Privacy Policy

This policy explains how Pascal’s Pager handles information in the iOS app, hosted service and website demo.

Effective and last updated: 18 August 2026

1. Who controls your data

Matthew Blake trading as designaway is the controller of personal data processed to operate Pascal’s Pager.

Matthew Blake trading as designaway
Unit 168942, PO Box 7169
Poole
BH15 9EL
United Kingdom

Email privacy questions and rights requests to privacy@pascalspager.com.

2. Information we process

Account and service information

  • Your email address, authentication identifier and any display name supplied through Clerk.
  • Your Sources, Source instructions, redaction settings and private webhook configuration.
  • Webhook JSON submitted to your Sources, the sanitised representation used for AI processing, generated Alerts and associated processing metadata.
  • Encrypted APNs device tokens, delivery results, app version and last-seen time needed to deliver Alerts.
  • Usage and rate-limit counters needed to apply service allowances and prevent abuse.
  • Messages and contact details you provide when asking for support.

Website and demo information

  • Plausible provides aggregate page-view and conversion-event analytics. We do not send demo JSON, generated text, IP hashes or free-form values to Plausible.
  • Cloudflare Turnstile and Netlify process technical request information, including IP addresses, to verify visitors and apply short per-IP request limits.
  • JSON pasted into the demo is sent through OpenRouter to a routed AI provider to create an Alert. The website demo does not apply your in-app masking configuration, so you must use test data only. Pascal’s Pager does not save the pasted JSON or generated Alert to a database.

3. How and why we use information

We process information to provide the service you request, authenticate accounts, receive webhooks, mask configured data, generate and deliver Alerts, administer subscriptions, provide support, secure the service and understand aggregate website conversion.

Our principal UK GDPR lawful bases are performance of our contract with you, our legitimate interests in operating and securing the service, compliance with legal obligations and, where required, your consent. We do not use your information for advertising or to make decisions with legal or similarly significant effects.

4. AI processing and redaction

Webhook payloads are untrusted content, not instructions to the model. In the app, when masking is enabled for a Source, Pascal replaces the field names and pattern options configured for that Source before the resulting representation is sent through OpenRouter to a selected AI provider.

You are responsible for reviewing the masking setup and adding every field needed for your payloads. Do not rely on masking as a guarantee, and do not submit secrets, special-category data or other personal data unless you have authority and a lawful basis to process it. The public website demo does not apply your Source configuration.

5. Service providers

ProviderPurpose
ClerkAccount authentication
ConvexApplication database, webhook processing and backend execution
OpenRouter and routed AI providersGeneration of structured Alerts from sanitised JSON
AppleApp distribution, subscriptions and push-notification delivery
NetlifyWebsite hosting and demo execution
Cloudflare TurnstileBot and abuse prevention for the demo
Plausible AnalyticsAggregate website and conversion analytics

These providers process information under their own terms and privacy commitments. Some processing may occur outside the United Kingdom. Where required, we rely on adequacy regulations or contractual safeguards for international transfers.

6. Retention and deletion

  • Accounts and Source configuration remain until you delete them or close your account.
  • Alerts, processed payloads and encrypted originals ordinarily expire after 30 days; the configured period may change within the limits explained in the service.
  • Completed processing jobs and short-lived rate-limit records are removed on scheduled cleanup cycles.
  • Demo JSON and generated demo Alerts are not intentionally stored by Pascal’s Pager. Infrastructure providers may retain limited security or operational logs under their own policies.
  • Support correspondence is kept only as long as reasonably needed to resolve the request and meet legal obligations.

Deleting your account removes Sources, Alerts, retained payloads, device registrations and the associated Pascal’s Pager account data. Subscription cancellation is a separate action managed through Apple.

7. Security

We use HTTPS in transit, access controls, independently encrypted webhook tokens, device tokens and retained original payloads, bounded input processing and limited administrative access. No system can be guaranteed completely secure.

8. Your rights

Depending on where you live, you may have rights to access, correct, erase, restrict, object to or obtain a portable copy of personal data, and to withdraw consent. Contact privacy@pascalspager.com. We may need to verify your identity.

UK users may complain to the Information Commissioner’s Office. EEA users may complain to their local supervisory authority. California residents may request access, correction or deletion and will not be discriminated against for exercising privacy rights. We do not sell or share personal information for cross-context behavioural advertising.

9. Children

Pascal’s Pager is intended for adults aged 18 or over and is not directed to children. Contact us if you believe a child has provided personal information.

10. Changes

We may update this policy as the service or law changes. We will post the new date here and provide additional notice for material changes where appropriate.