Last Updated: September 2026

Privacy Policy

Pagepod is committed to strict data ownership, security sandboxing, and account-level privacy isolation. This policy outlines how your data is handled across our platform.

1. Account-Level Private Project Protection

When you mark a project as Private, our backend strictly enforces account-level access control. Unauthenticated visitors and search engine crawlers are blocked with 403 Forbidden. Only you can access, preview, or run your private projects when signed into your account.

2. Public Projects & Sandbox Execution

Projects published as Public are intentionally accessible for discovery in our showcase gallery. All standalone executions run under strict HTML5 sandbox isolation to physically isolate third-party scripts from host cookies and authentication tokens.

3. Information We Collect

In Cloud SaaS mode, we collect minimal account data (email) via GitHub or Google OAuth through Supabase Auth, along with titles, descriptions, and tags you explicitly attach to projects.

4. Third-Party Infrastructure

Depending on configuration, Pagepod integrates with trusted infrastructure providers: Supabase (PostgreSQL & Auth), Cloudflare (R2 object storage & CDN), and Vercel (Edge Hosting & Analytics). These providers adhere to SOC 2 Type II and GDPR standards.

5. Data Retention & Deletion Rights

You retain 100% ownership of your code. You can delete any uploaded project at any time from your Workspace dashboard. Deletion permanently purges metadata from the database and assets from storage buckets.