Privacy policy

Last updated 26 August 2026

What we store, why, and who else sees it. Short version: your account, your files, and what's needed to bill you. No analytics, no trackers, and nothing that follows anyone between sites — the one exception is a site you have deliberately set to ask visitors for an email, which is described below.

Who is responsible

Pagegoat is operated by an individual developer based in India, who is the data controller for everything described here. There is no registered company, no published office address and no data protection officer. Email support@pagegoat.com for anything on this page.

What we collect

Your account. Email address, display name, whether the address is verified, and which sign-in methods you use: a password, a linked Google account, or your employer's single sign-on where we have set that up. If you set a password we store a hash of it, never the password. We also store your sessions, and your plan and its status.

What you upload. The files themselves, plus each site's title, URL slug, visibility setting and version history. For password-protected sites we store a hash of the password, not the password.

Comments. The text, who wrote it, and, so a comment can find its place again after the page changes, short excerpts of the page text around it: the selected passage and a little of what comes before and after. If you highlight something sensitive on a page and comment on it, that excerpt is stored with the comment.

Collaboration. Who has access to which site, team memberships, and the email addresses of people you invite. Those belong to someone else, so only invite people who would expect to hear from you.

Emails captured by your sites. If you set a site to ask visitors for an email before it loads, we store each address given to that site, whether it was confirmed by code, and the date it first appeared. We mail a six-digit code to that address on your site's behalf. Those addresses belong to your visitors: you are the controller of that list and we are the processor, so collecting it lawfully — telling people what it is for, and having a basis to hold it — is yours to get right. You can export the list as CSV or delete any row at any time, from the site's Visitors tab. Addresses that were sent a code and never confirmed it are kept alongside the rest, so that you can see who started and stopped. Nothing expires them for you. Three things remove them: deleting rows yourself, deleting the site, or deleting your account. Note that switching the site back to public, private or password stops collection but deliberately leaves the list intact — so a mode you turned on and off still holds what it gathered until you clear it.

API keys. Stored hashed. We show a key once, at creation, and cannot recover it afterwards.

Billing. Our payment provider's customer and subscription identifiers, your plan, its status and its renewal dates. No card details ever reach us.

Server logs. Ordinary operational logs, which can include your account identifier and email address. They are for diagnosing faults and are not used to build any profile of you.

What we don't collect

We don't count visits. There is no analytics package on this site or on the sites we host for you, no page-view counter, and no visitor profiling. That is also why our plans promise “fair-use bandwidth” rather than a traffic figure: we genuinely aren't measuring it. Nothing here records how often a page was opened, how long anyone stayed, or where they came from — not even for a site that asks visitors for an email, where we store the address and the date it first appeared and nothing about what was read.

The one exception, stated plainly. A site set to ask visitors for an email does collect something about the people who open it, because that is what the setting is for. It is off unless the site's owner switches it on, it applies only to that site, and it never follows anyone to another one. If you are a visitor who would rather not, the answer is not to enter an address — nothing is stored before you do.

No advertising, no third-party trackers, no data brokers. We don't sell or rent anything about you, and we never will.

Cookies

Only strictly necessary ones. There is no cookie banner because there is nothing to consent to.

  • A session cookie that keeps you signed in. It is HttpOnly, so page scripts can't read it.
  • A matching session cookie on our sign-in service, for the same purpose.
  • A short-lived pass, stored per site, recording that you entered the correct password for a password-protected site.
  • The same kind of pass for a site that asks visitors for an email, recording that you cleared its gate. The site's owner chooses how long it lasts; where they chose “every visit” it is a session cookie and dies with the browser.

Why we process it, and on what basis

To run the service you asked for: hosting your files, signing you in, letting collaborators reach your sites, and taking payment. That is performance of our contract with you.

To keep the service working and safe: fixing faults, preventing abuse, and protecting against attacks. That is our legitimate interest.

To meet tax and accounting obligations, which is a legal requirement.

We send you service email only where it is needed to run your account: a sign-in link when you ask for one, and notices such as a password change. We never send marketing email.

Mail we send to other people, on your behalf. Two kinds, both triggered by something you did, and neither requiring the recipient to have an account with us. An invitation, when you give someone access to a site or a team. And a six-digit code, when a visitor enters their address at a site you have set to ask for one. Both are sent in pagegoat's name from our mail provider, and neither is ever used to market anything to the recipient.

Who we share it with

A short list, and no one else:

  • Dodo Payments, our payment provider and merchant of record. They receive what a purchase requires (your name, email, billing address and tax details) and handle your card entirely on their own systems. We receive back identifiers and subscription status.
  • Amazon Web Services (Amazon SES), which delivers the few account notices we send. It handles the recipient address and the message. We don't operate a mailing list or a marketing email tool, and no other email service receives your address.
  • Google, and only if you choose to sign in with a Google account, and only to confirm who you are. If your employer has single sign-on set up with us, their identity provider does the same.
  • Our hosting and infrastructure providers, which store the data on our behalf.

We may also disclose data where the law requires it, and would tell you unless prohibited from doing so.

Anything you publish publicly

A site set to public is on the open internet: anyone with the URL can read it, and search engines may index it. Whatever you put in those files, including your own contact details, becomes public with them. Comments are visible to everyone who can see the site they're on.

How long we keep it

Your account data for as long as your account exists. Delete your account — from Settings, at any time — and we delete it, along with your sites, your files, your comments and your API keys, apart from what we must keep for tax and accounting.

Two kinds of record stay, with your identity removed rather than the record: if you published a version to someone else's site, or resolved a comment on one, that site's history keeps the entry and shows it as a deleted account. Those belong to the person whose site it is, and no longer identify you.

Only the current version of each site's files is stored. Earlier versions are a record of what was published and when, not a retained copy of the bytes.

Your rights

You can ask for a copy of your data, correct it, delete it, or object to how we're using it. Email support@pagegoat.com and we'll respond within 30 days. Much of it you can do yourself from your account settings.

If you are in India, the Digital Personal Data Protection Act gives you these rights. If you are in the UK or EU, the GDPR does, and you may also complain to your national supervisory authority. We'd rather you came to us first.

Security

Traffic is served over HTTPS. Passwords and API keys are stored hashed. Session cookies are HttpOnly, and every request for a site is checked against that site's access rules. No service can promise perfect security, and we don't. But if something goes wrong that affects you, we'll tell you.

Where your data is

Our providers operate internationally, so your data may be processed outside India, including in the United States and the European Union. We use providers that offer appropriate safeguards for those transfers.

Children

Pagegoat isn't intended for children, and we don't knowingly collect their data. If you believe a child has given us information, email us and we'll remove it.

Changes to this policy

The date at the top always reflects the current version. If a change materially affects how we handle your data, we'll email account holders before it takes effect.

Contact