1. Who we are
Pageree is operated by Aleksandr Shelestov PR JustOneDev, Jurija Gagarina 231, Novi Beograd, 11070 Belgrade, Serbia, PIB (tax identification number) 113504102. In this policy, “Pageree,” “we,” and “us” refer to that operator.
This policy covers our marketing website, account console, Model Context Protocol (MCP) service, subscriptions, support, and landing-page hosting and lead-collection features. Our Terms of Use describe the proposed service agreement.
For account administration, billing, security, and our own business communications, we determine how and why information is used. When a business uses Pageree to collect inquiries or measure visits to its landing pages, that business normally determines the purpose, and Pageree processes information on its behalf. The appropriate data processing agreement must govern that relationship.
The business’s own privacy notice explains its use of your inquiry and subsequent communications. This policy does not replace that notice. Contact the business shown on the landing page, or ask privacy@pageree.com for help routing a request.
2. Information we handle
The information involved depends on which features you use:
- Website visits
- Network and security information needed to deliver the website, such as your IP address, requested URL, browser information, time, and security events. Our marketing site serves its fonts and illustrations locally.
- Accounts and sign-in
- Email address, username, password hash where password login is used, account and role identifiers, and authentication records. Optional Google sign-in uses basic profile information such as your identifier, name, email, and profile picture; it does not request access to Gmail messages, contacts, or Drive files.
- Connected agents and page creation
- Client and authorization details, tool requests and results, page instructions, content and versions, uploaded and generated assets, image prompts and generation metadata, domains, and publishing configuration.
- Lead submissions and form choices
- Fields a visitor submits, such as name, email, phone number, company, or message; page and form identifiers, submission time, delivery status, IP address, user agent, referrer, and approximate country where available. Configured consent records can include checkbox choices, the wording and policy version presented, timestamps, and request metadata.
- Customer landing-page analytics
- Page and session identifiers, URLs and query parameters, referrers, browser and device information, screen dimensions, approximate country, visits, section engagement, clicks, and form-submission events. Click records may include the clicked element’s text and attributes. These records are not necessarily anonymous.
- Support and diagnostics
- Messages, contact details, privacy-request verification records, relevant account or page information, and errors and performance data with technical context. Console session replay is excluded from our configuration; error and performance monitoring is separate.
- Trials and billing
- Trial status, billing contact and tax information, customer and subscription identifiers, orders, payment status, amounts, currency, invoices, cancellation, refund, and dispute records. A payment card is required to start the 30-day trial. Dodo Payments is our selected merchant of record and processes payment-method information during trial setup and purchases.
Do not put passwords, authentication tokens, card details, or unnecessary personal information in page URLs, public content, image prompts, or lead forms.
3. Why we use information
We use information to provide requested features, authenticate users, administer accounts and subscriptions, deliver service communications, respond to requests, troubleshoot problems, detect abuse, protect the service, and meet legal obligations.
For customer-controlled information, we carry out the customer’s instructions, including publishing a page, delivering submissions to configured destinations, and producing page analytics. A submitted inquiry does not authorize us to use that person’s details for unrelated marketing.
Pageree does not send promotional emails. Account verification, security notices, support replies, receipts, and required billing notices are operational communications. A customer’s follow-up messages and an independent provider’s communications are governed by their own notices and applicable law.
Where a legal basis is required, it depends on the activity: performing a contract or taking requested pre-contract steps, legitimate interests such as proportionate security and business-account administration, legal obligations, or consent where required. Accepting this policy is not blanket consent. A customer’s contract with Pageree is not automatically a contractual basis for processing every visitor’s information.
4. AI agents and generation
A connected agent sends Pageree the information needed for authorized tool requests and receives tool results. Connecting does not give Pageree your entire conversation; we receive what your client sends. Information returned to the client is also handled under that client provider’s terms and privacy settings.
Image generation can send prompts to an external AI provider. We store generated assets and associated prompts, model information, and creation times. Automated content checks can send extracted page text, metadata, links, and image references to an AI provider.
Our implementation supports OpenAI and compatible API endpoints. OpenAI states that its API data is not used for training by default unless the customer opts in; retention depends on the endpoint and account settings, with default abuse-monitoring retention generally up to 30 days and stated exceptions. See OpenAI’s API data controls. Those statements do not establish the practices of every compatible provider or your chosen agent.
Automated moderation can flag content or restrict publication. Contact abuse@pageree.com to request review of a restriction.
5. Providers and other recipients
Information can be received by providers needed to operate the service, your authorized users and connected agents, and the business receiving a lead and its chosen email, webhook, or CRM destination. Public page content is accessible to visitors and may be copied by search engines or others.
The service’s provider inventory includes:
- Cloudflare: global delivery and storage of pages and assets, routing, and security. Turnstile is used for supported bot-protection flows.
- Hetzner Online GmbH: application servers in Germany.
- DigitalOcean, LLC: database hosting in the EU.
- Email delivery providers: operational messages and lead notifications. The implementation supports a configured relay or Cloudflare Email Service.
- OpenAI or a configured compatible AI provider: image generation and content checks.
- Sentry: error and performance monitoring, with console session replay disabled in the configuration.
- Google: optional account sign-in.
- Dodo Payments: our selected merchant of record for billing, tax, transaction administration, fraud prevention, refunds, and disputes.
Dodo acts as an independent controller for its own merchant-of-record purposes; not all its activities are performed solely on our instructions. Its Privacy Policy and Data Processing Agreement explain those roles. The applicable Dodo entity is identified in the checkout and transaction documents. Deletion of Pageree records does not necessarily require Dodo to erase records it must retain independently.
Cloudflare’s Turnstile Privacy Addendum describes both bot-protection processing and its own use of signals to improve detection.
We may also disclose information to advisers or authorities for lawful requests, legal obligations, security, or the protection of rights, or in connection with a business transfer subject to applicable safeguards.
Provider review is still in progress, including the final email relay, AI endpoint, Dodo contracting entity, processing locations, and production settings. This draft inventory is not a finalized subprocessor notice.
6. Cookies and browser storage
Our website, console, and customer pages have different storage and tracking behavior. The console stores an authentication token and appearance preference in browser local storage. These have no fixed browser expiry; server-side token validity is separate. Clearing browser storage removes local items and may sign you out or reset preferences.
The console also sets a 365-day cookie intended to exclude an account owner’s own visits from page tracking. This is not a general visitor privacy opt-out. Customer-page analytics uses session events and browser information; bot-protection services also process browser and network signals.
The reviewed analytics implementation does not currently demonstrate automatic handling of Do Not Track or Global Privacy Control signals. Blocking cookies or clearing storage does not necessarily stop analytics network requests. Customer page owners must describe their own additional scripts and practices.
Production tracking, consent and objection controls, and legally required opt-out signals must be verified and completed before this policy becomes effective. A cookie-free implementation alone does not establish an exemption from those requirements.
7. Data retention
Retention differs by record type. The following expiry settings are established in the current implementation; database expiry is asynchronous, so deletion is not guaranteed at the exact second.
- Lead submissions: 30 days after capture
- Lead payloads, delivery metadata, and attached consent evidence are scheduled to expire after 30 days, including successfully delivered leads. A valid earlier deletion request can shorten this period.
- Privacy-request records: 365 days after creation
- Verification links expire after 24 hours. Link expiry does not itself delete the request record.
- MCP authorization records
- Authorization codes expire after 10 minutes, access tokens after one hour, and refresh tokens after 30 days from issue. Token records are scheduled for deletion at the later token expiry. Refreshing may create a new record with a new expiry.
The retention schedule for closed accounts, pages and versions, assets and image prompts, analytics, logs, support, billing, and backups is still under review. No automatic 30-day deletion promise applies to those categories. Proposed periods are not presented here as implemented behavior.
Copies delivered to an inbox, CRM, webhook, or AI agent follow that recipient’s retention practices. Removing a Pageree lead does not delete those copies. Public content may remain in third-party caches after removal.
8. International processing
Our operator is based in Serbia. Listed application infrastructure is in Germany and database infrastructure is in the EU, while Cloudflare operates a global edge network. Providers, operator access, connected agents, and customer-selected destinations can involve processing outside your country. An EU database location does not mean all processing stays in the EU or EEA.
The final country inventory and applicable international-transfer safeguards remain under review. This draft does not represent that specific transfer agreements or certifications are already in place. Contact privacy@pageree.com for information about a particular processing arrangement.
9. Your choices and rights
Depending on applicable law, you may have rights to access, correct, delete, or receive a portable copy of information; restrict or object to processing; withdraw consent for future processing; and complain to a regulator. Withdrawing consent does not change the lawfulness of earlier consent-based processing. We will not unlawfully discriminate against you for exercising your rights.
Send requests to privacy@pageree.com with enough context to identify the relevant account or page. We may need proportionate identity or representative verification. We will explain applicable limitations and respond within the legal deadline. Do not send identification documents unless we explain why they are needed and how to send them safely.
For a lead submitted to a customer’s page, contact that business or ask us to route your request. The business remains responsible for its own systems and follow-up use.
You can complain to Serbia’s Commissioner for Information of Public Importance and Personal Data Protection; contact details are on the Commissioner’s website. Where applicable, you can also contact the competent regulator in your country. You do not have to contact us first.
10. Security and age limits
No online system can guarantee absolute security. Protect account credentials, review connected-agent permissions, and limit the personal information included in public content and prompts. This policy does not claim any security certification or compliance approval for regulated information.
You must be at least 18 to create or use a Pageree account. Pageree is not designed as a children’s service. Customer forms must not knowingly collect children’s information or sensitive regulated information without a separately approved, legally compliant arrangement. If you believe a child has provided information, contact privacy@pageree.com.
11. Policy changes
The finalized policy will carry an effective date. Material changes will receive additional notice or consent where required by law. A revised policy does not retroactively authorize incompatible uses of previously collected information.
12. Contact us
Aleksandr Shelestov PR JustOneDevJurija Gagarina 231, Novi Beograd
11070 Belgrade, Serbia
PIB (tax identification number): 113504102
- General: a@pageree.com
- Support and billing: support@pageree.com
- Privacy requests: privacy@pageree.com
- Legal notices: legal@pageree.com
- Content reports: abuse@pageree.com