather than an additional one.

Hostinger hosts the server the application and its database run on.

If the optional AI features are released, text you explicitly send to them will be processed by Anthropic to produce the result. Those features are not on sale and nothing is sent anywhere until they are.

Anyone you give a link to. If you publish a page, we store a separate copy of that page and serve it at an unguessable web address to anyone who has it, with no sign-in. Nothing is published unless you choose to publish it, one page at a time. The copy holds the page as it was when you published it — later edits are not shown until you publish again — and it deliberately leaves out links to your other pages, embedded pages and anything filed beneath it. Making the page private again deletes that copy, and the link and its images stop working immediately. Publishing again issues a new link, so any link you shared before stops working too.

We ask search engines not to index published pages, and they are not listed anywhere on this site. That is a request we make of well-behaved crawlers, not a guarantee about anyone you send the link to — treat a published page as public.

We do not sell personal data, and we do not share it for advertising.

5. Cookies

Only cookies the site needs to work. There is no analytics, no tracking pixel and no advertising cookie on DigiPages, so there is no consent banner to dismiss.

One cookie keeps you signed in. Three more remember how you left the app looking — whether the sidebar is open, how wide the page is set, and whether you were reading or editing — so it comes back the same way rather than rearranging itself after it loads. They hold no identifier and are readable only by this site.

6. Where it is stored

On a single server, in one PostgreSQL database, with uploaded images on that server's own disk. It is not copied to other services and there is no third-party file store in front of it. Traffic to the site is encrypted in transit.

7. How long we keep it

Your account, your pages and your uploads are kept for as long as your account is open. Cancelling a subscription does not delete them — it stops the billing and the access, and leaves your content in place so resubscribing restores it. While it is locked you can still download all of it.

A published page. The copy made when you publish a page is kept until you make that page private again, archive it, delete it, or close your account — any of those removes it. It is removed as part of the same action, not on a timer.

Archiving is not deleting. A page you archive leaves your sidebar but stays in your account, in your trash, for as long as you leave it there — we do not remove it on a timer. Deleting it from the trash removes it and everything filed inside it straight away, and we cannot put it back.

After an account closes. If we close your account we keep its content for 30 days, so it can be put back if the closure was a mistake, and delete it after that. If you ask us to delete your data, we do it within 30 days of the request rather than waiting. If you delete the account yourself, there is no such grace period — the content is removed straight away and we cannot put it back.

One thing survives a deletion, and it is not about you. When an account with a cancelled subscription is removed, we keep that subscription’s Paddle reference number, who removed the account and when. No name, no email address, no content — nothing that identifies you. It is kept because Paddle can send us a message about a cancelled subscription after the account is gone (a refund, for instance), and without that reference our system would keep retrying a message it can never make sense of. Paddle holds its own record of the transaction regardless, as the merchant of record.

Sign-ups never completed. If you start creating an account and never verify the email address, the record still exists and cannot be used. We clear these periodically, and will remove one sooner if you ask.

Sessions carry an expiry and stop working at it; the records are cleared once expired. Signing out ends the session immediately.

Billing records. We keep only your subscription status and the Paddle identifiers, for as long as the account exists. The transaction records themselves are Paddle's, and tax law requires them to be kept for several years — their retention period is set out in their privacy policy, not ours.

8. Your rights

You can ask us for a copy of the personal data we hold about you, to correct it if it is wrong, to delete it, to restrict or object to what we do with it, or to receive it in a portable form.

How to exercise any of them: email support@digipages.io from the address on your account. We respond within one month. There is no charge.

Deletion is a button, and it is immediate. Your account page has a Delete account control. It removes every page, folder and uploaded image you have, and it cannot be undone — we keep no copy to restore from. If you have a subscription it is cancelled with Paddle at the same moment, and the record is removed as soon as Paddle confirms the cancellation, which is normally a few seconds. The order matters: removing the record first would leave a cancelled account still being charged.

Cancelling and deleting are not the same choice. Cancelling from the subscription panel keeps your access until the end of the period you have already paid for. Deleting cancels immediately, and the remainder of that period is not refunded. If you want to stop being billed but keep the time you have paid for, cancel rather than delete.

Or ask us instead. You do not have to use the button. If you would rather we did it, or you cannot reach your account, email us and we will delete it within 30 days.

Your pages, in the meantime, are yours to take. Any page can be exported from the app, and whether or not you have a subscription you can download all of them at once — as Markdown files, with their images — from the pricing page while signed in.

Payment data is Paddle's. Because they are an independent controller for it, requests about your card, billing address or tax details go to Paddle. We will point you at the right place if you write to us first.

If you are in the UK or the EEA, the rights above are the ones UK and EU data protection law gives you, and they apply to us even though we operate from the United States. You may also complain to the data protection authority in your own country — that is your right regardless of where we are established, and it is the authority to approach rather than any US body.

If you are in the United States, several states — California, Colorado, Connecticut, Virginia and others — give residents rights to know what is held about them, to have it corrected or deleted, and not to be discriminated against for asking. We apply the process above to every request rather than checking which state you are in first. Two things worth stating plainly, because they are what those laws are mostly concerned with: we do not sell your personal information, and we do not share it for cross-context behavioural advertising. You may also contact the Federal Trade Commission or your state attorney general.

Either way, please tell us first if you think we have handled your data badly — we would rather fix it.

9. International transfers

DigiPages is operated from the United States, and the server holding your account and your pages is located in the United States. That is where your content stays; we do not replicate it to other regions.

So if you are outside the United States, using DigiPages means your data is transferred to it. For readers in the UK or the EEA that is an international transfer in the legal sense, and the United States is not covered by a general adequacy decision. Where safeguards are required for that transfer we rely on the European Commission's standard contractual clauses, and the UK addendum to them for UK data.

Paddle is international too. It handles payments worldwide and is an independent controller for that data, so its own transfer safeguards apply rather than ours. Our own email is relayed by Hostinger, the same provider that hosts the server, so it does not add a further destination.

If you would like more detail about the safeguards relied on for a particular transfer, write to support@digipages.io and we will point you to the current terms.

10. Children

DigiPages is not intended for children. You must be at least 18 years old to hold an account, which is the same requirement as in our terms of service.

We do not knowingly collect personal data from anyone under that age. If you believe a child has created an account, write to support@digipages.io and we will delete it and the content in it.

11. Changes to this policy

Changes are published on this page, and the date the current version came into force is shown at the top of it.

If a change materially affects how we handle your data — a new recipient, a new purpose, a longer retention period — we will tell you by email to the address on your account, or in the app, before it takes effect.

Corrections that do not change what we do with your data, such as a clearer wording or an updated contact detail, take effect when published.

12. Contact

Privacy questions and data-subject requests: support@digipages.io.

DigiPages, Gilbert, AZ 85296, United States. Full postal address available on request.