Skip to content
PageSoarPageSoar

Privacy Policy

How hosted PageSoar handles the information you give it and the accounts you connect.

Last updated 25 September 2026. This page covers the hosted PageSoar service. A self-managed installation stores data on the operator’s own infrastructure and can use different connections.

Your account and workspace

PageSoar stores your account name and sign-in details, workspace membership and role, settings, and records of activity such as sign-ins and administrative changes. Sign-in and security records can include an IP address and browser information. Passwords are stored as hashes, not as readable passwords.

Your workspace holds the website information PageSoar reads, audits, proposed edits, saved results and change history. Connected WordPress credentials let PageSoar read your site and publish the changes you approve. Workspace members can see data according to their roles; PageSoar administrators have access to operate and support the service.

Connecting Google

Connecting Google is optional. The hosted sign-in asks for two read-only permissions:

  • Search Console: list the sites your Google account can access and read search and indexing information for the site you select, including queries, page URLs, clicks, impressions, click-through rates and positions (webmasters.readonly).
  • Google Analytics: list the accounts and properties you can access and read reports for the property you select, including landing pages, traffic sources, sessions, engagement and conversion or revenue metrics (analytics.readonly).

PageSoar uses these figures to identify pages needing attention, guide suggestions, build reports and measure results after changes. These permissions do not let PageSoar edit your Search Console or Analytics settings. The hosted Google connection does not request access to Gmail, Drive or Google Ads.

Google handles your Google password. PageSoar receives an authorization grant and stores its tokens in the workspace’s encrypted credential store so it can refresh access and read reports without asking you to sign in for each request.

Processing and service providers

Hosted PageSoar runs on Fly.io. Its storage holds account and workspace records. When you use AI writing or analysis features, relevant website content, your instructions, and Search Console query and performance context can be sent to Anthropic through PageSoar’s model service to produce the suggestions shown in your workspace. The model service also records usage and cost totals.

Website URLs and search terms used for market or page-speed checks are sent to the services that perform those checks, including DataForSEO and Google PageSpeed. Connecting Google does not publish your reports to other customers. Report files you download can be shared by whoever holds them.

For supported sales spreadsheet uploads, PageSoar reads transaction rows, removes recognized name and email columns, and stores the sales lines rather than the original workbook.

Messages, cookies and demo activity

Contact forms and connector requests store the details you submit so PageSoar can review and respond to them. These can include your name, email, company, website and message. When email delivery is configured, a notification is also sent to PageSoar’s inbox through its mail provider.

PageSoar uses cookies for sign-in sessions and form security, and browser storage for preferences such as appearance. The sample tour records progress and feedback so PageSoar can see where visitors stop and respond to requests. Do not put customer records or secrets into contact or connector-request forms.

Disconnecting, stored data and deletion

In your workspace, open Connect and disconnect Google to remove PageSoar’s stored Google sign-in grant and selected properties. This does not revoke the grant at Google. To remove access there as well, open your Google Account’s third-party connections, select PageSoar and remove its access. Google explains how to manage these connections.

Disconnecting or revoking access does not delete previously collected reports, audits or history from PageSoar, and does not remove files you downloaded. Those stored records can remain after you disconnect. To request deletion of your account or workspace data, or ask what is stored, email hello@skailstudio.com and identify the account or workspace. PageSoar will need to verify that you are entitled to make the request.

For privacy questions or corrections, use the same address: hello@skailstudio.com.

Google API Services: Limited Use

PageSoar’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Search Console and Analytics data is used only to provide and improve the features you see in your workspace; it is never sold, never used for advertising, never used to train generalized AI or machine-learning models, and is read by a person at PageSoar only with your permission, for security, or where the law requires it.

Why we may use it (GDPR and UK GDPR)

Where European or UK data protection law applies: we use account, workspace and billing information to perform our contract with you; sign-in and security records, and replies to messages, for our legitimate interest in running a safe service and answering you; and Google data only because you chose to connect it, which you can undo at any time. For personal data inside a customer’s workspace, the customer decides why it is processed and PageSoar processes it for them under the Data Processing Addendum.

Sign-up, contact forms and the email we send

Sign-up. The trial form keeps your name, work email, company, website, plan and billing period, the network (IP) address the form came from, and which version of the Terms you accepted and when. We use them to set up your workspace and to show what you agreed to.

Contact us and the demo tour. These keep your name, email, company, website and message, and on the demo tour’s closing form also your role, how interested you are, how far through the tour you got and how many chapters you finished. We use them to reply and to see where the tour loses people.

Email to customers. We send account email you need (setting a password, invitations, a reset, what happens to your workspace when a payment fails) and, to workspace members, a weekly results email. Every weekly email has a link at the bottom that stops it, and your Account page has the same switch. Account email cannot be turned off while you have an account, because it is how the service works. Paddle sends receipts itself.

Alerts to our staff. When a message, a connector request or a trial sign-up arrives, PageSoar sends a short alert with the sender’s name, email and message (or the new customer’s name, email and plan) to a staff member’s phone. It goes through Nowlark, a notification service run by Skail Consulting LLC on Fly.io, and Apple’s push service delivers it to the phone. Nowlark deletes it after the history length set on that account.

Businesses we write to

We write to a small number of businesses we think PageSoar can help. If you received such an email, this is what we hold and why.

  • Where your address came from: your business publishes it on its own website, usually its contact page. We use only addresses a business publishes, such as info@ or sales@, never one we guessed or bought.
  • What we keep: the business’s web address and country, the published address and the page it is on, the results of a free check of the public website, and each step we took (drafted, sent, replied).
  • Why: to offer PageSoar to a business it may help. Under GDPR and UK GDPR our basis is legitimate interest (Article 6(1)(f)), in telling a business about a service relevant to its work.
  • How long: a business we never wrote to is deleted after 90 days; one we wrote to, 24 months after the last step.
  • How to object: reply “no” to any of our emails, or write to hello@skailstudio.com. We stop at once and do not write again. We keep your address or domain on a do-not-contact list with the date and reason, only so we never write again; it is the one record we keep for good.

Who else receives it

The companies that process data for us are on the subprocessors list, with what each receives and where. Data is stored in the United States; where it moves from the EU or UK, the transfer relies on the European Commission’s standard contractual clauses or an equivalent safeguard. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

How long it is kept

Account and workspace data is kept while the workspace is open. After a workspace closes its data is kept until an admin asks for it to be deleted or we delete the workspace. Billing records are kept by Paddle as tax law requires. We answer a verified request to delete within one month. The rest is deleted on a schedule PageSoar runs by itself:

  • Sign-in and security records (the activity log, with the IP address of each sign-in, and ended sessions with their IP address and browser): 12 months.
  • The IP address a sign-up form was sent from: blanked after 12 months.
  • A sign-up form that never reached a payment: 90 days.
  • Contact us and demo tour messages: 24 months.
  • Businesses found for outreach and never written to: 90 days. Those written to: 24 months after the last step.
  • The do-not-contact list: kept for good, so an objection is always honoured.

Your rights

Depending on where you live, including under GDPR, UK GDPR and the California Consumer Privacy Act, you can ask to know what we hold about you, get a copy, correct it, delete it, restrict or object to its use, or move it elsewhere. We will not treat you differently for asking. Write to hello@skailstudio.com; an authorised agent may ask for you. If you are in the EU or UK you can also complain to your data protection authority. If your data is in a workspace another business runs, we will pass your request to them.

Cookies, children and changes

The cookies PageSoar sets are all needed for it to work; they are listed on the cookies page. PageSoar is not meant for anyone under 16. When this policy changes in a way that matters, we update the date above and tell workspace admins by email.

Who is responsible

Skail Consulting LLC (Skail Studio) runs hosted PageSoar and is responsible for the data described here. Contact: hello@skailstudio.com.

Report a security issue

Found a vulnerability in PageSoar? The Security page says where to write and what happens next. Please give us time to fix it before you tell anyone else, and do not access data that is not yours.

Changes

  • 25 September 2026: Adds businesses we write to, what the sign-up and contact forms keep, customer email, how staff alerts are delivered, and how long each record is kept.
  • 25 September 2026: Adds Google Limited Use, GDPR bases, recipients and your rights.