PASCAL’S PAGER
Privacy Policy
This policy explains how Pascal’s Pager handles information in the iOS app, hosted service and website demo.
Effective and last updated: 25 August 20261. Who controls your data
Matthew Blake trading as designaway is the controller of personal data processed to operate Pascal’s Pager.
Matthew Blake trading as designawayUnit 168942, PO Box 7169
Poole
BH15 9EL
United Kingdom
Email privacy questions and rights requests to privacy@pascalspager.com.
2. Information we process
Account and service information
- Your email address, authentication identifier and any display name supplied through Clerk.
- Your Sources, Source instructions, redaction settings and private webhook configuration.
- Webhook JSON submitted to your Sources, the canonical representation used for AI processing after your configured masking (which may be unredacted if masking is disabled), generated Alerts and associated processing metadata.
- Encrypted APNs device tokens, delivery results, app version and last-seen time needed to deliver Alerts.
- Usage and rate-limit counters needed to apply service allowances and prevent abuse.
- RevenueCat customer, entitlement and billing-period metadata used to verify subscription access. Apple handles payment details; Pascal’s Pager does not receive full card details.
- If you opt in, reminder-consent and last-sent timestamps used to limit passive webhook-activity reminders. Reminder pushes identify the Source but never include webhook content.
- Messages and contact details you provide when asking for support.
Website and demo information
- Plausible provides aggregate page-view and conversion-event analytics. We do not send demo JSON, generated text, IP hashes or free-form values to Plausible.
- Cloudflare Turnstile and Netlify process technical request information, including IP addresses, to verify visitors and apply short per-IP request limits.
- JSON pasted into the demo is sent through OpenRouter to OpenAI, Anthropic or Google (for a Gemini model) to create an Alert. The website demo does not apply your in-app masking configuration, so you must use test data only. Pascal’s Pager does not save the pasted JSON or generated Alert to a database.
3. How and why we use information
We process information to provide the service you request, authenticate accounts, receive webhooks, mask configured data, generate and deliver Alerts, administer subscriptions, provide support, secure the service and understand aggregate website conversion.
Our principal UK GDPR lawful bases are performance of our contract with you, our legitimate interests in operating and securing the service, compliance with legal obligations and, where required, your consent. We do not use your information for advertising or to make decisions with legal or similarly significant effects.
4. AI processing and redaction
Webhook payloads are untrusted content, not instructions to the model. For each Alert, Pascal sends the Source name, your saved Source instructions and the canonical payload after your configured masking to OpenRouter. OpenRouter routes that request to either OpenAI, Anthropic or Google for processing by a selected model, which may be a Gemini model when Google is selected. The generated output returns through OpenRouter to Pascal’s Pager.
When masking is enabled for a Source, Pascal replaces the configured field names and detected pattern matches before transmission. When masking is disabled, the canonical payload is sent without that redaction. You are responsible for reviewing the masking setup and adding every field needed for your payloads. Do not rely on masking as a guarantee, and do not submit secrets, special-category data or other personal data unless you have authority and a lawful basis to process it. The public website demo does not apply your Source configuration.
Every AI request requires an OpenRouter endpoint with Zero Data Retention, denies provider data collection and requires support for the requested structured-output parameters. These controls are intended to prevent OpenRouter and the selected model endpoint from retaining prompt or response content or using it for training. OpenRouter and Pascal’s Pager may still retain non-content operational metadata such as the model and provider identifiers, token counts, cost, timing and success or failure information. Zero Data Retention does not prevent the providers from processing the content to generate the Alert.
5. Service providers
These providers process information under their own terms and privacy commitments. You can review the privacy information published by OpenRouter, OpenAI, Anthropic and Google. Some processing may occur outside the United Kingdom. Where required, we rely on adequacy regulations or contractual safeguards for international transfers.
6. Retention and deletion
- Accounts and Source configuration remain until you delete them or close your account.
- AI-generated Alert titles, summaries, facts, actions and lifecycle state remain until you delete the Source or close your account.
- The separately encrypted original payload and the sanitised JSON sent for AI processing are automatically deleted 30 days after the webhook is received. After that, the Alert remains but its payload audit views are unavailable.
- Completed processing jobs and short-lived rate-limit records are removed on scheduled cleanup cycles.
- Subscription entitlement, usage and processing-cost records are retained while needed to operate the account, reconcile allowances and meet legal obligations.
- Demo JSON and generated demo Alerts are not intentionally stored by Pascal’s Pager. Infrastructure providers may retain limited security or operational logs under their own policies.
- Support correspondence is kept only as long as reasonably needed to resolve the request and meet legal obligations.
Deleting your account removes Sources, Alerts, retained payloads, device registrations and the associated Pascal’s Pager account data. Subscription cancellation is a separate action managed through Apple.
7. Security
We use HTTPS in transit, access controls, independently encrypted webhook tokens, device tokens and retained original payloads, bounded input processing and limited administrative access. No system can be guaranteed completely secure.
8. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, object to or obtain a portable copy of personal data, and to withdraw consent. Contact privacy@pascalspager.com. We may need to verify your identity.
UK users may complain to the Information Commissioner’s Office. EEA users may complain to their local supervisory authority. California residents may request access, correction or deletion and will not be discriminated against for exercising privacy rights. We do not sell or share personal information for cross-context behavioural advertising.
9. Children
Pascal’s Pager is intended for adults aged 18 or over and is not directed to children. Contact us if you believe a child has provided personal information.
10. Changes
We may update this policy as the service or law changes. We will post the new date here and provide additional notice for material changes where appropriate.