Privacy policy
Pagemark is a platform for publishing and discovering academic and creative work: theses, capstones, posters, decks, studio and design work, class projects, and similar. It is operated by Pagemark HQ LLC, a Texas limited liability company. This policy explains what information Pagemark collects, how it is used, and the choices you have. The short version: we collect what's needed to run the product, your work is as public as you choose to make it, we don't sell your personal information, and we don't run advertising.
Information you provide
- Account details. Your name, email address, and password. Passwords are handled by our authentication provider (Supabase) and stored only in hashed form, Pagemark never sees or stores your plain-text password.
- Profile information. Education history (schools, positions, fields of study, years), a short bio, an about section, interests, optional links (LinkedIn, personal website), and an optional profile photo.
- Your work. Projects you publish, including titles, summaries, and any documents, slides, posters, or other files you upload.
- Activity. Comments you post, projects you appreciate or save, authors you follow, and reports you submit.
Information collected automatically
Pagemark stores small amounts of data in your browser to make the product work: your sign-in session (so you stay signed in), saved searches, and a local reading history used to improve your recommendations. The reading history stays on your device. The only cookie Pagemark itself sets remembers whether you chose a light or dark theme.
Pagemark uses no advertising trackers and no analytics cookies. For product analytics, understanding which features are used and where people get stuck, Pagemark uses PostHog in a cookieless mode: it stores nothing on your device, keeps no cross-session identity, never records your screen, and receives only the events described under “What Pagemark measures” below.
Browsers can send a “Do Not Track” signal. There is no common agreement on how services should interpret it, so Pagemark does not currently respond to it. Pagemark does not track you across other websites, and does not run advertising.
What Pagemark measures
Pagemark records some activity to power author statistics and to keep discovery working:
- Counts of project views, shares, and citation copies. These are totals, not a log of who did what.
- For a signed-in reader, the school and field shown on their profile are added to aggregate counts, so an author can see, for example, that their work reached readers in Biology across several universities. These are counts only: Pagemark never shows an author who read their work, a school or field appears only once at least five readers fall into it (so no one can be singled out), and each author sees only their own project's numbers.
Product analytics (PostHog) is separate. It records a short list of named events, such as a project being published or a search being run. Those events carry no name, email address, or profile details, are never used to identify you, and are not linked together across sessions, so we can understand how the product is used in aggregate. It runs without cookies and stores nothing on your device. The raw network request still carries your IP address and browser type, as every web request does, but Pagemark disables the location lookup on these events so they are not turned into a stored city or region.
Aggregate and de-identified information
Pagemark may produce aggregate and de-identified information about how work is published and read, for example how activity in a field is changing over time, and may publish or share it, including with schools and other institutions.
Before we do, we apply technical and organizational safeguards designed so that the information cannot reasonably be linked back to you or your household, including suppressing small groups, combining rare categories, and reviewing whether anyone could be singled out by combining it with information already public. We keep it in de-identified form, we do not attempt to re-identify it except to test that our own safeguards work, and we require anyone we share it with to do the same.
This does not change anything else in this policy: Pagemark does not sell your personal information, and does not run advertising. If information cannot be properly de-identified, we treat it as personal information.
How your information is used
- To operate your account and display your profile and published work.
- To personalize your feed and recommendations based on your interests and activity.
- To send essential account email (e.g. confirming an email-address change). Pagemark does not send marketing email.
- To review reports of plagiarism or misuse and keep the platform trustworthy.
- To understand, in aggregate, how the product is used, so we can improve it.
- To produce aggregate, de-identified statistics about how work is published and read, as described above.
- To feature a public project in Pagemark's own marketing, as described in our Terms, unless you have turned featuring off for your account.
Lawful bases for processing
If you are in the UK or EU, data protection law asks which legal basis covers each use of your data:
- Performing our contract with you covers running your account and publishing and displaying your work.
- Our legitimate interests cover keeping the service secure, preventing abuse, understanding in aggregate how the product is used, and producing aggregate and de-identified statistics, each weighed against your privacy and subject to your right to object. Featuring your work in our marketing rests on the permission in our Terms, which you can withdraw at any time in Settings, for your whole account.
- Consent covers anything we ask you to opt into specifically. Where we rely on consent, you can withdraw it at any time.
- Legal obligations cover the rare cases where the law requires us to keep or disclose information.
Visibility of your work
You control who can see each project: Public (visible in discovery, search, and your profile), Profile only (kept out of discovery and search), or Link only (visible to anyone who has the link). Your profile page, name, education, bio, and public projects, is visible to anyone with its link, which is the point of a shareable portfolio. Choose visibility accordingly, and treat link-only URLs like anything else you share: anyone you give the link to can open it.
Where your data lives
Pagemark relies on a small set of providers. Except where noted, each processes data only on Pagemark's behalf and only to run the service:
- Supabase, accounts, authentication, and the database (profiles, projects, comments, follows, and reports). Passwords are hashed by Supabase and never seen by Pagemark.
- Vercel, website hosting and delivery.
- Cloudflare R2, storage for the documents and images you upload.
- Sentry, error monitoring, so crashes can be diagnosed and fixed. It receives technical error details, which can include your IP address and browser.
- Resend, sending essential account email. It receives the recipient's email address.
- Upstash, rate limiting that protects the site from abuse. It receives IP addresses briefly.
- Cloudflare Turnstile, a bot check on sign-in and account actions. It receives your IP address and basic browser signals.
- Google, if you choose to sign in with a Google account. Google handles that sign-in under its own privacy policy, and Pagemark receives only the account details needed to create and identify your account.
- PostHog, the cookieless product analytics described above.
Pagemark does not sell your personal information, and does not share it with anyone other than these providers, except where the law requires it, where you have made your work public, or where a public project appears in Pagemark's own marketing as described in our Terms.
If Pagemark is involved in a merger, acquisition, financing, bankruptcy, dissolution, or sale of assets, your information may be transferred as part of that transaction. We will tell you before your information becomes subject to a different privacy policy.
Where your data is processed
These providers are based in the United States, so if you use Pagemark from outside the US your information is transferred to and processed in the United States. Pagemark has data processing agreements in place with Supabase, Vercel, Cloudflare, Google, PostHog, Sentry, Upstash, and Resend, the providers described above. Where the law requires a safeguard for an international transfer, Pagemark relies on the mechanisms its providers make available, which may include the European Commission's standard contractual clauses, the UK International Data Transfer Addendum, or an adequacy decision.
How your data is protected
Your connection to Pagemark is encrypted in transit with HTTPS, and the providers above encrypt stored data at rest. Passwords are hashed by Supabase and never reach Pagemark in readable form. Access controls in the database limit each account to its own data and to the public work that others have chosen to share. No system is ever perfectly secure, but protecting your work is something Pagemark takes seriously.
If there is a breach
If a data breach ever affects your personal information, Pagemark will notify you, and any regulator that the law requires, without undue delay.
How long data is kept
- Your profile, projects, and uploaded files are kept until you delete them, or delete your account.
- When you delete a file, a project, or your whole account, Pagemark deletes the uploaded files from storage, and keeps no version history of them.
- Database records (your profile, projects, and comments) may persist in encrypted daily backups of the database until those backups roll off, currently up to seven days. File storage is a separate system and is not covered by that backup window.
- Error-monitoring records (Sentry) are kept for up to 90 days and then deleted automatically.
- Product-analytics events (PostHog) are kept for up to 12 months and then deleted.
- Rate-limiting records (Upstash) are transient and expire within minutes, well under a day.
- Aggregate readership counts are kept while a project exists. They are aggregate, not personal, and contain no reader identity.
Your choices
- Edit or remove any profile information from Edit profile.
- Change a project's visibility or delete it entirely at any time.
- Turn featuring off for your whole account, in Settings.
- Change your email or password from Account settings.
- Delete your account entirely from Account settings.
Your rights over your data
Depending on where you live, you have rights over the personal data Pagemark holds about you: to access a copy of it, to correct anything that is wrong, to delete it, to receive it in a portable form, to object to or restrict certain uses, and to complain to your local data protection authority. Many of these you can exercise yourself from your settings (see Your choices above). For anything else, or to make a formal request, email legal@pagemarkhq.com and Pagemark will respond within the time the law allows.
State privacy rights
Some US states give their residents specific privacy rights. This section lists them by state. If anything here conflicts with the rest of this policy, this section governs for residents of that state. To make a request under any of these laws, email legal@pagemarkhq.com. We will verify your request using the email on your account, and you may use an authorized agent to submit a request on your behalf if you give the agent written permission and we can verify your identity.
California
Pagemark may not currently be covered by the California Consumer Privacy Act, but it offers California residents these rights anyway. You have the right to know what categories of personal information Pagemark collects (the account, profile, work, and activity described above), to access or delete it, to correct it, and to receive it in a portable form. Pagemark does not sell or share your personal information and does not use it for targeted advertising, so there is nothing to opt out of, and you will never be treated differently for exercising these rights. If we decline a request, you may appeal by replying to our response, and we will have someone else review it.
Age requirement
Pagemark is intended for students and creators aged 16 and older. Some countries set a higher minimum age for using an online service without a parent's permission, and if you live somewhere that does, you need to meet that higher age instead. If we learn an account belongs to someone below the age that applies to them, we will close the account and delete its data.
Changes to this policy
If this policy changes materially, the effective date above will be updated and significant changes will be noted on the site. This version names Pagemark HQ LLC as the operator, raises the minimum age to 16, describes the aggregate and de-identified statistics Pagemark may produce, explains how featuring works and how to turn it off, and adds sections on state privacy rights, business transfers, and Do Not Track. Continued use of Pagemark after a change means you accept the updated policy.
Contact
Questions about privacy or your data: legal@pagemarkhq.com.