Privacy Policy
Pagepod is committed to strict data ownership, security sandboxing, and account-level privacy isolation. This policy outlines how your data is handled across our platform.
1. Account-Level Private Project Protection
When you mark a project as Private, our backend strictly enforces account-level access control. Unauthenticated visitors and search engine crawlers are blocked with 403 Forbidden. Only you can access, preview, or run your private projects when signed into your account.
2. Public Projects & Sandbox Execution
Projects published as Public are intentionally accessible for discovery in our showcase gallery. All standalone executions run under strict HTML5 sandbox isolation to physically isolate third-party scripts from host cookies and authentication tokens.
3. Information We Collect
In Cloud SaaS mode, we collect minimal account data (email) via GitHub or Google OAuth through Supabase Auth, along with titles, descriptions, and tags you explicitly attach to projects.
4. Third-Party Infrastructure
Depending on configuration, Pagepod integrates with trusted infrastructure providers: Supabase (PostgreSQL & Auth), Cloudflare (R2 object storage & CDN), and Vercel (Edge Hosting & Analytics). These providers adhere to SOC 2 Type II and GDPR standards.
5. Data Retention & Deletion Rights
You retain 100% ownership of your code. You can delete any uploaded project at any time from your Workspace dashboard. Deletion permanently purges metadata from the database and assets from storage buckets.